Scanning & Enumeration
Active probing: ports, services, vulnerability templates, and directory discovery.
Dirb
ScanningClassic web content scanner using wordlists to discover hidden directories and files.
enum4linux-ng
ScanningModern SMB/LDAP/RPC enumerator for Windows and Samba hosts—users, groups, shares, and policies.
Feroxbuster
ScanningRecursive content discovery tool with smart filtering, backups, and automatic extraction of new URLs.
ffuf
ScanningFast web fuzzer for directories, parameters, vhosts, and header injection with flexible matchers.
Gobuster
ScanningFast directory, DNS, vhost, and S3 bucket brute-forcer written in Go.
httpx
ScanningFast HTTP probe for live URLs, status codes, titles, and tech fingerprinting from host lists.
Masscan
ScanningHigh-speed Internet-scale port scanner for rapid discovery before deeper nmap enumeration.
Nikto
ScanningWeb server scanner for dangerous files, misconfigurations, and outdated software indicators.
Nmap
ScanningNetwork mapper for host discovery, port scanning, service/version detection, and NSE scripting.
Nuclei
ScanningTemplate-based fast scanner for CVEs, misconfigs, and exposures across HTTP, DNS, and more.
RustScan
ScanningFast port scanner that pipes discovered ports directly into Nmap for scripting and version detection.
SearchSploit
ScanningCommand-line search of Exploit-DB for public exploits, shellcode, and papers by keyword or CVE.
wafw00f
ScanningIdentifies Web Application Firewalls in front of targets to tune bypass and testing strategy.
Wfuzz
ScanningPython web fuzzer for brute-forcing parameters, directories, and headers with flexible filters.
WhatWeb
ScanningWeb technology fingerprinter identifying CMS, frameworks, plugins, and server headers.