w3af
w3af is a Web Application Attack and Audit Framework
20 Alternatives To w3af
Acunetix
Audit your website security and web applications for SQL injection, Cross site scripting and other…
Burp Suite
Burp Suite is an integrated platform for performing security testing of web applications.
Censys
Censys helps organizations, individuals, and researchers find and monitor every server on the Internet to reduce exposure and improve security.
Charles
HTTP proxy / HTTP monitor / Reverse Proxy
IVRE
Network recon framework, including a web interface to browse Nmap scan results.
Intruder
Intruder is a security monitoring platform for internet-facing systems.
IronWASP
Learn, download and use the most flexible and powerful web application security testing framework.
Netsparker
Netsparker is a tool for scanning web sites for security vulnerabilities.
Nikto
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web…
PunkSPIDER
PunkSPIDER is a global-reaching web application vulnerability search engine.
SecApps
Find security vulnerabilities right from your browser.
Shodan
Shodan is the world’s first search engine for Internet-connected devices.
Tamper Data
Firefox add-on that lets you change headers and request parameters before they’re sent to the…
Thingful
Search engine for the Internet of Things
Vega
Subgraph Vega | Free and Open Source Web Application Vulnerability and Security Scanner
Websecurify
Websecurify free and premium security tools automatically scan websites for vulnerabilities like SQL Injection, Cross-site Scripting and others
Zed Attack Proxy
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding…
ZoomEye
Network mapping service
skipfish
A fully automated, active web application security reconnaissance tool.
wapiti
Wapiti allows you to audit the security of your web applications. Wapiti is a command line tool.