Automated Vulnerability Scanning
Last updated
Last updated
Automated Vulnerability Scanning is a critical component of active web application reconnaissance, allowing for the efficient identification of known vulnerabilities in web applications.
OWASP ZAP (Zed Attack Proxy): Automated vulnerability scanner for web applications.
Nessus: Widely used vulnerability scanner with web application scanning capabilities.
Acunetix: Automated tool to scan web applications for vulnerabilities.
Nikto (CLI-based): Web server scanner which performs tests against web servers for multiple items.
Qualys Web Application Scanning: Cloud service for automated web application scanning.
SQLmap (CLI-based): Automated tool for SQL injection discovery and exploitation.
WebInspect: Automated dynamic application security testing.
AppSpider: Scans web applications to identify vulnerabilities.
W3af: Web application attack and audit framework.
IBM Security AppScan: Suite of software products for security testing of web applications.
Detectify: Automated vulnerability scanner that mimics a hacker's techniques.
Netsparker: Automated web application security testing.
Veracode Static Analysis: Identifies and fixes vulnerabilities in web applications in all major languages.
Probely: Finds vulnerabilities and provides guidance on fixing them.
Invicti (Formerly NetSparker): Scans web applications, websites, and web services to detect security flaws.
SiteLock: Provides website scanning and malware detection.
Syhunt: A suite of tools for dynamic and static analysis of web applications.
BeEF (Browser Exploitation Framework): Focuses on the web browser, aiming to assess the security posture of a target environment.
Grabber: Scans small web applications for common vulnerabilities.