Burp Suite
Web Applicationkali · parrotThe industry-standard intercepting proxy for web app and API testing. Core bug bounty tool.
Install
sudo apt install burpsuite
Common commands
burpsuite # Configure browser proxy 127.0.0.1:8080 # Install Burp CA certificate
Use only on systems you are authorized to test. Follow program scope.
Related tools
ffuf
featuredFast web fuzzer for directories, virtual hosts, and parameters. Preferred over older gobusters for speed.
httpx
featuredFast HTTP toolkit from ProjectDiscovery for probing live hosts and tech detection.
OWASP ZAP
featuredFree open-source web app scanner and proxy — solid Burp alternative for automated scans.
Dirb
Classic content scanner that brute-forces web directories and files.