OWASP ZAP
Web Applicationkali · parrotFree open-source web app scanner and proxy — solid Burp alternative for automated scans.
Install
sudo apt install zaproxy
Common commands
zaproxy zap.sh -daemon -port 8080
Use only on systems you are authorized to test. Follow program scope.
Related tools
Burp Suite
featuredThe industry-standard intercepting proxy for web app and API testing. Core bug bounty tool.
ffuf
featuredFast web fuzzer for directories, virtual hosts, and parameters. Preferred over older gobusters for speed.
httpx
featuredFast HTTP toolkit from ProjectDiscovery for probing live hosts and tech detection.
Dirb
Classic content scanner that brute-forces web directories and files.