WFuzz
Web ApplicationkaliFlexible web application fuzzer for parameters, headers, and auth.
Install
sudo apt install wfuzz
Common commands
wfuzz -c -z file,wordlist.txt --hc 404 https://target.com/FUZZ
Use only on systems you are authorized to test. Follow program scope.
Related tools
Burp Suite
featuredThe industry-standard intercepting proxy for web app and API testing. Core bug bounty tool.
ffuf
featuredFast web fuzzer for directories, virtual hosts, and parameters. Preferred over older gobusters for speed.
httpx
featuredFast HTTP toolkit from ProjectDiscovery for probing live hosts and tech detection.
OWASP ZAP
featuredFree open-source web app scanner and proxy — solid Burp alternative for automated scans.