Vulnerability Scanners
Sirius
Open Source Vulnerability Scanner

Nessus

Request free licence: https://www.tenable.com/products/nessus/activation-code

Install package:
Starting Nessus
Access Nessus:
https://localhost:8834

Export Nessus Scan
OpenVAS
Install on Ubuntu (OsBoxes)
sudo su
Start OpenVAS
Doesn't work on my ubuntu, use Docker: https://greenbone.github.io/docs/latest/22.4/container/index.html
Creds - admin::admin

Export result
stop all containers
$ docker stop $(docker ps -a -q)
Web Apps Scan
BBScan
Nuclei

Reporting

Custom Templates
CVE Scanning Templates
All Templates
Nuclei AI Prompts
NucleiFuzzer
Rogue - LLM agent
OWASP Nettacker
TerminatorZ
Wapiti - Web Scan

Scant3r
Mantis
GBounty
Lostools
LOXS (LFI, Open Redirect, XSS, SQLi)
Nikto

reconFTW
Interesting Books
Interesting BooksThe Web Application Hacker’s Handbook The go-to manual for web app pentesters. Covers XSS, SQLi, logic flaws, and more
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities Learn how to perform reconnaissance on a target, how to identify vulnerabilities, and how to exploit them
Real-World Bug Hunting: A Field Guide to Web Hacking Learn about the most common types of bugs like cross-site scripting, insecure direct object references, and server-side request forgery.
Support this Gitbook
I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.
Last updated


