Understanding Application Vulnerabilities Flashcards
Burp Suite
A proprietary interception proxy and web application assessment tool.
Zed Attack Proxy(ZAP)
An open-source interception proxy and web application assessment tool.
Nikto
Vulnerability scanner that can be used to identify known web server vulnerabilities and misconfigurations, identify web applications running on a server, and identify potential known vulnerabilities in those web applications.
Arachni
An open-source web application scanner.
Application Debugger
tool is used to look “inside” of binaries to reveal how they work at an instruction-by-instruction level
ScoutSuite
An open-source cloud vulnerability scanner designed for AWS, Azure, and GCP auditing.
Prowler
An open-source cloud vulnerability scanner designed for AWS auditing
Pacu
An open-source cloud penetration testing framework.