In-app reader
I’m not looking for a huge list of pentesting tools. I’m interested in the actual workflow used by professional web pentesters during an engagement. For example: recon → fingerprinting → crawling → content discovery → attack surface mapping → automated vulnerability scanning → manual testing → vulnerability-specific tools → validation / PoC Which tools do you actually use at each stage? I’m especially interested in: Nmap Whatweb Wpscan Searchsploit Sqli Burp Suite httpx Nmap / Naabu WhatWeb Katana ffuf / Feroxbuster Nuclei Arjun sqlmap WPScan Dalfox Metasploit Which of these tools are redundant in 2026? For example, is there still a reason to use Gobuster, Dirsearch, Nikto, Hakrawler or GoSpider if you’re already using ffuf, Katana, Nuclei and Burp Suite? What parts of web pentesting do you automate and what parts do you still always test manually? I’d also like to see an example of the actual order in which you run the tools during a web application pentest, rather than just a list of tools. submitted by /u/No-Argument-956 [link] [comments]
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.