Skip to main content

VAPT Tools

Vulnerability Assessment and Penetration Testing (VAPT) is a range of security testing services to identify and address cybersecurity vulnerabilities. VAPT Tools Capture

note

Helium offers a variety of VA Scanners and Pentest Tools. Below are the different types available.

VA Scanner

VA ScannerFunction
Website ScannerDiscover vulnerabilities in web applications, including Log4j, SQL Injection, and XSS.
Network ScannerDiscover outdated network services, insecure software configuration, missing security patches, and more vulnerabilities.
API ScannerUsers can identify potential vulnerabilities and improve IoT network security.
Mobile Apps ScannerDiscover vulnerabilities that affect mobile apps (Android and iOS), including insecure data storage and poor client code quality.
info

To use the Mobile Apps Scanner tool, users can only access it via the navigation menu.

Pentest Tools

Pentest ToolsFunction
BruteforceFind service credentials on Web Apps, SSH, FTP, MySQL, Telnet, and more.
CMS ScannerDetecting security flaws of the foremost popular CMSs.
Find DNSFind name servers of a target domain vulnerable to DNS Zone.
Find Git ExposureDiscover source code via the exposed .git folder.
Find Open Ports and ServicesDiscover network services, operating systems, misconfigurations, and more.
Find Security HeadersDiscover the Security Header policies in place and add another level of protection that can stop common attacks such as code injection, XSS attacks, and clickjacking.
Find SubdomainDiscover subdomains and enumerate the vulnerabilities.
Find Website DirectoryDiscover hidden directories and files on a website, making it easier for you for information gathering.
Find Website TechFind useful information about the technologies a target web application uses - server-side and client-side.
Google HackingA hacker technique called Google dorking uses Google Search and other Google apps to search for vulnerabilities in website code and configuration.
SQLI ExploitationDiscover SQL Injection vulnerabilities in web applications.
Website ReconFind useful information about Misconfiguration and sensitive folders/files used by a target web application - server-side and client-side.
Whois LookupDiscover data about an Internet resource such as a domain name or IP address.
XSS ScannerDiscover Cross-Site Scripting (XSS) vulnerabilities in web applications.
XSS HuntingAssuring your Proofs-of-Concept and demonstrating the risk of XSS vulnerabilities in web applications.
info

To use the Google Hacking dan XSS Hunting tool, users can only access it via the navigation menu.

note

Users can access the tools via the navigation menu by clicking on "VAPT Tools". If the user chooses to perform scanning via the navigation menu, then the user must enter the required target values. This is different from scanning via the targets page because the target value is entered at the beginning when adding the target. Once the scanning process is complete, users will receive a notification via email, and if they have integrated with Telegram or Slack, they will also receive notifications via both platforms.