Developed by OWASP (Open Web Application Security Project), ZAP or Zed Attack Proxy is a multi-platform, open-source web application security testing tool.
Wfuzz
Developed in Python, Wfuzz is popularly used for brute-forcing web applications.
WireShark
Wireshark is a network protocol analyzer, or an application that captures packets from a network connection, such as from your computer to your home office or the internet to analyse risk.
W3af
w3af is an open-source web application security scanner. It provides a vulnerability scanner and exploitation tool for Web applications.
Burp Suite
Burp Suite is an integrated platform/graphical tool for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities