Network Tools
π Port Scanner
Fast port scanner focused on reliable open-port discovery across your external attack surface.
What it finds:
- Open TCP/UDP ports
- Live hosts with reachable ports (host discovery)
- The port map that seeds web tools like Web Probe (which handles HTTP service and technology detection)
Port Scanner is a pure port scanner β it reports which ports are open, not what's running on them. TurboPentest fingerprints the services on top of that map:
- Web ports (80, 443, 8080, 8443, β¦) are handed to Web Probe for server header, technology-stack, and version detection.
- Non-web ports (SSH, FTP, SMTP, RDP, databases, β¦) are handed to Vuln Scanner, which runs its network service-detection and version templates to fingerprint the service and its version, then matches known CVE templates against that version.
π TLS Analyzer
Comprehensive TLS/SSL testing tool.
What it finds:
- Expired or self-signed certificates
- Weak cipher suites
- Protocol vulnerabilities (BEAST, POODLE, Heartbleed, etc.)
- Missing HSTS headers
- Certificate chain issues
π‘ Sub Hunter
Passive subdomain discovery tool.
What it finds:
- Subdomains from public sources (DNS, certificate transparency, search engines)
- Potential shadow IT or forgotten services
π Web Probe
HTTP toolkit for probing discovered hosts.
What it finds:
- HTTP response codes and server headers
- Technology stack detection
- Content length and title extraction
- Redirect chains
π§± WAF Detect
Web Application Firewall detection tool.
What it finds:
- Whether a WAF is present
- WAF vendor identification (Cloudflare, AWS WAF, Akamai, etc.)
- Helps interpret findings from other tools (some issues may be mitigated by WAF)
OWASP Top 10 Coverage
How TurboPentest's 14 Phase-1 security tools map to the OWASP Top 10 2025, with Paladin (Phase 2) adding an analysis layer that spans every category.
Web Application Tools
TurboPentest's web application testing tools - the DAST scanners that probe your app for OWASP Top 10 and other vulnerabilities.