OWASP ZAP
scans through your web application to identity any security vulnerabilities as possible.
Burp Suite
graphical tool for performing security testing of web applications.
Gobuster
a tool used to brute-force URIs including directories and files as well as DNS subdomains.