CompTIA CySA+ CS0-003: Nikto

Nikto is a free CLI scanner for web servers. It performs generic and server type specific checks and looks for dangerous files/CGIs and other vulnerabilities related to server software. Targets can be entered individually or even as a bulk list . In the CLI you simply type in the IP or the URL. The tool does take around an hour to run depending on the speed of the web server and it does quite well in detecting vulnerabilities. It is not a stealthy tool and will generate over 2000 HTTP GET requests to web servers, but you can also test IDS or HDS at the same time.