Burp Suite
What it’s for
An intercepting web proxy: it sits between your browser and the target so you can view, change and replay every HTTP request. Most web app testing runs through it.
Where it shines
- Repeater and Intruder make manual testing fast
- A huge extension ecosystem (the BApp store) for almost anything
Where it falls down
- The scanner and Intruder throttling are Pro-only; Community is limited
- Can get heavy and RAM-hungry on large sites
My take
I havn't completed a webapp test to date without using Burpsuite, it is, in my opinion, the absolute goat of web app pentesting tools.