commit 0a4129cb337fbf1b2094906d0a7bfaddf74377d1
parent a5a5703a1f2d2232fb856b55e0ef2bfe5ee1c656
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Tue, 15 Sep 2026 01:59:07 +0100
feat: add detailed feroxbuster content-discovery cheatsheet
New enumeration sheet covering feroxbuster v2.11.x: install methods,
core/HTTP/recursion flags, matchers and filters, link extraction and
collection, performance/stealth (auto-tune, auto-bail, rate-limit),
the interactive scan menu, FUZZ keyword, resume/state files, config
file, wordlists, and CTF/pentest/bug-bounty workflows.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LGt1BFBCTS16MDy6Vewoxe
Diffstat:
1 file changed, 359 insertions(+), 0 deletions(-)
diff --git a/src/content/sheets/enumeration/feroxbuster.md b/src/content/sheets/enumeration/feroxbuster.md
@@ -0,0 +1,359 @@
+---
+title: "feroxbuster"
+description: "feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters."
+category: enumeration
+tags: [enumeration, web, brute-force, recursion]
+tools: [feroxbuster]
+difficulty: beginner
+updated: "2026-09-15"
+---
+
+# feroxbuster
+
+> **feroxbuster** — Fast, simple, recursive content-discovery tool written in Rust (v2.11.x). Author: Ben "epi" Risher (`@epi052`).
+> Key differentiators over `gobuster`/`dirb`: **recursion is on by default**, it **extracts links** from response bodies (HTML/JS/robots.txt) and scans them, auto-filters obvious wildcard/404 responses, and offers an **interactive scan-management menu** while running.
+
+## Installation
+
+```bash
+# Kali / Debian / Ubuntu (repo package)
+sudo apt install feroxbuster
+
+# Cargo (Rust toolchain, always latest)
+cargo install feroxbuster
+
+# Homebrew (macOS / Linuxbrew)
+brew install feroxbuster
+
+# Static binary install script (no root needed, drops ./feroxbuster)
+curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash
+
+# Prebuilt release binary (Linux x86_64)
+curl -sL https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-linux-feroxbuster.tar.gz \
+ | tar -xz && sudo mv feroxbuster /usr/local/bin/
+
+# Docker
+docker run --init -it ghcr.io/epi052/feroxbuster:latest \
+ -u http://target.com -w /wordlists/common.txt
+```
+
+```bash
+feroxbuster -h # concise help
+feroxbuster --help # full help with every flag and default
+feroxbuster -V # version
+```
+
+## Quick Start
+
+```bash
+# The one command you'll run 90% of the time — recursion is automatic
+feroxbuster -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
+
+# With extensions and a saved log
+feroxbuster -u http://10.10.10.100 \
+ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
+ -x php,html,txt -o ferox.txt
+```
+
+## Core Flags
+
+| Flag | Short | Description |
+|------|-------|-------------|
+| `--url <url>` | `-u` | Target URL. **Repeatable** — pass `-u` multiple times to scan several targets |
+| `--wordlist <path>` | `-w` | Wordlist path (default: `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt`) |
+| `--threads <int>` | `-t` | Total number of concurrent threads (default: `50`) |
+| `--depth <int>` | `-d` | Maximum recursion depth; `0` means recurse infinitely (default: `4`) |
+| `--extensions <exts>` | `-x` | Extensions to append, comma-separated (`php,html,txt`). Use `-x tar.gz` etc. for multi-part |
+| `--methods <methods>` | `-m` | HTTP methods to try, comma-separated (default: `GET`) |
+| `--data <data>` | | Request body to send (e.g. for `POST`); accepts `@file` to read from a file |
+| `--stdin` | | Read the target URL(s) from STDIN instead of `-u` |
+| `--output <file>` | `-o` | Write results to a file (plain text, or JSON with `--json`) |
+| `--json` | | Emit newline-delimited JSON (great for piping / jq) |
+| `--silent` | | Machine-readable output only — URLs, no banner or progress (ideal for piping) |
+| `--quiet` | `-q` | Suppress the progress bars and banner but keep status lines |
+| `--verbosity` | `-v` | Increase log verbosity (`-v`, `-vv`, `-vvvv`) |
+| `--no-recursion` | `-n` | Disable recursion entirely (behave like gobuster `dir`) |
+| `--add-slash` | `-f` | Append `/` to each word (find directories that only answer with a trailing slash) |
+| `--resume-from <state>` | | Resume a previous scan from its `ferox-<ts>.state` file |
+
+## HTTP / Request Flags
+
+| Flag | Short | Description |
+|------|-------|-------------|
+| `--headers <header>` | `-H` | Custom header, repeatable (`-H 'Authorization: Bearer …' -H 'X-Api: 1'`) |
+| `--cookies <cookie>` | `-b` | Cookie(s) to send, repeatable (`-b 'PHPSESSID=abc'`) |
+| `--query <param>` | `-Q` | Query-string parameter, repeatable (`-Q 'debug=1'`) |
+| `--user-agent <string>` | `-a` | Set the User-Agent (default: `feroxbuster/<version>`) |
+| `--random-agent` | `-A` | Pick a random User-Agent per scan from a built-in list |
+| `--redirects` | `-r` | Follow 3xx redirects (off by default — 301/302 are reported, not followed) |
+| `--insecure` | `-k` | Disable TLS certificate validation |
+| `--proxy <url>` | `-p` | Proxy all traffic (`http://127.0.0.1:8080`, `socks5://127.0.0.1:1080`) |
+| `--replay-proxy <url>` | `-P` | Send **only matched** responses to a second proxy (e.g. Burp) to cut noise |
+| `--replay-codes <codes>` | `-R` | Status codes that get sent to the replay proxy (default: your match codes) |
+| `--burp` | | Shortcut for `--proxy http://127.0.0.1:8080 --insecure` |
+| `--burp-replay` | | Shortcut for `--replay-proxy http://127.0.0.1:8080 --insecure` |
+| `--server-certs <pem>` | | Trust a custom CA / self-signed server cert (repeatable) |
+| `--client-cert <pem>` | | Client certificate for mTLS |
+| `--client-key <pem>` | | Client private key for mTLS |
+| `--timeout <secs>` | `-T` | Per-request timeout in seconds (default: `7`) |
+
+## Status Codes, Matchers & Filters
+
+feroxbuster's real power is filtering. By default it reports status codes `200-299, 301, 302, 307, 308, 401, 403, 405` and auto-filters wildcard responses. Tune with:
+
+| Flag | Short | Description |
+|------|-------|-------------|
+| `--status-codes <codes>` | `-s` | Whitelist: only report these status codes (space/comma separated) |
+| `--filter-status <codes>` | `-C` | Blacklist: hide these status codes (e.g. `-C 404,403`) |
+| `--filter-size <bytes>` | `-S` | Hide responses of exactly these byte sizes (repeatable) |
+| `--filter-words <count>` | `-W` | Hide responses with this many words |
+| `--filter-lines <count>` | `-N` | Hide responses with this many lines |
+| `--filter-regex <regex>` | `-X` | Hide responses whose body matches this regex |
+| `--filter-similar-to <url>` | | Hide responses fuzzy-similar (ssdeep) to a known page — kills soft-404s |
+| `--dont-filter` | | Turn OFF wildcard/auto filtering (report literally everything) |
+
+> **Workflow — kill false positives fast:** Run once, spot a repeating bogus size/word/line count in the output, then re-run adding `-S <size>` / `-W <words>` / `-N <lines>`. For soft-404 pages that vary in size, `--filter-similar-to http://target/definitely-404-page` is the sharpest tool.
+
+## Recursion Control
+
+| Flag | Description |
+|------|-------------|
+| `-n`, `--no-recursion` | Disable recursion completely |
+| `-d`, `--depth <int>` | Cap recursion depth (`0` = unlimited; default `4`) |
+| `--force-recursion` | Recurse into every discovered URL even without a trailing slash / not obviously a directory |
+| `-L`, `--scan-limit <int>` | Max number of directory scans running concurrently (throttles a recursion explosion) |
+| `-I`, `--dont-scan <regex>` | Skip URLs matching this regex, repeatable (e.g. `-I 'logout' -I '\.js$'`) |
+
+```bash
+# Deep but controlled: unlimited depth, but only 3 directories scanned at once
+feroxbuster -u http://target -w wordlist.txt -d 0 -L 3
+
+# Recurse everywhere, but never into logout or static asset paths
+feroxbuster -u http://target -w wordlist.txt --force-recursion -I 'logout' -I '\.(js|css|png|jpg)$'
+```
+
+## Link Extraction & Collection
+
+feroxbuster parses response bodies and pulls out more targets automatically:
+
+| Flag | Short | Description |
+|------|-------|-------------|
+| `--extract-links` | `-e` | Parse HTML/JS/`robots.txt` for links and scan them (on by default in recent builds; flag forces it) |
+| `--dont-extract-links` | | Turn link extraction off |
+| `--scan-dir-listings` | | Also brute-force inside auto-indexed (`Index of /`) directory listings |
+| `--collect-extensions` | | Learn extensions seen in responses and add them to the scan on the fly |
+| `--collect-backups` | | On each found page, also request backup variants (`.bak`, `~`, `.old`, …) |
+| `--collect-words` | | Harvest words from responses and add them to the wordlist mid-scan |
+
+```bash
+# "Just find everything" mode — collect extensions, backups, and words as it goes
+feroxbuster -u http://target -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
+ --collect-extensions --collect-backups --collect-words
+```
+
+## Performance & Stealth
+
+| Flag | Short | Description |
+|------|-------|-------------|
+| `--threads <int>` | `-t` | Concurrent threads (default `50`) |
+| `--rate-limit <int>` | | Cap requests **per second** per directory scan |
+| `--scan-limit <int>` | `-L` | Concurrent directory scans |
+| `--time-limit <spec>` | | Stop after a duration (`10m`, `1h`, `30s`) |
+| `--auto-tune` | | Automatically slow down when the server starts erroring, then speed back up |
+| `--auto-bail` | | Abort a scan that trips too many errors/timeouts/403s (guards against WAF bans) |
+| `--smart` | | Preset: `--auto-tune --collect-words --collect-backups --extract-links` |
+| `--thorough` | | Preset: everything `--smart` does plus `--collect-extensions --scan-dir-listings` |
+
+```bash
+# Gentle scan against a rate-limited / WAF'd target
+feroxbuster -u http://target -w wordlist.txt --rate-limit 20 --auto-tune --auto-bail
+
+# Aggressive but self-throttling one-liner
+feroxbuster -u http://target -w wordlist.txt --thorough --auto-tune
+```
+
+## Interactive Scan Menu
+
+While a scan is running, press **`Enter`** to open the interactive menu. From there you can:
+
+- List all active recursive scans with their IDs.
+- **Cancel** a runaway scan (e.g. a huge auto-indexed directory) without killing the whole run: type the scan number(s) and confirm.
+- Cancelled scans are pruned so the rest of the run continues.
+
+This is the main reason to prefer feroxbuster on messy targets — you prune noisy recursion live instead of restarting.
+
+## Practical Examples
+
+```bash
+# Basic recursive scan with extensions
+feroxbuster -u http://10.10.10.100 \
+ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
+ -x php,html,txt
+
+# Authenticated scan (session cookie + bearer token)
+feroxbuster -u http://10.10.10.100 \
+ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
+ -b 'PHPSESSID=abc123def456' -H 'Authorization: Bearer eyJhbGciOi...'
+
+# Over HTTPS with a bad cert, following redirects
+feroxbuster -u https://10.10.10.100 -w wordlist.txt -k -r
+
+# Proxy everything through Burp
+feroxbuster -u http://10.10.10.100 -w wordlist.txt --burp
+
+# Scan fast, but replay only interesting hits to Burp
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -t 100 \
+ --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302
+
+# Filter out a soft-404 baseline (page is 200 but always ~1274 bytes / 96 words)
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -S 1274 -W 96
+
+# Only show 200s and 301s
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -s 200,301
+
+# Hide 403/404 noise
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -C 403,404
+
+# POST-based content discovery
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -m POST --data 'action=FUZZ'
+
+# Multiple targets in one run
+feroxbuster -u http://10.10.10.100 -u http://10.10.10.101 -w wordlist.txt
+
+# Pipe a list of live hosts from httpx into a parallel scan
+cat live_hosts.txt | feroxbuster --stdin -w wordlist.txt --silent
+
+# Save both a human log and machine-readable JSON
+feroxbuster -u http://10.10.10.100 -w wordlist.txt -o ferox.txt
+feroxbuster -u http://10.10.10.100 -w wordlist.txt --json -o ferox.json
+```
+
+## FUZZ Keyword
+
+feroxbuster substitutes the `FUZZ` keyword anywhere in the URL, headers, cookies, query, or body — combine with multiple wordlists for positional fuzzing:
+
+```bash
+# Fuzz a path segment
+feroxbuster -u http://10.10.10.100/FUZZ/admin -w wordlist.txt
+
+# Fuzz a query-parameter value
+feroxbuster -u 'http://10.10.10.100/item?id=FUZZ' -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt
+
+# Fuzz a header value
+feroxbuster -u http://10.10.10.100 -H 'X-Forwarded-For: FUZZ' -w ips.txt
+```
+
+## Resume & State Files
+
+Every scan writes a `ferox-<timestamp>.state` file on interruption (`Ctrl-C`) so nothing is lost:
+
+```bash
+# Ctrl-C mid-scan writes ferox-1694781234.state, then:
+feroxbuster --resume-from ferox-1694781234.state
+```
+
+## Config File (`ferox-config.toml`)
+
+Persistent defaults live in `ferox-config.toml`, searched in the current directory, then `~/.config/feroxbuster/`, then `/etc/feroxbuster/`. Generate a documented template:
+
+```bash
+# The repo ships a fully-commented template
+curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/ferox-config.toml.example \
+ -o ~/.config/feroxbuster/ferox-config.toml
+```
+
+```toml
+# ~/.config/feroxbuster/ferox-config.toml
+wordlist = "/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt"
+threads = 50
+depth = 3
+extensions = ["php", "html", "txt", "bak"]
+auto_tune = true
+# status codes to hide by default
+filter_status = [404]
+```
+
+## Recommended Wordlists
+
+| Purpose | Path |
+|---------|------|
+| feroxbuster default | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` |
+| Directories (large) | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` |
+| Files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` |
+| Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` |
+| API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` |
+| Backup/config files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` (add `--collect-backups`) |
+| Kali built-in common | `/usr/share/wordlists/dirb/common.txt` |
+| Kali built-in big | `/usr/share/wordlists/dirb/big.txt` |
+
+## Extension Stacking by Tech Stack
+
+Match `-x` to the detected technology (or let `--collect-extensions` learn them):
+
+```bash
+# PHP: -x php,phps,php5,phtml,inc,bak
+# ASP/.NET: -x asp,aspx,ashx,asmx,config
+# Java: -x jsp,jspx,do,action
+# Node/JS: -x js,json,ts,map
+# Python: -x py,pyc,wsgi
+# Backups: -x bak,old,orig,save,swp,txt,zip,tar.gz (or just --collect-backups)
+```
+
+## Quick Reference — Common Workflows
+
+### HTB / CTF Initial Enumeration
+
+```bash
+# One recursive pass with extensions, collect as you go, gentle auto-tuning
+feroxbuster -u http://target.htb \
+ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
+ -x php,html,txt -C 404 --collect-extensions --auto-tune -o ferox_initial.txt
+```
+
+### Web App Pentest via Burp
+
+```bash
+# Fast scan, but only matched hits land in Burp's proxy history for triage
+feroxbuster -u https://target.com \
+ -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \
+ -x php,bak,old,conf -k -t 80 \
+ --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302,401 \
+ -o ferox_pentest.txt
+```
+
+### Bug Bounty — many hosts, be polite
+
+```bash
+subfinder -d target.com -silent | httpx -silent \
+ | feroxbuster --stdin -w wordlist.txt --rate-limit 15 --auto-tune --auto-bail --silent -o ferox_bb.txt
+```
+
+## Troubleshooting
+
+| Problem | Solution |
+|---------|----------|
+| Everything returns the same status/size (wildcard) | Auto-filtered by default; if not, add `-S`/`-W`/`-N` or `--filter-similar-to <404-url>` |
+| Recursion exploding on a huge directory | Press `Enter`, open the menu, cancel that scan; or pre-empt with `-L` and `-I <regex>` |
+| Flooded with 403s / getting banned | Add `--auto-bail`, lower `--rate-limit`, try `--random-agent` |
+| Scan too slow | Raise `-t` and drop `--rate-limit`; verify `--auto-tune` isn't throttling on errors |
+| TLS / self-signed cert errors | Add `-k` (or `--server-certs ca.pem` to trust a specific CA) |
+| Missing redirected content | Add `-r` to follow 3xx |
+| Soft-404 pages (200 with "not found" text) | `--filter-similar-to` a known bad URL, or `-X 'not found'` regex filter |
+| Lost a long scan to Ctrl-C | `--resume-from ferox-<ts>.state` |
+| Too much noise in Burp | Use `--replay-proxy` + `--replay-codes` instead of `--proxy` |
+
+## feroxbuster vs the Alternatives
+
+| Tool | Language | Key Advantage |
+|------|----------|---------------|
+| **feroxbuster** | Rust | Recursion by default, link extraction, live scan-cancel menu, auto-tune/auto-bail |
+| **ffuf** | Go | Multiple `FUZZ` positions, richest matcher/filter syntax, clusterbomb/pitchfork modes |
+| **gobuster** | Go | Simple, fast, dedicated `dns`/`vhost`/`s3` modes |
+| **dirsearch** | Python | Built-in recursion, smart extension substitution |
+
+## See Also
+
+- **[ffuf](/enumeration/ffuf)** — when you need multi-position fuzzing and advanced matchers.
+- **[gobuster](/enumeration/gobuster)** — when you specifically want DNS/vhost/S3 modes.
+
+Based on feroxbuster v2.11.x — https://github.com/epi052/feroxbuster