daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 0a4129cb337fbf1b2094906d0a7bfaddf74377d1
parent a5a5703a1f2d2232fb856b55e0ef2bfe5ee1c656
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Tue, 15 Sep 2026 01:59:07 +0100

feat: add detailed feroxbuster content-discovery cheatsheet

New enumeration sheet covering feroxbuster v2.11.x: install methods,
core/HTTP/recursion flags, matchers and filters, link extraction and
collection, performance/stealth (auto-tune, auto-bail, rate-limit),
the interactive scan menu, FUZZ keyword, resume/state files, config
file, wordlists, and CTF/pentest/bug-bounty workflows.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LGt1BFBCTS16MDy6Vewoxe

Diffstat:
Asrc/content/sheets/enumeration/feroxbuster.md | 359+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 359 insertions(+), 0 deletions(-)

diff --git a/src/content/sheets/enumeration/feroxbuster.md b/src/content/sheets/enumeration/feroxbuster.md @@ -0,0 +1,359 @@ +--- +title: "feroxbuster" +description: "feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters." +category: enumeration +tags: [enumeration, web, brute-force, recursion] +tools: [feroxbuster] +difficulty: beginner +updated: "2026-09-15" +--- + +# feroxbuster + +> **feroxbuster** — Fast, simple, recursive content-discovery tool written in Rust (v2.11.x). Author: Ben "epi" Risher (`@epi052`). +> Key differentiators over `gobuster`/`dirb`: **recursion is on by default**, it **extracts links** from response bodies (HTML/JS/robots.txt) and scans them, auto-filters obvious wildcard/404 responses, and offers an **interactive scan-management menu** while running. + +## Installation + +```bash +# Kali / Debian / Ubuntu (repo package) +sudo apt install feroxbuster + +# Cargo (Rust toolchain, always latest) +cargo install feroxbuster + +# Homebrew (macOS / Linuxbrew) +brew install feroxbuster + +# Static binary install script (no root needed, drops ./feroxbuster) +curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash + +# Prebuilt release binary (Linux x86_64) +curl -sL https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-linux-feroxbuster.tar.gz \ + | tar -xz && sudo mv feroxbuster /usr/local/bin/ + +# Docker +docker run --init -it ghcr.io/epi052/feroxbuster:latest \ + -u http://target.com -w /wordlists/common.txt +``` + +```bash +feroxbuster -h # concise help +feroxbuster --help # full help with every flag and default +feroxbuster -V # version +``` + +## Quick Start + +```bash +# The one command you'll run 90% of the time — recursion is automatic +feroxbuster -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt + +# With extensions and a saved log +feroxbuster -u http://10.10.10.100 \ + -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ + -x php,html,txt -o ferox.txt +``` + +## Core Flags + +| Flag | Short | Description | +|------|-------|-------------| +| `--url <url>` | `-u` | Target URL. **Repeatable** — pass `-u` multiple times to scan several targets | +| `--wordlist <path>` | `-w` | Wordlist path (default: `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt`) | +| `--threads <int>` | `-t` | Total number of concurrent threads (default: `50`) | +| `--depth <int>` | `-d` | Maximum recursion depth; `0` means recurse infinitely (default: `4`) | +| `--extensions <exts>` | `-x` | Extensions to append, comma-separated (`php,html,txt`). Use `-x tar.gz` etc. for multi-part | +| `--methods <methods>` | `-m` | HTTP methods to try, comma-separated (default: `GET`) | +| `--data <data>` | | Request body to send (e.g. for `POST`); accepts `@file` to read from a file | +| `--stdin` | | Read the target URL(s) from STDIN instead of `-u` | +| `--output <file>` | `-o` | Write results to a file (plain text, or JSON with `--json`) | +| `--json` | | Emit newline-delimited JSON (great for piping / jq) | +| `--silent` | | Machine-readable output only — URLs, no banner or progress (ideal for piping) | +| `--quiet` | `-q` | Suppress the progress bars and banner but keep status lines | +| `--verbosity` | `-v` | Increase log verbosity (`-v`, `-vv`, `-vvvv`) | +| `--no-recursion` | `-n` | Disable recursion entirely (behave like gobuster `dir`) | +| `--add-slash` | `-f` | Append `/` to each word (find directories that only answer with a trailing slash) | +| `--resume-from <state>` | | Resume a previous scan from its `ferox-<ts>.state` file | + +## HTTP / Request Flags + +| Flag | Short | Description | +|------|-------|-------------| +| `--headers <header>` | `-H` | Custom header, repeatable (`-H 'Authorization: Bearer …' -H 'X-Api: 1'`) | +| `--cookies <cookie>` | `-b` | Cookie(s) to send, repeatable (`-b 'PHPSESSID=abc'`) | +| `--query <param>` | `-Q` | Query-string parameter, repeatable (`-Q 'debug=1'`) | +| `--user-agent <string>` | `-a` | Set the User-Agent (default: `feroxbuster/<version>`) | +| `--random-agent` | `-A` | Pick a random User-Agent per scan from a built-in list | +| `--redirects` | `-r` | Follow 3xx redirects (off by default — 301/302 are reported, not followed) | +| `--insecure` | `-k` | Disable TLS certificate validation | +| `--proxy <url>` | `-p` | Proxy all traffic (`http://127.0.0.1:8080`, `socks5://127.0.0.1:1080`) | +| `--replay-proxy <url>` | `-P` | Send **only matched** responses to a second proxy (e.g. Burp) to cut noise | +| `--replay-codes <codes>` | `-R` | Status codes that get sent to the replay proxy (default: your match codes) | +| `--burp` | | Shortcut for `--proxy http://127.0.0.1:8080 --insecure` | +| `--burp-replay` | | Shortcut for `--replay-proxy http://127.0.0.1:8080 --insecure` | +| `--server-certs <pem>` | | Trust a custom CA / self-signed server cert (repeatable) | +| `--client-cert <pem>` | | Client certificate for mTLS | +| `--client-key <pem>` | | Client private key for mTLS | +| `--timeout <secs>` | `-T` | Per-request timeout in seconds (default: `7`) | + +## Status Codes, Matchers & Filters + +feroxbuster's real power is filtering. By default it reports status codes `200-299, 301, 302, 307, 308, 401, 403, 405` and auto-filters wildcard responses. Tune with: + +| Flag | Short | Description | +|------|-------|-------------| +| `--status-codes <codes>` | `-s` | Whitelist: only report these status codes (space/comma separated) | +| `--filter-status <codes>` | `-C` | Blacklist: hide these status codes (e.g. `-C 404,403`) | +| `--filter-size <bytes>` | `-S` | Hide responses of exactly these byte sizes (repeatable) | +| `--filter-words <count>` | `-W` | Hide responses with this many words | +| `--filter-lines <count>` | `-N` | Hide responses with this many lines | +| `--filter-regex <regex>` | `-X` | Hide responses whose body matches this regex | +| `--filter-similar-to <url>` | | Hide responses fuzzy-similar (ssdeep) to a known page — kills soft-404s | +| `--dont-filter` | | Turn OFF wildcard/auto filtering (report literally everything) | + +> **Workflow — kill false positives fast:** Run once, spot a repeating bogus size/word/line count in the output, then re-run adding `-S <size>` / `-W <words>` / `-N <lines>`. For soft-404 pages that vary in size, `--filter-similar-to http://target/definitely-404-page` is the sharpest tool. + +## Recursion Control + +| Flag | Description | +|------|-------------| +| `-n`, `--no-recursion` | Disable recursion completely | +| `-d`, `--depth <int>` | Cap recursion depth (`0` = unlimited; default `4`) | +| `--force-recursion` | Recurse into every discovered URL even without a trailing slash / not obviously a directory | +| `-L`, `--scan-limit <int>` | Max number of directory scans running concurrently (throttles a recursion explosion) | +| `-I`, `--dont-scan <regex>` | Skip URLs matching this regex, repeatable (e.g. `-I 'logout' -I '\.js$'`) | + +```bash +# Deep but controlled: unlimited depth, but only 3 directories scanned at once +feroxbuster -u http://target -w wordlist.txt -d 0 -L 3 + +# Recurse everywhere, but never into logout or static asset paths +feroxbuster -u http://target -w wordlist.txt --force-recursion -I 'logout' -I '\.(js|css|png|jpg)$' +``` + +## Link Extraction & Collection + +feroxbuster parses response bodies and pulls out more targets automatically: + +| Flag | Short | Description | +|------|-------|-------------| +| `--extract-links` | `-e` | Parse HTML/JS/`robots.txt` for links and scan them (on by default in recent builds; flag forces it) | +| `--dont-extract-links` | | Turn link extraction off | +| `--scan-dir-listings` | | Also brute-force inside auto-indexed (`Index of /`) directory listings | +| `--collect-extensions` | | Learn extensions seen in responses and add them to the scan on the fly | +| `--collect-backups` | | On each found page, also request backup variants (`.bak`, `~`, `.old`, …) | +| `--collect-words` | | Harvest words from responses and add them to the wordlist mid-scan | + +```bash +# "Just find everything" mode — collect extensions, backups, and words as it goes +feroxbuster -u http://target -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ + --collect-extensions --collect-backups --collect-words +``` + +## Performance & Stealth + +| Flag | Short | Description | +|------|-------|-------------| +| `--threads <int>` | `-t` | Concurrent threads (default `50`) | +| `--rate-limit <int>` | | Cap requests **per second** per directory scan | +| `--scan-limit <int>` | `-L` | Concurrent directory scans | +| `--time-limit <spec>` | | Stop after a duration (`10m`, `1h`, `30s`) | +| `--auto-tune` | | Automatically slow down when the server starts erroring, then speed back up | +| `--auto-bail` | | Abort a scan that trips too many errors/timeouts/403s (guards against WAF bans) | +| `--smart` | | Preset: `--auto-tune --collect-words --collect-backups --extract-links` | +| `--thorough` | | Preset: everything `--smart` does plus `--collect-extensions --scan-dir-listings` | + +```bash +# Gentle scan against a rate-limited / WAF'd target +feroxbuster -u http://target -w wordlist.txt --rate-limit 20 --auto-tune --auto-bail + +# Aggressive but self-throttling one-liner +feroxbuster -u http://target -w wordlist.txt --thorough --auto-tune +``` + +## Interactive Scan Menu + +While a scan is running, press **`Enter`** to open the interactive menu. From there you can: + +- List all active recursive scans with their IDs. +- **Cancel** a runaway scan (e.g. a huge auto-indexed directory) without killing the whole run: type the scan number(s) and confirm. +- Cancelled scans are pruned so the rest of the run continues. + +This is the main reason to prefer feroxbuster on messy targets — you prune noisy recursion live instead of restarting. + +## Practical Examples + +```bash +# Basic recursive scan with extensions +feroxbuster -u http://10.10.10.100 \ + -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ + -x php,html,txt + +# Authenticated scan (session cookie + bearer token) +feroxbuster -u http://10.10.10.100 \ + -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ + -b 'PHPSESSID=abc123def456' -H 'Authorization: Bearer eyJhbGciOi...' + +# Over HTTPS with a bad cert, following redirects +feroxbuster -u https://10.10.10.100 -w wordlist.txt -k -r + +# Proxy everything through Burp +feroxbuster -u http://10.10.10.100 -w wordlist.txt --burp + +# Scan fast, but replay only interesting hits to Burp +feroxbuster -u http://10.10.10.100 -w wordlist.txt -t 100 \ + --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302 + +# Filter out a soft-404 baseline (page is 200 but always ~1274 bytes / 96 words) +feroxbuster -u http://10.10.10.100 -w wordlist.txt -S 1274 -W 96 + +# Only show 200s and 301s +feroxbuster -u http://10.10.10.100 -w wordlist.txt -s 200,301 + +# Hide 403/404 noise +feroxbuster -u http://10.10.10.100 -w wordlist.txt -C 403,404 + +# POST-based content discovery +feroxbuster -u http://10.10.10.100 -w wordlist.txt -m POST --data 'action=FUZZ' + +# Multiple targets in one run +feroxbuster -u http://10.10.10.100 -u http://10.10.10.101 -w wordlist.txt + +# Pipe a list of live hosts from httpx into a parallel scan +cat live_hosts.txt | feroxbuster --stdin -w wordlist.txt --silent + +# Save both a human log and machine-readable JSON +feroxbuster -u http://10.10.10.100 -w wordlist.txt -o ferox.txt +feroxbuster -u http://10.10.10.100 -w wordlist.txt --json -o ferox.json +``` + +## FUZZ Keyword + +feroxbuster substitutes the `FUZZ` keyword anywhere in the URL, headers, cookies, query, or body — combine with multiple wordlists for positional fuzzing: + +```bash +# Fuzz a path segment +feroxbuster -u http://10.10.10.100/FUZZ/admin -w wordlist.txt + +# Fuzz a query-parameter value +feroxbuster -u 'http://10.10.10.100/item?id=FUZZ' -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt + +# Fuzz a header value +feroxbuster -u http://10.10.10.100 -H 'X-Forwarded-For: FUZZ' -w ips.txt +``` + +## Resume & State Files + +Every scan writes a `ferox-<timestamp>.state` file on interruption (`Ctrl-C`) so nothing is lost: + +```bash +# Ctrl-C mid-scan writes ferox-1694781234.state, then: +feroxbuster --resume-from ferox-1694781234.state +``` + +## Config File (`ferox-config.toml`) + +Persistent defaults live in `ferox-config.toml`, searched in the current directory, then `~/.config/feroxbuster/`, then `/etc/feroxbuster/`. Generate a documented template: + +```bash +# The repo ships a fully-commented template +curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/ferox-config.toml.example \ + -o ~/.config/feroxbuster/ferox-config.toml +``` + +```toml +# ~/.config/feroxbuster/ferox-config.toml +wordlist = "/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt" +threads = 50 +depth = 3 +extensions = ["php", "html", "txt", "bak"] +auto_tune = true +# status codes to hide by default +filter_status = [404] +``` + +## Recommended Wordlists + +| Purpose | Path | +|---------|------| +| feroxbuster default | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` | +| Directories (large) | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` | +| Files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` | +| Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` | +| API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` | +| Backup/config files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` (add `--collect-backups`) | +| Kali built-in common | `/usr/share/wordlists/dirb/common.txt` | +| Kali built-in big | `/usr/share/wordlists/dirb/big.txt` | + +## Extension Stacking by Tech Stack + +Match `-x` to the detected technology (or let `--collect-extensions` learn them): + +```bash +# PHP: -x php,phps,php5,phtml,inc,bak +# ASP/.NET: -x asp,aspx,ashx,asmx,config +# Java: -x jsp,jspx,do,action +# Node/JS: -x js,json,ts,map +# Python: -x py,pyc,wsgi +# Backups: -x bak,old,orig,save,swp,txt,zip,tar.gz (or just --collect-backups) +``` + +## Quick Reference — Common Workflows + +### HTB / CTF Initial Enumeration + +```bash +# One recursive pass with extensions, collect as you go, gentle auto-tuning +feroxbuster -u http://target.htb \ + -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ + -x php,html,txt -C 404 --collect-extensions --auto-tune -o ferox_initial.txt +``` + +### Web App Pentest via Burp + +```bash +# Fast scan, but only matched hits land in Burp's proxy history for triage +feroxbuster -u https://target.com \ + -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \ + -x php,bak,old,conf -k -t 80 \ + --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302,401 \ + -o ferox_pentest.txt +``` + +### Bug Bounty — many hosts, be polite + +```bash +subfinder -d target.com -silent | httpx -silent \ + | feroxbuster --stdin -w wordlist.txt --rate-limit 15 --auto-tune --auto-bail --silent -o ferox_bb.txt +``` + +## Troubleshooting + +| Problem | Solution | +|---------|----------| +| Everything returns the same status/size (wildcard) | Auto-filtered by default; if not, add `-S`/`-W`/`-N` or `--filter-similar-to <404-url>` | +| Recursion exploding on a huge directory | Press `Enter`, open the menu, cancel that scan; or pre-empt with `-L` and `-I <regex>` | +| Flooded with 403s / getting banned | Add `--auto-bail`, lower `--rate-limit`, try `--random-agent` | +| Scan too slow | Raise `-t` and drop `--rate-limit`; verify `--auto-tune` isn't throttling on errors | +| TLS / self-signed cert errors | Add `-k` (or `--server-certs ca.pem` to trust a specific CA) | +| Missing redirected content | Add `-r` to follow 3xx | +| Soft-404 pages (200 with "not found" text) | `--filter-similar-to` a known bad URL, or `-X 'not found'` regex filter | +| Lost a long scan to Ctrl-C | `--resume-from ferox-<ts>.state` | +| Too much noise in Burp | Use `--replay-proxy` + `--replay-codes` instead of `--proxy` | + +## feroxbuster vs the Alternatives + +| Tool | Language | Key Advantage | +|------|----------|---------------| +| **feroxbuster** | Rust | Recursion by default, link extraction, live scan-cancel menu, auto-tune/auto-bail | +| **ffuf** | Go | Multiple `FUZZ` positions, richest matcher/filter syntax, clusterbomb/pitchfork modes | +| **gobuster** | Go | Simple, fast, dedicated `dns`/`vhost`/`s3` modes | +| **dirsearch** | Python | Built-in recursion, smart extension substitution | + +## See Also + +- **[ffuf](/enumeration/ffuf)** — when you need multi-position fuzzing and advanced matchers. +- **[gobuster](/enumeration/gobuster)** — when you specifically want DNS/vhost/S3 modes. + +Based on feroxbuster v2.11.x — https://github.com/epi052/feroxbuster