daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

feroxbuster.md (16603B)


      1 ---
      2 title: "feroxbuster"
      3 description: "feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters."
      4 category: enumeration
      5 tags: [enumeration, web, brute-force, recursion]
      6 tools: [feroxbuster]
      7 difficulty: beginner
      8 updated: "2026-09-15"
      9 ---
     10 
     11 # feroxbuster
     12 
     13 > **feroxbuster** — Fast, simple, recursive content-discovery tool written in Rust (v2.11.x). Author: Ben "epi" Risher (`@epi052`).
     14 > Key differentiators over `gobuster`/`dirb`: **recursion is on by default**, it **extracts links** from response bodies (HTML/JS/robots.txt) and scans them, auto-filters obvious wildcard/404 responses, and offers an **interactive scan-management menu** while running.
     15 
     16 ## Installation
     17 
     18 ```bash
     19 # Kali / Debian / Ubuntu (repo package)
     20 sudo apt install feroxbuster
     21 
     22 # Cargo (Rust toolchain, always latest)
     23 cargo install feroxbuster
     24 
     25 # Homebrew (macOS / Linuxbrew)
     26 brew install feroxbuster
     27 
     28 # Static binary install script (no root needed, drops ./feroxbuster)
     29 curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash
     30 
     31 # Prebuilt release binary (Linux x86_64)
     32 curl -sL https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-linux-feroxbuster.tar.gz \
     33   | tar -xz && sudo mv feroxbuster /usr/local/bin/
     34 
     35 # Docker
     36 docker run --init -it ghcr.io/epi052/feroxbuster:latest \
     37   -u http://target.com -w /wordlists/common.txt
     38 ```
     39 
     40 ```bash
     41 feroxbuster -h        # concise help
     42 feroxbuster --help    # full help with every flag and default
     43 feroxbuster -V        # version
     44 ```
     45 
     46 ## Quick Start
     47 
     48 ```bash
     49 # The one command you'll run 90% of the time — recursion is automatic
     50 feroxbuster -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
     51 
     52 # With extensions and a saved log
     53 feroxbuster -u http://10.10.10.100 \
     54   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
     55   -x php,html,txt -o ferox.txt
     56 ```
     57 
     58 ## Core Flags
     59 
     60 | Flag | Short | Description |
     61 |------|-------|-------------|
     62 | `--url <url>` | `-u` | Target URL. **Repeatable** — pass `-u` multiple times to scan several targets |
     63 | `--wordlist <path>` | `-w` | Wordlist path (default: `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt`) |
     64 | `--threads <int>` | `-t` | Total number of concurrent threads (default: `50`) |
     65 | `--depth <int>` | `-d` | Maximum recursion depth; `0` means recurse infinitely (default: `4`) |
     66 | `--extensions <exts>` | `-x` | Extensions to append, comma-separated (`php,html,txt`). Use `-x tar.gz` etc. for multi-part |
     67 | `--methods <methods>` | `-m` | HTTP methods to try, comma-separated (default: `GET`) |
     68 | `--data <data>` | | Request body to send (e.g. for `POST`); accepts `@file` to read from a file |
     69 | `--stdin` | | Read the target URL(s) from STDIN instead of `-u` |
     70 | `--output <file>` | `-o` | Write results to a file (plain text, or JSON with `--json`) |
     71 | `--json` | | Emit newline-delimited JSON (great for piping / jq) |
     72 | `--silent` | | Machine-readable output only — URLs, no banner or progress (ideal for piping) |
     73 | `--quiet` | `-q` | Suppress the progress bars and banner but keep status lines |
     74 | `--verbosity` | `-v` | Increase log verbosity (`-v`, `-vv`, `-vvvv`) |
     75 | `--no-recursion` | `-n` | Disable recursion entirely (behave like gobuster `dir`) |
     76 | `--add-slash` | `-f` | Append `/` to each word (find directories that only answer with a trailing slash) |
     77 | `--resume-from <state>` | | Resume a previous scan from its `ferox-<ts>.state` file |
     78 
     79 ## HTTP / Request Flags
     80 
     81 | Flag | Short | Description |
     82 |------|-------|-------------|
     83 | `--headers <header>` | `-H` | Custom header, repeatable (`-H 'Authorization: Bearer …' -H 'X-Api: 1'`) |
     84 | `--cookies <cookie>` | `-b` | Cookie(s) to send, repeatable (`-b 'PHPSESSID=abc'`) |
     85 | `--query <param>` | `-Q` | Query-string parameter, repeatable (`-Q 'debug=1'`) |
     86 | `--user-agent <string>` | `-a` | Set the User-Agent (default: `feroxbuster/<version>`) |
     87 | `--random-agent` | `-A` | Pick a random User-Agent per scan from a built-in list |
     88 | `--redirects` | `-r` | Follow 3xx redirects (off by default — 301/302 are reported, not followed) |
     89 | `--insecure` | `-k` | Disable TLS certificate validation |
     90 | `--proxy <url>` | `-p` | Proxy all traffic (`http://127.0.0.1:8080`, `socks5://127.0.0.1:1080`) |
     91 | `--replay-proxy <url>` | `-P` | Send **only matched** responses to a second proxy (e.g. Burp) to cut noise |
     92 | `--replay-codes <codes>` | `-R` | Status codes that get sent to the replay proxy (default: your match codes) |
     93 | `--burp` | | Shortcut for `--proxy http://127.0.0.1:8080 --insecure` |
     94 | `--burp-replay` | | Shortcut for `--replay-proxy http://127.0.0.1:8080 --insecure` |
     95 | `--server-certs <pem>` | | Trust a custom CA / self-signed server cert (repeatable) |
     96 | `--client-cert <pem>` | | Client certificate for mTLS |
     97 | `--client-key <pem>` | | Client private key for mTLS |
     98 | `--timeout <secs>` | `-T` | Per-request timeout in seconds (default: `7`) |
     99 
    100 ## Status Codes, Matchers & Filters
    101 
    102 feroxbuster's real power is filtering. By default it reports status codes `200-299, 301, 302, 307, 308, 401, 403, 405` and auto-filters wildcard responses. Tune with:
    103 
    104 | Flag | Short | Description |
    105 |------|-------|-------------|
    106 | `--status-codes <codes>` | `-s` | Whitelist: only report these status codes (space/comma separated) |
    107 | `--filter-status <codes>` | `-C` | Blacklist: hide these status codes (e.g. `-C 404,403`) |
    108 | `--filter-size <bytes>` | `-S` | Hide responses of exactly these byte sizes (repeatable) |
    109 | `--filter-words <count>` | `-W` | Hide responses with this many words |
    110 | `--filter-lines <count>` | `-N` | Hide responses with this many lines |
    111 | `--filter-regex <regex>` | `-X` | Hide responses whose body matches this regex |
    112 | `--filter-similar-to <url>` | | Hide responses fuzzy-similar (ssdeep) to a known page — kills soft-404s |
    113 | `--dont-filter` | | Turn OFF wildcard/auto filtering (report literally everything) |
    114 
    115 > **Workflow — kill false positives fast:** Run once, spot a repeating bogus size/word/line count in the output, then re-run adding `-S <size>` / `-W <words>` / `-N <lines>`. For soft-404 pages that vary in size, `--filter-similar-to http://target/definitely-404-page` is the sharpest tool.
    116 
    117 ## Recursion Control
    118 
    119 | Flag | Description |
    120 |------|-------------|
    121 | `-n`, `--no-recursion` | Disable recursion completely |
    122 | `-d`, `--depth <int>` | Cap recursion depth (`0` = unlimited; default `4`) |
    123 | `--force-recursion` | Recurse into every discovered URL even without a trailing slash / not obviously a directory |
    124 | `-L`, `--scan-limit <int>` | Max number of directory scans running concurrently (throttles a recursion explosion) |
    125 | `-I`, `--dont-scan <regex>` | Skip URLs matching this regex, repeatable (e.g. `-I 'logout' -I '\.js$'`) |
    126 
    127 ```bash
    128 # Deep but controlled: unlimited depth, but only 3 directories scanned at once
    129 feroxbuster -u http://target -w wordlist.txt -d 0 -L 3
    130 
    131 # Recurse everywhere, but never into logout or static asset paths
    132 feroxbuster -u http://target -w wordlist.txt --force-recursion -I 'logout' -I '\.(js|css|png|jpg)$'
    133 ```
    134 
    135 ## Link Extraction & Collection
    136 
    137 feroxbuster parses response bodies and pulls out more targets automatically:
    138 
    139 | Flag | Short | Description |
    140 |------|-------|-------------|
    141 | `--extract-links` | `-e` | Parse HTML/JS/`robots.txt` for links and scan them (on by default in recent builds; flag forces it) |
    142 | `--dont-extract-links` | | Turn link extraction off |
    143 | `--scan-dir-listings` | | Also brute-force inside auto-indexed (`Index of /`) directory listings |
    144 | `--collect-extensions` | | Learn extensions seen in responses and add them to the scan on the fly |
    145 | `--collect-backups` | | On each found page, also request backup variants (`.bak`, `~`, `.old`, …) |
    146 | `--collect-words` | | Harvest words from responses and add them to the wordlist mid-scan |
    147 
    148 ```bash
    149 # "Just find everything" mode — collect extensions, backups, and words as it goes
    150 feroxbuster -u http://target -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
    151   --collect-extensions --collect-backups --collect-words
    152 ```
    153 
    154 ## Performance & Stealth
    155 
    156 | Flag | Short | Description |
    157 |------|-------|-------------|
    158 | `--threads <int>` | `-t` | Concurrent threads (default `50`) |
    159 | `--rate-limit <int>` | | Cap requests **per second** per directory scan |
    160 | `--scan-limit <int>` | `-L` | Concurrent directory scans |
    161 | `--time-limit <spec>` | | Stop after a duration (`10m`, `1h`, `30s`) |
    162 | `--auto-tune` | | Automatically slow down when the server starts erroring, then speed back up |
    163 | `--auto-bail` | | Abort a scan that trips too many errors/timeouts/403s (guards against WAF bans) |
    164 | `--smart` | | Preset: `--auto-tune --collect-words --collect-backups --extract-links` |
    165 | `--thorough` | | Preset: everything `--smart` does plus `--collect-extensions --scan-dir-listings` |
    166 
    167 ```bash
    168 # Gentle scan against a rate-limited / WAF'd target
    169 feroxbuster -u http://target -w wordlist.txt --rate-limit 20 --auto-tune --auto-bail
    170 
    171 # Aggressive but self-throttling one-liner
    172 feroxbuster -u http://target -w wordlist.txt --thorough --auto-tune
    173 ```
    174 
    175 ## Interactive Scan Menu
    176 
    177 While a scan is running, press **`Enter`** to open the interactive menu. From there you can:
    178 
    179 - List all active recursive scans with their IDs.
    180 - **Cancel** a runaway scan (e.g. a huge auto-indexed directory) without killing the whole run: type the scan number(s) and confirm.
    181 - Cancelled scans are pruned so the rest of the run continues.
    182 
    183 This is the main reason to prefer feroxbuster on messy targets — you prune noisy recursion live instead of restarting.
    184 
    185 ## Practical Examples
    186 
    187 ```bash
    188 # Basic recursive scan with extensions
    189 feroxbuster -u http://10.10.10.100 \
    190   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
    191   -x php,html,txt
    192 
    193 # Authenticated scan (session cookie + bearer token)
    194 feroxbuster -u http://10.10.10.100 \
    195   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
    196   -b 'PHPSESSID=abc123def456' -H 'Authorization: Bearer eyJhbGciOi...'
    197 
    198 # Over HTTPS with a bad cert, following redirects
    199 feroxbuster -u https://10.10.10.100 -w wordlist.txt -k -r
    200 
    201 # Proxy everything through Burp
    202 feroxbuster -u http://10.10.10.100 -w wordlist.txt --burp
    203 
    204 # Scan fast, but replay only interesting hits to Burp
    205 feroxbuster -u http://10.10.10.100 -w wordlist.txt -t 100 \
    206   --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302
    207 
    208 # Filter out a soft-404 baseline (page is 200 but always ~1274 bytes / 96 words)
    209 feroxbuster -u http://10.10.10.100 -w wordlist.txt -S 1274 -W 96
    210 
    211 # Only show 200s and 301s
    212 feroxbuster -u http://10.10.10.100 -w wordlist.txt -s 200,301
    213 
    214 # Hide 403/404 noise
    215 feroxbuster -u http://10.10.10.100 -w wordlist.txt -C 403,404
    216 
    217 # POST-based content discovery
    218 feroxbuster -u http://10.10.10.100 -w wordlist.txt -m POST --data 'action=FUZZ'
    219 
    220 # Multiple targets in one run
    221 feroxbuster -u http://10.10.10.100 -u http://10.10.10.101 -w wordlist.txt
    222 
    223 # Pipe a list of live hosts from httpx into a parallel scan
    224 cat live_hosts.txt | feroxbuster --stdin -w wordlist.txt --silent
    225 
    226 # Save both a human log and machine-readable JSON
    227 feroxbuster -u http://10.10.10.100 -w wordlist.txt -o ferox.txt
    228 feroxbuster -u http://10.10.10.100 -w wordlist.txt --json -o ferox.json
    229 ```
    230 
    231 ## FUZZ Keyword
    232 
    233 feroxbuster substitutes the `FUZZ` keyword anywhere in the URL, headers, cookies, query, or body — combine with multiple wordlists for positional fuzzing:
    234 
    235 ```bash
    236 # Fuzz a path segment
    237 feroxbuster -u http://10.10.10.100/FUZZ/admin -w wordlist.txt
    238 
    239 # Fuzz a query-parameter value
    240 feroxbuster -u 'http://10.10.10.100/item?id=FUZZ' -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt
    241 
    242 # Fuzz a header value
    243 feroxbuster -u http://10.10.10.100 -H 'X-Forwarded-For: FUZZ' -w ips.txt
    244 ```
    245 
    246 ## Resume & State Files
    247 
    248 Every scan writes a `ferox-<timestamp>.state` file on interruption (`Ctrl-C`) so nothing is lost:
    249 
    250 ```bash
    251 # Ctrl-C mid-scan writes ferox-1694781234.state, then:
    252 feroxbuster --resume-from ferox-1694781234.state
    253 ```
    254 
    255 ## Config File (`ferox-config.toml`)
    256 
    257 Persistent defaults live in `ferox-config.toml`, searched in the current directory, then `~/.config/feroxbuster/`, then `/etc/feroxbuster/`. Generate a documented template:
    258 
    259 ```bash
    260 # The repo ships a fully-commented template
    261 curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/ferox-config.toml.example \
    262   -o ~/.config/feroxbuster/ferox-config.toml
    263 ```
    264 
    265 ```toml
    266 # ~/.config/feroxbuster/ferox-config.toml
    267 wordlist = "/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt"
    268 threads  = 50
    269 depth    = 3
    270 extensions = ["php", "html", "txt", "bak"]
    271 auto_tune  = true
    272 # status codes to hide by default
    273 filter_status = [404]
    274 ```
    275 
    276 ## Recommended Wordlists
    277 
    278 | Purpose | Path |
    279 |---------|------|
    280 | feroxbuster default | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` |
    281 | Directories (large) | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` |
    282 | Files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` |
    283 | Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` |
    284 | API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` |
    285 | Backup/config files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` (add `--collect-backups`) |
    286 | Kali built-in common | `/usr/share/wordlists/dirb/common.txt` |
    287 | Kali built-in big | `/usr/share/wordlists/dirb/big.txt` |
    288 
    289 ## Extension Stacking by Tech Stack
    290 
    291 Match `-x` to the detected technology (or let `--collect-extensions` learn them):
    292 
    293 ```bash
    294 # PHP:       -x php,phps,php5,phtml,inc,bak
    295 # ASP/.NET:  -x asp,aspx,ashx,asmx,config
    296 # Java:      -x jsp,jspx,do,action
    297 # Node/JS:   -x js,json,ts,map
    298 # Python:    -x py,pyc,wsgi
    299 # Backups:   -x bak,old,orig,save,swp,txt,zip,tar.gz   (or just --collect-backups)
    300 ```
    301 
    302 ## Quick Reference — Common Workflows
    303 
    304 ### HTB / CTF Initial Enumeration
    305 
    306 ```bash
    307 # One recursive pass with extensions, collect as you go, gentle auto-tuning
    308 feroxbuster -u http://target.htb \
    309   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
    310   -x php,html,txt -C 404 --collect-extensions --auto-tune -o ferox_initial.txt
    311 ```
    312 
    313 ### Web App Pentest via Burp
    314 
    315 ```bash
    316 # Fast scan, but only matched hits land in Burp's proxy history for triage
    317 feroxbuster -u https://target.com \
    318   -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \
    319   -x php,bak,old,conf -k -t 80 \
    320   --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302,401 \
    321   -o ferox_pentest.txt
    322 ```
    323 
    324 ### Bug Bounty — many hosts, be polite
    325 
    326 ```bash
    327 subfinder -d target.com -silent | httpx -silent \
    328   | feroxbuster --stdin -w wordlist.txt --rate-limit 15 --auto-tune --auto-bail --silent -o ferox_bb.txt
    329 ```
    330 
    331 ## Troubleshooting
    332 
    333 | Problem | Solution |
    334 |---------|----------|
    335 | Everything returns the same status/size (wildcard) | Auto-filtered by default; if not, add `-S`/`-W`/`-N` or `--filter-similar-to <404-url>` |
    336 | Recursion exploding on a huge directory | Press `Enter`, open the menu, cancel that scan; or pre-empt with `-L` and `-I <regex>` |
    337 | Flooded with 403s / getting banned | Add `--auto-bail`, lower `--rate-limit`, try `--random-agent` |
    338 | Scan too slow | Raise `-t` and drop `--rate-limit`; verify `--auto-tune` isn't throttling on errors |
    339 | TLS / self-signed cert errors | Add `-k` (or `--server-certs ca.pem` to trust a specific CA) |
    340 | Missing redirected content | Add `-r` to follow 3xx |
    341 | Soft-404 pages (200 with "not found" text) | `--filter-similar-to` a known bad URL, or `-X 'not found'` regex filter |
    342 | Lost a long scan to Ctrl-C | `--resume-from ferox-<ts>.state` |
    343 | Too much noise in Burp | Use `--replay-proxy` + `--replay-codes` instead of `--proxy` |
    344 
    345 ## feroxbuster vs the Alternatives
    346 
    347 | Tool | Language | Key Advantage |
    348 |------|----------|---------------|
    349 | **feroxbuster** | Rust | Recursion by default, link extraction, live scan-cancel menu, auto-tune/auto-bail |
    350 | **ffuf** | Go | Multiple `FUZZ` positions, richest matcher/filter syntax, clusterbomb/pitchfork modes |
    351 | **gobuster** | Go | Simple, fast, dedicated `dns`/`vhost`/`s3` modes |
    352 | **dirsearch** | Python | Built-in recursion, smart extension substitution |
    353 
    354 ## See Also
    355 
    356 - **[ffuf](/enumeration/ffuf)** — when you need multi-position fuzzing and advanced matchers.
    357 - **[gobuster](/enumeration/gobuster)** — when you specifically want DNS/vhost/S3 modes.
    358 
    359 Based on feroxbuster v2.11.x — https://github.com/epi052/feroxbuster