daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

eyewitness.md (12205B)


      1 ---
      2 title: "EyeWitness"
      3 description: "EyeWitness bulk web/RDP/VNC screenshotting and reporting for rapid visual recon."
      4 category: tools
      5 tags: [recon, screenshots, web]
      6 tools: [EyeWitness]
      7 difficulty: beginner
      8 updated: "2026-08-09"
      9 source: "vault:Tools/EyeWitness-Cheatsheet.md"
     10 ---
     11 
     12 # EyeWitness Cheatsheet
     13 
     14 > **Author**: Netrunner | **Last Updated**: 2026-08-06 | **Context**: HTB Pro Labs, CTF, authorised pentesting | **Tool**: [EyeWitness](https://github.com/RedSiege/EyeWitness) (CLI reference)
     15 
     16 Web screenshot / recon CLI reference for authorised assessments. Flags below were checked against the [RedSiege/EyeWitness](https://github.com/RedSiege/EyeWitness) README and `Python/EyeWitness.py` argument parser — nothing invented.
     17 
     18 Related notes: Nuclei-Cheatsheet · Ffuf-Cheatsheet · webfuzz · NetExec-Cheatsheet
     19 
     20 ---
     21 
     22 ## Table of Contents
     23 
     24 1. [Summary](#summary)
     25 2. [Project Status & Alternatives](#project-status--alternatives)
     26 3. [Quick-Reference Flag Table](#quick-reference-flag-table)
     27 4. [Installation](#installation)
     28 5. [Basic Usage](#basic-usage)
     29 6. [Input Formats](#input-formats)
     30 7. [Timing, Proxy & Browser Options](#timing-proxy--browser-options)
     31 8. [Resume & Config](#resume--config)
     32 9. [Output Layout](#output-layout)
     33 10. [Practical Recipes](#practical-recipes)
     34 11. [Alternatives (gowitness / aquatone / httpx)](#alternatives-gowitness--aquatone--httpx)
     35 12. [Troubleshooting & Gotchas](#troubleshooting--gotchas)
     36 13. [Lessons Learned](#lessons-learned)
     37 14. [References](#references)
     38 
     39 ---
     40 
     41 ## Summary
     42 
     43 [EyeWitness](https://github.com/RedSiege/EyeWitness) takes screenshots of HTTP(S) targets, records response headers/source, and attempts to flag known default credentials. It is useful after host/URL discovery (nmap, httpx, masscan) when you need a visual triage of large web attack surfaces. Modern builds use **Chromium/Chrome + Selenium**, install into an isolated **Python venv**, and support text URL lists, Nmap/Nessus XML, single-URL mode, and resume via SQLite (`ew.db`).
     44 
     45 > **Note —** + Authorised-use framing
     46 > `fas:TriangleExclamation`
     47 > 1. Only run against systems you own or have written authorisation to assess.
     48 > 2. Screenshot tools generate significant browser/CPU load — tune `--threads` and timeouts on fragile lab targets.
     49 > 3. Proxy through Burp/ZAP when you need request inspection (`--proxy-ip` / `--proxy-port`).
     50 
     51 ---
     52 
     53 ## Project Status & Alternatives
     54 
     55 | Tool | Status (as of 2026) | Notes |
     56 |---|---|---|
     57 | **EyeWitness** (RedSiege) | **Actively maintained** | Formerly FortyNorthSecurity; Chromium-powered rewrite with venv install |
     58 | **gowitness** | Actively maintained | Go, fast, good for large lists |
     59 | **aquatone** | **Archived / unmaintained** | Still seen in older writeups; prefer gowitness or EyeWitness |
     60 | **httpx `-screenshot`** | Actively maintained | Lightweight screenshots in the ProjectDiscovery pipeline |
     61 
     62 > **Note —** + When to pick what
     63 > `fas:Lightbulb`
     64 > 1. **EyeWitness**: HTML report + default-cred hints + Nmap/Nessus XML ingest.
     65 > 2. **gowitness**: speed and Go single-binary ops on large host lists.
     66 > 3. **httpx -screenshot**: already in a `subfinder → httpx → nuclei` chain and only need quick PNGs.
     67 > 4. **aquatone**: legacy labs only — project is archived.
     68 
     69 ---
     70 
     71 ## Quick-Reference Flag Table `fas:ClipboardList`
     72 
     73 | Flag | Purpose |
     74 |---|---|
     75 | `--web` | HTTP screenshot via Selenium (default action) |
     76 | `-f <file>` | Line-separated URL/host file |
     77 | `-x <file.xml>` | Nmap XML or Nessus file |
     78 | `--single <URL>` | Single URL/host |
     79 | `--no-dns` | Skip DNS resolution |
     80 | `-d <dir>` | Output directory for screenshots/report |
     81 | `--timeout <sec>` | Page request timeout (default 7) |
     82 | `--jitter <sec>` | Randomise order + random delay |
     83 | `--delay <sec>` | Delay after navigator open before screenshot |
     84 | `--threads <n>` | Worker threads (default ≈ 2×CPU, max 20) |
     85 | `--max-retries <n>` | Retries on timeout (default 1) |
     86 | `--results <n>` | Results per report page (default 25) |
     87 | `--no-prompt` | Skip “open report?” prompt |
     88 | `--user-agent <UA>` | Custom User-Agent |
     89 | `--proxy-ip` / `--proxy-port` | HTTP/SOCKS proxy |
     90 | `--proxy-type` | `http` (default) or `socks5` |
     91 | `--show-selenium` | Show browser UI (debug) |
     92 | `--resolve` | Resolve IP/hostname for targets |
     93 | `--add-http-ports` / `--add-https-ports` | Extra ports treated as http/https |
     94 | `--only-ports` | Exclusive port list |
     95 | `--prepend-https` | Prepend `http://` and `https://` when scheme missing |
     96 | `--validate-urls` | Validate only, no screenshots |
     97 | `--skip-validation` | Skip URL validation |
     98 | `--cookies key=val,...` | Extra cookies |
     99 | `--width` / `--height` | Screenshot size (width 600–7680, height 400–4320) |
    100 | `--resume <ew.db>` | Resume from DB |
    101 | `--config <json>` | Load config file |
    102 | `--create-config` | Write sample config |
    103 
    104 ---
    105 
    106 ## Installation `fas:Screwdriver`
    107 
    108 > **Note —** + [EyeWitness](https://github.com/RedSiege/EyeWitness) Overview
    109 > Chromium-based HTTP screenshot and reporting tool with default-credential categorisation.
    110 > 1. Accepts URL lists and Nmap/Nessus XML.
    111 > 2. Isolates Python deps in `eyewitness-venv/`.
    112 > 3. Writes searchable HTML report + `ew.db` for resume.
    113 
    114 ```bash
    115 # Clone
    116 git clone https://github.com/RedSiege/EyeWitness.git
    117 cd EyeWitness/setup
    118 
    119 # Linux / Kali / macOS (needs sudo for system packages + venv)
    120 sudo ./setup.sh
    121 
    122 # Activate venv (required before every run)
    123 cd ..
    124 source eyewitness-venv/bin/activate
    125 
    126 # Smoke test
    127 python Python/EyeWitness.py --single https://example.com
    128 ```
    129 
    130 > **Note —** + Install Breakdown
    131 > 1. **setup.sh / setup.ps1**: creates `eyewitness-venv/`, installs Selenium stack, pulls Chromium/ChromeDriver.
    132 > 2. **Always activate the venv** — running system Python will miss deps / hit PEP 668 errors.
    133 > 3. **Docker**: still marked “in development” upstream — prefer native install for labs.
    134 > 4. **Cleanup**: delete `eyewitness-venv/` and re-run setup if the env breaks.
    135 
    136 ---
    137 
    138 ## Basic Usage
    139 
    140 ```bash
    141 source eyewitness-venv/bin/activate
    142 
    143 # Single target
    144 python Python/EyeWitness.py --web --single https://app.target.lab
    145 
    146 # URL list
    147 python Python/EyeWitness.py --web -f urls.txt -d ./ew-out --no-prompt
    148 
    149 # From Nmap XML
    150 python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-nmap --threads 8 --timeout 15
    151 ```
    152 
    153 > **Note —** + Command Breakdown
    154 > 1. **--web**: Selenium HTTP screenshot engine (required action).
    155 > 2. **-f / -x / --single**: mutually exclusive-style inputs — provide at least one.
    156 > 3. **-d**: fixed output path; omit to get a timestamped folder in CWD.
    157 > 4. **--no-prompt**: automation-friendly (CI / headless SSH).
    158 
    159 ---
    160 
    161 ## Input Formats
    162 
    163 ```bash
    164 # urls.txt — one URL or host per line
    165 https://intranet.target.lab
    166 http://10.10.10.50:8080
    167 target.lab
    168 
    169 # Nmap XML (open http/https services)
    170 nmap -p 80,443,8080,8443 -sV -oX nmap_http.xml 10.10.10.0/24
    171 python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-scan --prepend-https
    172 
    173 # Validate URLs only
    174 python Python/EyeWitness.py -f urls.txt --validate-urls -d ./ew-validate
    175 ```
    176 
    177 > **Note —** + Prepend schemes carefully
    178 > `fas:Lightbulb`
    179 > 1. Bare hostnames need `--prepend-https` (or explicit schemes in the list).
    180 > 2. Combine with `--only-ports 80,443,8080` when XML contains noisy services.
    181 > 3. `--add-http-ports 8000,8888` for non-standard HTTP listeners.
    182 
    183 ---
    184 
    185 ## Timing, Proxy & Browser Options
    186 
    187 ```bash
    188 python Python/EyeWitness.py --web -f urls.txt -d ./ew-slow \
    189   --threads 5 --timeout 30 --delay 2 --jitter 5 \
    190   --proxy-ip 127.0.0.1 --proxy-port 8080 --proxy-type http \
    191   --user-agent "Mozilla/5.0 (authorised-assessment)" \
    192   --width 1920 --height 1080 \
    193   --cookies "SESSIONID=abc123"
    194 ```
    195 
    196 > **Note —** + Tuning Breakdown
    197 > 1. **--threads**: lower on low-RAM boxes; EyeWitness may auto-reduce based on memory.
    198 > 2. **--timeout / --max-retries**: slow lab links and flaky VPN paths.
    199 > 3. **--proxy-***: send browser traffic through Burp (`http`) or SOCKS.
    200 > 4. **--width/--height**: must stay inside documented ranges or the parser exits.
    201 
    202 ---
    203 
    204 ## Resume & Config `fas:ClipboardList`
    205 
    206 ```bash
    207 # Sample config
    208 python Python/EyeWitness.py --create-config
    209 
    210 # Use config
    211 python Python/EyeWitness.py --web -f urls.txt --config ~/.eyewitness/config.json
    212 
    213 # Resume interrupted run
    214 python Python/EyeWitness.py --resume ./ew-out/ew.db
    215 ```
    216 
    217 Example config keys (from upstream README):
    218 
    219 ```json
    220 {
    221     "threads": 10,
    222     "timeout": 30,
    223     "delay": 0,
    224     "jitter": 0,
    225     "user_agent": "Custom User Agent",
    226     "proxy_ip": "127.0.0.1",
    227     "proxy_port": 8080,
    228     "output_dir": "./sessions",
    229     "prepend_https": false,
    230     "show_selenium": false,
    231     "resolve": false,
    232     "skip_validation": false,
    233     "results_per_page": 25,
    234     "max_retries": 2
    235 }
    236 ```
    237 
    238 ---
    239 
    240 ## Output Layout
    241 
    242 | Path | Contents |
    243 |---|---|
    244 | `report.html` | Main categorised report |
    245 | `screens/` | Screenshot images |
    246 | `source/` | Saved page source |
    247 | `ew.db` | SQLite DB for resume |
    248 | `logfile.log` | Run log |
    249 
    250 Categories commonly include High Value, CMS, network devices, etc., plus default-credential hints when signatures match.
    251 
    252 ---
    253 
    254 ## Practical Recipes
    255 
    256 ```bash
    257 # 1) httpx live hosts → EyeWitness
    258 httpx -l hosts.txt -ports 80,443,8080,8443 -o live.txt -silent
    259 python Python/EyeWitness.py --web -f live.txt -d ./ew-live --threads 10 --no-prompt
    260 
    261 # 2) Full TCP discover → XML → screenshots
    262 nmap -p- --min-rate 2000 -oX full.xml 10.10.10.5
    263 python Python/EyeWitness.py --web -x full.xml -d ./ew-full --prepend-https --timeout 20
    264 
    265 # 3) Authenticated cookie session (lab app)
    266 python Python/EyeWitness.py --web --single https://app.target.lab/admin \
    267   --cookies "auth=TOKEN" -d ./ew-auth --no-prompt
    268 ```
    269 
    270 ---
    271 
    272 ## Alternatives (gowitness / aquatone / httpx) `fas:Screwdriver`
    273 
    274 ### gowitness
    275 
    276 ```bash
    277 go install github.com/sensepost/gowitness@latest
    278 # single
    279 gowitness single https://example.com
    280 # file
    281 gowitness file -f urls.txt
    282 # scan CIDR / ports (check gowitness -h for current subcommands)
    283 gowitness scan --cidr 10.10.10.0/24 --ports 80,443,8080
    284 ```
    285 
    286 ### aquatone (archived)
    287 
    288 ```bash
    289 # Legacy pattern — prefer gowitness for new work
    290 cat hosts.txt | aquatone -ports large -out ./aqua-out
    291 cat nmap.xml | aquatone -nmap -out ./aqua-nmap
    292 ```
    293 
    294 ### httpx screenshots
    295 
    296 ```bash
    297 httpx -l hosts.txt -screenshot -screenshot-timeout 10 -o httpx-live.txt
    298 # screenshots land under ./screenshot/ (path may vary by httpx version — confirm with httpx -h)
    299 ```
    300 
    301 > **Note —** + Aquatone maintenance
    302 > `fas:TriangleExclamation`
    303 > 1. [michenriksen/aquatone](https://github.com/michenriksen/aquatone) is archived.
    304 > 2. Chrome/chromedp breakage is common on modern Kali.
    305 > 3. Keep it only for reproducing old lab steps.
    306 
    307 ---
    308 
    309 ## Troubleshooting & Gotchas `fas:CircleXmark`
    310 
    311 > **Note —** + Common failures
    312 > `fas:CircleXmark`
    313 > 1. **ChromeDriver missing** → re-run `setup/setup.sh` inside the project.
    314 > 2. **PEP 668 / missing modules** → you forgot `source eyewitness-venv/bin/activate`.
    315 > 3. **Timeouts over VPN** → raise `--timeout`, lower `--threads`.
    316 > 4. **Low disk** → EyeWitness warns when free space is low; prune `source/` if needed.
    317 > 5. **Width/height rejected** → stay within 600–7680 × 400–4320.
    318 
    319 ---
    320 
    321 ## Lessons Learned `fas:Lightbulb`
    322 
    323 1. Treat EyeWitness as a **triage** step after httpx/nmap — not a replacement for content discovery (Ffuf-Cheatsheet, Nuclei-Cheatsheet).
    324 2. Prefer **RedSiege** EyeWitness or **gowitness** over aquatone for new engagements.
    325 3. Always **activate the venv**; most “broken install” tickets are path/Python confusion.
    326 4. Use `--resume` after VPN drops — `ew.db` saves a lot of rework.
    327 5. Screenshot noise is high; filter input with httpx status/title first.
    328 
    329 ---
    330 
    331 ## References `fas:BookOpen`
    332 
    333 1. [RedSiege/EyeWitness](https://github.com/RedSiege/EyeWitness)
    334 2. [EyeWitness README](https://github.com/RedSiege/EyeWitness/blob/master/README.md)
    335 3. [sensepost/gowitness](https://github.com/sensepost/gowitness)
    336 4. [michenriksen/aquatone (archived)](https://github.com/michenriksen/aquatone)
    337 5. [ProjectDiscovery httpx](https://github.com/projectdiscovery/httpx)
    338 6. [HackTricks — Web Discovery](https://book.hacktricks.xyz/)
    339 
    340 ---
    341 
    342 #Tool #EyeWitness #gowitness #aquatone #httpx #WebTesting #Recon #Screenshots