eyewitness.md (12205B)
1 --- 2 title: "EyeWitness" 3 description: "EyeWitness bulk web/RDP/VNC screenshotting and reporting for rapid visual recon." 4 category: tools 5 tags: [recon, screenshots, web] 6 tools: [EyeWitness] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "vault:Tools/EyeWitness-Cheatsheet.md" 10 --- 11 12 # EyeWitness Cheatsheet 13 14 > **Author**: Netrunner | **Last Updated**: 2026-08-06 | **Context**: HTB Pro Labs, CTF, authorised pentesting | **Tool**: [EyeWitness](https://github.com/RedSiege/EyeWitness) (CLI reference) 15 16 Web screenshot / recon CLI reference for authorised assessments. Flags below were checked against the [RedSiege/EyeWitness](https://github.com/RedSiege/EyeWitness) README and `Python/EyeWitness.py` argument parser — nothing invented. 17 18 Related notes: Nuclei-Cheatsheet · Ffuf-Cheatsheet · webfuzz · NetExec-Cheatsheet 19 20 --- 21 22 ## Table of Contents 23 24 1. [Summary](#summary) 25 2. [Project Status & Alternatives](#project-status--alternatives) 26 3. [Quick-Reference Flag Table](#quick-reference-flag-table) 27 4. [Installation](#installation) 28 5. [Basic Usage](#basic-usage) 29 6. [Input Formats](#input-formats) 30 7. [Timing, Proxy & Browser Options](#timing-proxy--browser-options) 31 8. [Resume & Config](#resume--config) 32 9. [Output Layout](#output-layout) 33 10. [Practical Recipes](#practical-recipes) 34 11. [Alternatives (gowitness / aquatone / httpx)](#alternatives-gowitness--aquatone--httpx) 35 12. [Troubleshooting & Gotchas](#troubleshooting--gotchas) 36 13. [Lessons Learned](#lessons-learned) 37 14. [References](#references) 38 39 --- 40 41 ## Summary 42 43 [EyeWitness](https://github.com/RedSiege/EyeWitness) takes screenshots of HTTP(S) targets, records response headers/source, and attempts to flag known default credentials. It is useful after host/URL discovery (nmap, httpx, masscan) when you need a visual triage of large web attack surfaces. Modern builds use **Chromium/Chrome + Selenium**, install into an isolated **Python venv**, and support text URL lists, Nmap/Nessus XML, single-URL mode, and resume via SQLite (`ew.db`). 44 45 > **Note —** + Authorised-use framing 46 > `fas:TriangleExclamation` 47 > 1. Only run against systems you own or have written authorisation to assess. 48 > 2. Screenshot tools generate significant browser/CPU load — tune `--threads` and timeouts on fragile lab targets. 49 > 3. Proxy through Burp/ZAP when you need request inspection (`--proxy-ip` / `--proxy-port`). 50 51 --- 52 53 ## Project Status & Alternatives 54 55 | Tool | Status (as of 2026) | Notes | 56 |---|---|---| 57 | **EyeWitness** (RedSiege) | **Actively maintained** | Formerly FortyNorthSecurity; Chromium-powered rewrite with venv install | 58 | **gowitness** | Actively maintained | Go, fast, good for large lists | 59 | **aquatone** | **Archived / unmaintained** | Still seen in older writeups; prefer gowitness or EyeWitness | 60 | **httpx `-screenshot`** | Actively maintained | Lightweight screenshots in the ProjectDiscovery pipeline | 61 62 > **Note —** + When to pick what 63 > `fas:Lightbulb` 64 > 1. **EyeWitness**: HTML report + default-cred hints + Nmap/Nessus XML ingest. 65 > 2. **gowitness**: speed and Go single-binary ops on large host lists. 66 > 3. **httpx -screenshot**: already in a `subfinder → httpx → nuclei` chain and only need quick PNGs. 67 > 4. **aquatone**: legacy labs only — project is archived. 68 69 --- 70 71 ## Quick-Reference Flag Table `fas:ClipboardList` 72 73 | Flag | Purpose | 74 |---|---| 75 | `--web` | HTTP screenshot via Selenium (default action) | 76 | `-f <file>` | Line-separated URL/host file | 77 | `-x <file.xml>` | Nmap XML or Nessus file | 78 | `--single <URL>` | Single URL/host | 79 | `--no-dns` | Skip DNS resolution | 80 | `-d <dir>` | Output directory for screenshots/report | 81 | `--timeout <sec>` | Page request timeout (default 7) | 82 | `--jitter <sec>` | Randomise order + random delay | 83 | `--delay <sec>` | Delay after navigator open before screenshot | 84 | `--threads <n>` | Worker threads (default ≈ 2×CPU, max 20) | 85 | `--max-retries <n>` | Retries on timeout (default 1) | 86 | `--results <n>` | Results per report page (default 25) | 87 | `--no-prompt` | Skip “open report?” prompt | 88 | `--user-agent <UA>` | Custom User-Agent | 89 | `--proxy-ip` / `--proxy-port` | HTTP/SOCKS proxy | 90 | `--proxy-type` | `http` (default) or `socks5` | 91 | `--show-selenium` | Show browser UI (debug) | 92 | `--resolve` | Resolve IP/hostname for targets | 93 | `--add-http-ports` / `--add-https-ports` | Extra ports treated as http/https | 94 | `--only-ports` | Exclusive port list | 95 | `--prepend-https` | Prepend `http://` and `https://` when scheme missing | 96 | `--validate-urls` | Validate only, no screenshots | 97 | `--skip-validation` | Skip URL validation | 98 | `--cookies key=val,...` | Extra cookies | 99 | `--width` / `--height` | Screenshot size (width 600–7680, height 400–4320) | 100 | `--resume <ew.db>` | Resume from DB | 101 | `--config <json>` | Load config file | 102 | `--create-config` | Write sample config | 103 104 --- 105 106 ## Installation `fas:Screwdriver` 107 108 > **Note —** + [EyeWitness](https://github.com/RedSiege/EyeWitness) Overview 109 > Chromium-based HTTP screenshot and reporting tool with default-credential categorisation. 110 > 1. Accepts URL lists and Nmap/Nessus XML. 111 > 2. Isolates Python deps in `eyewitness-venv/`. 112 > 3. Writes searchable HTML report + `ew.db` for resume. 113 114 ```bash 115 # Clone 116 git clone https://github.com/RedSiege/EyeWitness.git 117 cd EyeWitness/setup 118 119 # Linux / Kali / macOS (needs sudo for system packages + venv) 120 sudo ./setup.sh 121 122 # Activate venv (required before every run) 123 cd .. 124 source eyewitness-venv/bin/activate 125 126 # Smoke test 127 python Python/EyeWitness.py --single https://example.com 128 ``` 129 130 > **Note —** + Install Breakdown 131 > 1. **setup.sh / setup.ps1**: creates `eyewitness-venv/`, installs Selenium stack, pulls Chromium/ChromeDriver. 132 > 2. **Always activate the venv** — running system Python will miss deps / hit PEP 668 errors. 133 > 3. **Docker**: still marked “in development” upstream — prefer native install for labs. 134 > 4. **Cleanup**: delete `eyewitness-venv/` and re-run setup if the env breaks. 135 136 --- 137 138 ## Basic Usage 139 140 ```bash 141 source eyewitness-venv/bin/activate 142 143 # Single target 144 python Python/EyeWitness.py --web --single https://app.target.lab 145 146 # URL list 147 python Python/EyeWitness.py --web -f urls.txt -d ./ew-out --no-prompt 148 149 # From Nmap XML 150 python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-nmap --threads 8 --timeout 15 151 ``` 152 153 > **Note —** + Command Breakdown 154 > 1. **--web**: Selenium HTTP screenshot engine (required action). 155 > 2. **-f / -x / --single**: mutually exclusive-style inputs — provide at least one. 156 > 3. **-d**: fixed output path; omit to get a timestamped folder in CWD. 157 > 4. **--no-prompt**: automation-friendly (CI / headless SSH). 158 159 --- 160 161 ## Input Formats 162 163 ```bash 164 # urls.txt — one URL or host per line 165 https://intranet.target.lab 166 http://10.10.10.50:8080 167 target.lab 168 169 # Nmap XML (open http/https services) 170 nmap -p 80,443,8080,8443 -sV -oX nmap_http.xml 10.10.10.0/24 171 python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-scan --prepend-https 172 173 # Validate URLs only 174 python Python/EyeWitness.py -f urls.txt --validate-urls -d ./ew-validate 175 ``` 176 177 > **Note —** + Prepend schemes carefully 178 > `fas:Lightbulb` 179 > 1. Bare hostnames need `--prepend-https` (or explicit schemes in the list). 180 > 2. Combine with `--only-ports 80,443,8080` when XML contains noisy services. 181 > 3. `--add-http-ports 8000,8888` for non-standard HTTP listeners. 182 183 --- 184 185 ## Timing, Proxy & Browser Options 186 187 ```bash 188 python Python/EyeWitness.py --web -f urls.txt -d ./ew-slow \ 189 --threads 5 --timeout 30 --delay 2 --jitter 5 \ 190 --proxy-ip 127.0.0.1 --proxy-port 8080 --proxy-type http \ 191 --user-agent "Mozilla/5.0 (authorised-assessment)" \ 192 --width 1920 --height 1080 \ 193 --cookies "SESSIONID=abc123" 194 ``` 195 196 > **Note —** + Tuning Breakdown 197 > 1. **--threads**: lower on low-RAM boxes; EyeWitness may auto-reduce based on memory. 198 > 2. **--timeout / --max-retries**: slow lab links and flaky VPN paths. 199 > 3. **--proxy-***: send browser traffic through Burp (`http`) or SOCKS. 200 > 4. **--width/--height**: must stay inside documented ranges or the parser exits. 201 202 --- 203 204 ## Resume & Config `fas:ClipboardList` 205 206 ```bash 207 # Sample config 208 python Python/EyeWitness.py --create-config 209 210 # Use config 211 python Python/EyeWitness.py --web -f urls.txt --config ~/.eyewitness/config.json 212 213 # Resume interrupted run 214 python Python/EyeWitness.py --resume ./ew-out/ew.db 215 ``` 216 217 Example config keys (from upstream README): 218 219 ```json 220 { 221 "threads": 10, 222 "timeout": 30, 223 "delay": 0, 224 "jitter": 0, 225 "user_agent": "Custom User Agent", 226 "proxy_ip": "127.0.0.1", 227 "proxy_port": 8080, 228 "output_dir": "./sessions", 229 "prepend_https": false, 230 "show_selenium": false, 231 "resolve": false, 232 "skip_validation": false, 233 "results_per_page": 25, 234 "max_retries": 2 235 } 236 ``` 237 238 --- 239 240 ## Output Layout 241 242 | Path | Contents | 243 |---|---| 244 | `report.html` | Main categorised report | 245 | `screens/` | Screenshot images | 246 | `source/` | Saved page source | 247 | `ew.db` | SQLite DB for resume | 248 | `logfile.log` | Run log | 249 250 Categories commonly include High Value, CMS, network devices, etc., plus default-credential hints when signatures match. 251 252 --- 253 254 ## Practical Recipes 255 256 ```bash 257 # 1) httpx live hosts → EyeWitness 258 httpx -l hosts.txt -ports 80,443,8080,8443 -o live.txt -silent 259 python Python/EyeWitness.py --web -f live.txt -d ./ew-live --threads 10 --no-prompt 260 261 # 2) Full TCP discover → XML → screenshots 262 nmap -p- --min-rate 2000 -oX full.xml 10.10.10.5 263 python Python/EyeWitness.py --web -x full.xml -d ./ew-full --prepend-https --timeout 20 264 265 # 3) Authenticated cookie session (lab app) 266 python Python/EyeWitness.py --web --single https://app.target.lab/admin \ 267 --cookies "auth=TOKEN" -d ./ew-auth --no-prompt 268 ``` 269 270 --- 271 272 ## Alternatives (gowitness / aquatone / httpx) `fas:Screwdriver` 273 274 ### gowitness 275 276 ```bash 277 go install github.com/sensepost/gowitness@latest 278 # single 279 gowitness single https://example.com 280 # file 281 gowitness file -f urls.txt 282 # scan CIDR / ports (check gowitness -h for current subcommands) 283 gowitness scan --cidr 10.10.10.0/24 --ports 80,443,8080 284 ``` 285 286 ### aquatone (archived) 287 288 ```bash 289 # Legacy pattern — prefer gowitness for new work 290 cat hosts.txt | aquatone -ports large -out ./aqua-out 291 cat nmap.xml | aquatone -nmap -out ./aqua-nmap 292 ``` 293 294 ### httpx screenshots 295 296 ```bash 297 httpx -l hosts.txt -screenshot -screenshot-timeout 10 -o httpx-live.txt 298 # screenshots land under ./screenshot/ (path may vary by httpx version — confirm with httpx -h) 299 ``` 300 301 > **Note —** + Aquatone maintenance 302 > `fas:TriangleExclamation` 303 > 1. [michenriksen/aquatone](https://github.com/michenriksen/aquatone) is archived. 304 > 2. Chrome/chromedp breakage is common on modern Kali. 305 > 3. Keep it only for reproducing old lab steps. 306 307 --- 308 309 ## Troubleshooting & Gotchas `fas:CircleXmark` 310 311 > **Note —** + Common failures 312 > `fas:CircleXmark` 313 > 1. **ChromeDriver missing** → re-run `setup/setup.sh` inside the project. 314 > 2. **PEP 668 / missing modules** → you forgot `source eyewitness-venv/bin/activate`. 315 > 3. **Timeouts over VPN** → raise `--timeout`, lower `--threads`. 316 > 4. **Low disk** → EyeWitness warns when free space is low; prune `source/` if needed. 317 > 5. **Width/height rejected** → stay within 600–7680 × 400–4320. 318 319 --- 320 321 ## Lessons Learned `fas:Lightbulb` 322 323 1. Treat EyeWitness as a **triage** step after httpx/nmap — not a replacement for content discovery (Ffuf-Cheatsheet, Nuclei-Cheatsheet). 324 2. Prefer **RedSiege** EyeWitness or **gowitness** over aquatone for new engagements. 325 3. Always **activate the venv**; most “broken install” tickets are path/Python confusion. 326 4. Use `--resume` after VPN drops — `ew.db` saves a lot of rework. 327 5. Screenshot noise is high; filter input with httpx status/title first. 328 329 --- 330 331 ## References `fas:BookOpen` 332 333 1. [RedSiege/EyeWitness](https://github.com/RedSiege/EyeWitness) 334 2. [EyeWitness README](https://github.com/RedSiege/EyeWitness/blob/master/README.md) 335 3. [sensepost/gowitness](https://github.com/sensepost/gowitness) 336 4. [michenriksen/aquatone (archived)](https://github.com/michenriksen/aquatone) 337 5. [ProjectDiscovery httpx](https://github.com/projectdiscovery/httpx) 338 6. [HackTricks — Web Discovery](https://book.hacktricks.xyz/) 339 340 --- 341 342 #Tool #EyeWitness #gowitness #aquatone #httpx #WebTesting #Recon #Screenshots