← All cheat sheets

DALFOX

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Fast, parameter-analysis-based XSS scanner by hahwul.
Supports pipeline integration with other ProjectDiscovery tools.

INSTALLATION#

# Go install
go install github.com/hahwul/dalfox/v2@latest

# Homebrew
brew install dalfox

# Docker
docker pull hahwul/dalfox

# Snap
sudo snap install dalfox

# From source
git clone https://github.com/hahwul/dalfox
cd dalfox && go build

BASIC USAGE#

# Single URL
dalfox url "https://example.com/search?q=test"

# Multiple URLs from file
dalfox file targets.txt

# From stdin (pipeline)
cat urls.txt | dalfox pipe

# With specific parameter
dalfox url "https://example.com/page" -p "search"
dalfox url "https://example.com/page" -p "q,id,name"

SCANNING MODES#

# URL mode (single target)
dalfox url "https://example.com/?q=test"

# File mode (multiple targets)
dalfox file urls.txt

# Pipe mode (stdin)
echo "https://example.com/?q=test" | dalfox pipe
cat urls.txt | dalfox pipe

# Server mode (API server)
dalfox server -p 8090
# Then: curl "localhost:8090/scan?url=https://example.com/?q=test"

PAYLOAD OPTIONS#

# Custom payloads
dalfox url URL --custom-payload payloads.txt

# Blind XSS (with callback)
dalfox url URL --blind "https://your.xss.ht"
dalfox url URL -b "https://interact.sh/xxxx"

# Custom alert value
dalfox url URL --custom-alert-value "document.domain"
dalfox url URL --custom-alert-type "str"    # String alert
dalfox url URL --custom-alert-type "none"   # No alert

# Remote payloads
dalfox url URL --remote-payloads portswigger
dalfox url URL --remote-payloads payloadbox

# Trigger XSS with specific browser
dalfox url URL --trigger                    # Open browser on finding

OUTPUT OPTIONS#

dalfox url URL -o results.txt               # Plain text
dalfox url URL -o results.json --format json # JSON
dalfox url URL --found-action "notify.sh"   # Execute on finding
dalfox url URL --silence                    # Only output results
dalfox url URL -v                           # Verbose

AUTHENTICATION & HEADERS#

# Custom headers
dalfox url URL -H "Authorization: Bearer TOKEN"
dalfox url URL -H "Cookie: session=abc123"

# Multiple headers
dalfox url URL -H "Authorization: Bearer TOKEN" -H "X-Custom: value"

# Cookie
dalfox url URL --cookie "session=abc123; token=xyz"

# HTTP method
dalfox url URL --method POST
dalfox url URL --method PUT

# POST data
dalfox url URL -d "param1=value1&param2=value2"
dalfox url URL --data '{"key":"value"}' -H "Content-Type: application/json"

# User-Agent
dalfox url URL --user-agent "Mozilla/5.0"

PROXY & NETWORK#

# Proxy
dalfox url URL --proxy http://127.0.0.1:8080    # Through Burp/Caido
dalfox url URL --proxy socks5://127.0.0.1:9050   # Through Tor

# Timeout
dalfox url URL --timeout 10

# Delay between requests
dalfox url URL --delay 500                       # Milliseconds

# Follow redirects
dalfox url URL --follow-redirects

ADVANCED OPTIONS#

# WAF detection
dalfox url URL --waf-evasion                     # Try WAF bypass

# Mining (parameter discovery from response)
dalfox url URL --mining-dict                     # Dictionary-based
dalfox url URL --mining-dom                      # DOM-based
dalfox url URL --mining-dict --mining-dom        # Both

# Only DOM XSS
dalfox url URL --only-discovery
dalfox url URL --skip-bav                        # Skip BAV analysis

# Grep for specific patterns
dalfox url URL --grep "error|exception|warning"

# Only specific XSS type
dalfox url URL --only-custom-payload             # Only custom payloads

# Skip specific checks
dalfox url URL --skip-mining-dict
dalfox url URL --skip-mining-dom
dalfox url URL --skip-xss-scanning

PIPELINE INTEGRATION#

# ProjectDiscovery pipeline
subfinder -d example.com | httpx | katana -jc | dalfox pipe

# With parameter discovery
cat urls.txt | gau | dalfox pipe

# Arjun → Dalfox
arjun -u https://example.com/page --stable -o params.json
# Parse Arjun output and feed to Dalfox

# With wayback URLs
echo example.com | waybackurls | dalfox pipe

# With Nuclei (complementary)
nuclei -l targets.txt -tags xss             # Template-based
cat targets.txt | dalfox pipe               # Parameter-based

COMMON WORKFLOWS#

# 1. Quick XSS scan on a URL with parameters
dalfox url "https://target.com/search?q=test&page=1"

# 2. Blind XSS hunting
dalfox url URL -b "https://your.interact.sh/callback"

# 3. Bug bounty pipeline
subfinder -d target.com | httpx | katana -jc | \
    grep "=" | dalfox pipe -b "https://your.xss.ht" -o results.txt

# 4. Authenticated scan
dalfox url URL -H "Cookie: session=TOKEN" -H "Authorization: Bearer JWT"

# 5. Through proxy for manual review
dalfox url URL --proxy http://127.0.0.1:8080

TIPS#

  - Parameter analysis is Dalfox's strength (auto-detects reflections)
  - Use --blind for stored/blind XSS with callback server
  - Mining mode discovers hidden parameters from page content
  - Pipeline mode (pipe) is ideal for large-scale scanning
  - Set --delay to avoid rate limiting on bug bounty targets
  - Route through proxy (--proxy) to review findings in Burp/Caido
  - Combine with katana (crawler) for comprehensive coverage
  - --waf-evasion helps against WAF-protected targets
  - Custom payloads for specific frameworks (React, Angular, etc.)
  - Server mode allows building XSS scanning into automation