← All cheat sheets

FEROXBUSTER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Feroxbuster is a fast, recursive content/directory discovery tool
written in Rust. It brute-forces paths and files on web servers and
recurses into found directories automatically. Complements ffuf/gobuster
with strong recursion and resume support. Authorized scope only.

BASIC USAGE#

feroxbuster -u https://corp.lu                 # Scan with default wordlist
feroxbuster -u https://corp.lu -w wordlist.txt # Custom wordlist
feroxbuster -u https://corp.lu -o out.txt      # Save results
feroxbuster --stdin -w list.txt < urls.txt     # URLs from stdin

WORDLIST & EXTENSIONS#

feroxbuster -u https://corp.lu -w raft.txt
feroxbuster -u https://corp.lu -x php,html,txt # Append extensions
feroxbuster -u https://corp.lu -x php,bak,old,zip
feroxbuster -u https://corp.lu --dont-extract-links

RECURSION CONTROL#

feroxbuster -u https://corp.lu -d 3            # Max recursion depth
feroxbuster -u https://corp.lu --no-recursion  # Disable recursion
feroxbuster -u https://corp.lu -d 0            # Unlimited depth
feroxbuster -u https://corp.lu --force-recursion

FILTERING#

feroxbuster -u https://corp.lu -s 200,301,302  # Match status codes
feroxbuster -u https://corp.lu -C 404,403       # Filter out codes
feroxbuster -u https://corp.lu -S 0             # Filter by size (bytes)
feroxbuster -u https://corp.lu -W 12            # Filter by word count
feroxbuster -u https://corp.lu -N 5             # Filter by line count
feroxbuster -u https://corp.lu --filter-regex "maintenance"

PERFORMANCE#

feroxbuster -u https://corp.lu -t 50           # Concurrent threads
feroxbuster -u https://corp.lu --rate-limit 100# Requests/sec
feroxbuster -u https://corp.lu --timeout 7
feroxbuster -u https://corp.lu -T 3            # Per-request timeout

HEADERS / AUTH / PROXY#

feroxbuster -u https://corp.lu -H "Authorization: Bearer TOKEN"
feroxbuster -u https://corp.lu -b "session=abc" # Cookies
feroxbuster -u https://corp.lu -a "Mozilla/5.0" # User-Agent
feroxbuster -u https://corp.lu -p http://127.0.0.1:8080  # Proxy (Burp)
feroxbuster -u https://corp.lu -k               # Ignore TLS errors

RESUME & STATE#

feroxbuster -u https://corp.lu --resume-from ferox.state
# Ctrl+C offers to save state; resume large scans later

EXAMPLES#

# Recursive discovery with common extensions, routed through Burp
feroxbuster -u https://corp.lu -x php,html,bak -p http://127.0.0.1:8080

# Big raft wordlist, depth-limited, filter noisy 404-like responses
feroxbuster -u https://corp.lu -w raft-large.txt -d 2 -C 404 -S 0

# Authenticated app scan with a session cookie
feroxbuster -u https://app.corp.lu -b "SESSION=deadbeef" -x json,php

# Feed live hosts from httpx into per-host content discovery
httpx -l subs.txt -silent | while read u; do feroxbuster -u "$u" -q; done

NOTES#

- Recursion + link extraction is feroxbuster's edge over gobuster;
  cap depth (-d) on large apps to avoid runaway scans
- Route through Burp (-p) to capture interesting responses for replay
- --resume-from makes long FS-app scans restartable
- Rust single binary - clean fit for a reproducible NixOS toolchain
- You already have FFUF/GOBUSTER; use feroxbuster when recursion and
  auto link-following save time on deep apps
- Respect scope and rate limits on production financial applications