HTTPX
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
httpx (ProjectDiscovery) is a fast, multi-purpose HTTP probing toolkit. It takes a list of hosts/subdomains and identifies live web servers, titles, status codes, technologies, and more. Core triage step between subdomain enum and vulnerability scanning. (Not to be confused with the Python httpx library.) Authorized scope only.
BASIC USAGE#
httpx -u https://corp.lu # Probe one URL httpx -l subs.txt # Probe a list of hosts subfinder -d corp.lu -silent | httpx # From a pipe httpx -l subs.txt -silent # Clean output for pipes
PROBE INFORMATION#
httpx -l subs.txt -title # Page titles httpx -l subs.txt -status-code # HTTP status httpx -l subs.txt -tech-detect # Wappalyzer-style tech httpx -l subs.txt -web-server # Server header httpx -l subs.txt -content-length # Body size httpx -l subs.txt -ip -cname # Resolved IP + CNAME httpx -l subs.txt -location # Redirect target httpx -l subs.txt -favicon # Favicon mmh3 hash httpx -l subs.txt -jarm # JARM TLS fingerprint
FILTERING & MATCHING#
httpx -l subs.txt -mc 200,301,302 # Match status codes httpx -l subs.txt -fc 404,403 # Filter out codes httpx -l subs.txt -ms "admin" # Match body string httpx -l subs.txt -ms "login" -title # Find login portals httpx -l subs.txt -filter-length 0 # Drop empty bodies
PORTS & PATHS#
httpx -l hosts.txt -ports 80,443,8080,8443 # Probe extra ports httpx -l subs.txt -path /admin # Probe a path httpx -l subs.txt -paths paths.txt # Multiple paths httpx -l subs.txt -probe # Show FAILED/ SUCCESS
PERFORMANCE#
httpx -l subs.txt -threads 100 # Concurrency httpx -l subs.txt -rate-limit 150 # Req/sec cap httpx -l subs.txt -timeout 10 -retries 2
OUTPUT#
httpx -l subs.txt -o live.txt # Text output httpx -l subs.txt -json -o live.json # JSON lines httpx -l subs.txt -sr -srd ./responses # Store raw responses httpx -l subs.txt -screenshot -srd ./shots # Headless screenshots
EXAMPLES#
# Live-host triage with the details that matter, piped from subfinder subfinder -d corp.lu -silent | \ httpx -silent -title -status-code -tech-detect -o live.txt # Find live admin/login surfaces across the estate httpx -l subs.txt -silent -path /admin -mc 200,401,403 -title # Screenshot every live host for fast visual review httpx -l subs.txt -silent -screenshot -srd ./shots # Full chain into nuclei for templated scanning subfinder -d corp.lu -silent | httpx -silent | nuclei -severity high,critical
NOTES#
- httpx is the triage layer: reduce thousands of DNS names to the few hundred LIVE web services worth testing - -silent output is designed to pipe into naabu/nuclei/katana - -favicon mmh3 hashes help fingerprint tech and find related assets (pivot in Shodan/Censys) - -screenshot needs a headless browser available on the host - Pairs with SUBFINDER (upstream) and NUCLEI (downstream) sheets - Single Go binary - trivial to pin in a reproducible NixOS toolchain