← All cheat sheets

HTTPX

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

httpx (ProjectDiscovery) is a fast, multi-purpose HTTP probing toolkit.
It takes a list of hosts/subdomains and identifies live web servers,
titles, status codes, technologies, and more. Core triage step between
subdomain enum and vulnerability scanning. (Not to be confused with the
Python httpx library.) Authorized scope only.

BASIC USAGE#

httpx -u https://corp.lu                       # Probe one URL
httpx -l subs.txt                              # Probe a list of hosts
subfinder -d corp.lu -silent | httpx           # From a pipe
httpx -l subs.txt -silent                      # Clean output for pipes

PROBE INFORMATION#

httpx -l subs.txt -title                        # Page titles
httpx -l subs.txt -status-code                  # HTTP status
httpx -l subs.txt -tech-detect                  # Wappalyzer-style tech
httpx -l subs.txt -web-server                    # Server header
httpx -l subs.txt -content-length               # Body size
httpx -l subs.txt -ip -cname                     # Resolved IP + CNAME
httpx -l subs.txt -location                      # Redirect target
httpx -l subs.txt -favicon                        # Favicon mmh3 hash
httpx -l subs.txt -jarm                           # JARM TLS fingerprint

FILTERING & MATCHING#

httpx -l subs.txt -mc 200,301,302               # Match status codes
httpx -l subs.txt -fc 404,403                    # Filter out codes
httpx -l subs.txt -ms "admin"                    # Match body string
httpx -l subs.txt -ms "login" -title             # Find login portals
httpx -l subs.txt -filter-length 0               # Drop empty bodies

PORTS & PATHS#

httpx -l hosts.txt -ports 80,443,8080,8443       # Probe extra ports
httpx -l subs.txt -path /admin                    # Probe a path
httpx -l subs.txt -paths paths.txt                # Multiple paths
httpx -l subs.txt -probe                          # Show FAILED/ SUCCESS

PERFORMANCE#

httpx -l subs.txt -threads 100                    # Concurrency
httpx -l subs.txt -rate-limit 150                 # Req/sec cap
httpx -l subs.txt -timeout 10 -retries 2

OUTPUT#

httpx -l subs.txt -o live.txt                     # Text output
httpx -l subs.txt -json -o live.json              # JSON lines
httpx -l subs.txt -sr -srd ./responses            # Store raw responses
httpx -l subs.txt -screenshot -srd ./shots        # Headless screenshots

EXAMPLES#

# Live-host triage with the details that matter, piped from subfinder
subfinder -d corp.lu -silent | \
  httpx -silent -title -status-code -tech-detect -o live.txt

# Find live admin/login surfaces across the estate
httpx -l subs.txt -silent -path /admin -mc 200,401,403 -title

# Screenshot every live host for fast visual review
httpx -l subs.txt -silent -screenshot -srd ./shots

# Full chain into nuclei for templated scanning
subfinder -d corp.lu -silent | httpx -silent | nuclei -severity high,critical

NOTES#

- httpx is the triage layer: reduce thousands of DNS names to the few
  hundred LIVE web services worth testing
- -silent output is designed to pipe into naabu/nuclei/katana
- -favicon mmh3 hashes help fingerprint tech and find related assets
  (pivot in Shodan/Censys)
- -screenshot needs a headless browser available on the host
- Pairs with SUBFINDER (upstream) and NUCLEI (downstream) sheets
- Single Go binary - trivial to pin in a reproducible NixOS toolchain