← All cheat sheets

WHATWEB

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

WhatWeb identifies websites and recognizes web technologies including
CMS, blogging platforms, JS libraries, web servers, embedded devices,
version numbers, email addresses, and more. It has over 1800 plugins.

BASIC USAGE#

whatweb <url>                    # Basic fingerprint
whatweb -v <url>                 # Verbose output
whatweb -a 3 <url>               # Aggressive scan

AGGRESSION LEVELS (-a)#

whatweb -a 1 <url>               # Stealthy (1 HTTP request)
whatweb -a 2 <url>               # Unused (reserved)
whatweb -a 3 <url>               # Aggressive (additional requests)
whatweb -a 4 <url>               # Heavy (many requests, brute force)

TARGET OPTIONS#

whatweb <url>                    # Single URL
whatweb <url1> <url2> <url3>    # Multiple URLs
whatweb -i urls.txt              # URLs from file
whatweb --input-file=urls.txt    # URLs from file (alt)
whatweb 192.168.1.0/24           # Scan IP range
whatweb 192.168.1.1-192.168.1.50 # Scan IP range

OUTPUT OPTIONS#

whatweb --log-brief=out.txt <url>     # Brief text output
whatweb --log-verbose=out.txt <url>   # Verbose text output
whatweb --log-json=out.json <url>     # JSON output
whatweb --log-xml=out.xml <url>       # XML output
whatweb --log-csv=out.csv <url>       # CSV output
whatweb --log-magictree=out.xml <url> # MagicTree XML
whatweb --log-sql=out.sql <url>       # SQL insert statements
whatweb --log-sql-create <url>        # SQL CREATE + INSERT
whatweb --log-errors=errors.txt <url> # Error log

AUTHENTICATION & PROXY#

whatweb --user=<user> --password=<pass> <url>
                                 # HTTP Basic Auth
whatweb --proxy=<host:port> <url>
                                 # HTTP proxy
whatweb --proxy-user=<u:p> <url> # Proxy authentication
whatweb -U <user-agent> <url>    # Custom User-Agent
whatweb --cookie=<cookie> <url>  # Set cookies
whatweb --header="X-Custom: val" <url>
                                 # Custom header

PERFORMANCE#

whatweb --max-threads=10 <url>   # Set max threads (default: 25)
whatweb --open-timeout=10 <url>  # Connection timeout (seconds)
whatweb --read-timeout=20 <url>  # Read timeout (seconds)
whatweb --wait=<seconds> <url>   # Wait between connections
whatweb --max-redirects=5 <url>  # Max HTTP redirects to follow

PLUGIN OPTIONS#

whatweb -l                       # List all plugins
whatweb --info-plugins=<name>    # Plugin details
whatweb -p <plugin1,plugin2> <url>
                                 # Use specific plugins only
whatweb --grep=<regex> <url>     # Custom grep plugin
whatweb --custom-plugin="..." <url>
                                 # Inline custom plugin

EXAMPLES#

# Quick website fingerprint
whatweb example.com

# Verbose scan with JSON output
whatweb -v --log-json=results.json example.com

# Aggressive scan with all details
whatweb -a 3 -v example.com

# Scan subnet for web servers
whatweb 192.168.1.0/24

# Scan with authentication
whatweb --user=admin --password=secret http://192.168.1.1/admin

# Scan through proxy
whatweb --proxy=127.0.0.1:8080 https://example.com

# Multiple targets from file
whatweb -i targets.txt --log-json=results.json

# Search for specific technology
whatweb -p WordPress example.com

DETECTED TECHNOLOGIES#

# Web Servers: Apache, Nginx, IIS, LiteSpeed
# CMS: WordPress, Drupal, Joomla, Magento
# Frameworks: Ruby on Rails, Django, Laravel, ASP.NET
# JS Libraries: jQuery, React, Angular, Vue.js
# Analytics: Google Analytics, Matomo, Hotjar
# Security: WAF indicators, security headers
# Server Info: PHP version, OS hints, headers
# And 1800+ more plugins...

NOTES#

- Ruby-based tool
- 1800+ recognition plugins
- Aggression level 1 is stealthy (single request)
- Level 3+ sends additional requests per technology
- Great for initial web application reconnaissance
- Can scan IP ranges and CIDR networks
- JSON output useful for automation and reporting
- Actively maintained