Content Discovery
content_discoveryFind hidden web directories and files by brute-forcing paths with a chosen wordlist, using rate-limited ffuf scans that require human approval before execution.
Instructions
[AGGRESSIVE — requires human approval] Brute-force paths with ffuf, at the engagement's rate limit.
wordlist is either a name from the vetted payload store ("admin",
"juicy-paths", "api-routes" — call payload_catalog for the list) or a
path to a file inside the engagement workspace.
There is no default. The size of the wordlist is the size of the impact on the target, and that should be a deliberate choice.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes | ||
| wordlist | Yes | ||
| extensions | No | ||
| max_seconds | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||