feroxbuster_scan
Scan target URLs to discover hidden directories and files using configurable wordlists, recursion, and filters, executed remotely via SSH.
Instructions
Start a feroxbuster directory scan against a target URL. Executes on remote Kali system via SSH.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Target URL to scan (e.g., http://example.com) | |
| wordlist | No | Path to wordlist on Kali (default: /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt) | |
| extensions | No | File extensions to check (e.g., ['php', 'html', 'js']) | |
| recursion_depth | No | Maximum recursion depth (0 = infinite, default: 4) | |
| threads | No | Number of concurrent threads (default: 50) | |
| timeout | No | Request timeout in seconds (default: 7) | |
| rate_limit | No | Maximum requests per second per directory | |
| filter_status | No | Status codes to filter OUT (exclude from results) | |
| status_codes | No | Status codes to include (default: 200,204,301,302,307,308,401,403,405,500) | |
| filter_size | No | Response sizes to filter OUT | |
| filter_words | No | Word counts to filter OUT | |
| filter_lines | No | Line counts to filter OUT | |
| headers | No | Custom headers to include (e.g., {"Authorization": "Bearer token"}) | |
| proxy | No | Proxy URL (e.g., http://127.0.0.1:8080 or socks5://127.0.0.1:9050) | |
| insecure | No | Disable TLS certificate validation | |
| no_recursion | No | Disable recursive scanning | |
| force_recursion | No | Force recursion on all found paths | |
| auto_tune | No | Automatically lower scan rate on errors | |
| auto_bail | No | Automatically stop on excessive errors | |
| silent | No | Only output URLs (for piping) | |
| json | No | Output results as JSON | |
| background | No | Run scan in background and return immediately | |
| dont_scan | No | URLs to exclude from recursion | |
| time_limit | No | Maximum scan time (e.g., '10m', '1h', '30s') | |
| scan_limit | No | Maximum concurrent directory scans | |
| user_agent | No | Custom User-Agent string | |
| cookies | No | Cookies to include (e.g., 'session=abc123; token=xyz') | |
| data | No | Request body data for POST requests | |
| methods | No | HTTP methods to use (default: GET) | |
| query | No | Query parameters to append (e.g., 'token=abc&debug=true') |