dirhunt

Web directory scanner

A tool to discover hidden directories on web servers without sending unnecessary requests

Find web directories without bruteforce

GitHub

2k stars
33 watching
255 forks
Language: Python
last commit: about 1 year ago
Linked from 1 awesome list

crawlerdirscannerpentestingpythonsecuritysecurity-toolswebsecwithout-bruteforce

Backlinks from these awesome lists:

Related projects:

Repository Description Stars
reddyyz/urlbrute A tool to scan and brute-force directories and subdomains on websites 48
digination/dirbuster-ng A CLI tool that scans websites for hidden directories and files using a brute-force approach. 343
cybercdh/dirlstr Traverses URL paths to detect exposed directories or open S3 buckets 51
diogo-fernan/domfind A tool to find identical domain names with SOA DNS records under different TLDs 24
darryllane/bluto Tools for gathering information about and exploiting vulnerabilities in domains 619
edoardottt/cariddi A tool for crawling and scanning websites for sensitive information such as endpoints, secrets, and tokens. 1,540
paulmillr/readdirp Provides an efficient way to recursively traverse and inspect the contents of directories in a streaming or promise-based manner. 383
0xbillyyy/scandir A tool designed to scan directories and detect sensitive files using PHP. 0
gennaro-tedesco/archimede Displays concise information about a directory structure and file composition. 44
diablohorn/yara4pentesters A tool to identify files containing sensitive information using YARA rules 124
stefanoj3/dirstalk A tool designed to brute force paths on web servers using multiple threads. 375
evilsocket/dirsearch A Go-based tool for concurrent HTTP enumeration of directories and files using a wordlist. 269
danmcinerney/fast-recon Automates the process of searching for sensitive files using Google dorks on a given domain 163
anirudhbiyani/findmytakeover Detects DNS record misconfigurations that could be exploited by attackers 135
blark/aiodnsbrute A tool for brute-forcing domain names by sending DNS queries asynchronously 646