Eye Witness
Webscreenshot tool for reconnaissance that captures screenshots of multiple websites for analysis.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with Eye Witness?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Eye Witness?
EyeWitness is an open-source web tool designed to automate the process of capturing screenshots of websites while gathering additional technical data about their underlying infrastructure. Its primary purpose is to assist security researchers, penetration testers, and system administrators in assessing web assets for potential vulnerabilities. The tool addresses the challenge of manually inspecting websites by streamlining the collection of visual and server-side information, which is critical for tasks like security audits and penetration testing. By integrating Chromium-based rendering, EyeWitness ensures reliable headless browser execution, making it a valuable asset for users who need consistent and repeatable results. The project’s cross-platform support and modular design cater to a wide range of users, from individual developers to enterprise teams, enabling them to analyze web resources efficiently without requiring complex setups.
How it works
EyeWitness is a command-line interface (CLI) tool that leverages Chromium to generate screenshots of websites and extract server header information. It is particularly useful for identifying default credentials in web applications, which can expose critical security weaknesses. The tool is maintained under the GNU General Public License v3.0, ensuring transparency and community-driven development. Its primary users include cybersecurity professionals and developers who need to evaluate web assets for compliance, security, or documentation purposes. EyeWitness captures high-resolution screenshots of websites, supports URL validation to filter invalid targets, and provides detailed server header data such as HTTP status codes and response headers. It also checks for known default credentials in web interfaces, which is essential for identifying misconfigured systems.
How to use it
- 1Clone the repository from GitHub using `git clone https://github.com/RedSiege/EyeWitness.git`.
- 2Install dependencies, including Chromium and Python libraries, as outlined in the INSTALLATION.md file.
- 3Run the tool via CLI with a list of URLs, using the `-u` flag to specify targets.
- 4Review output files, which include screenshots, server headers, and credential detection results. Practical tips: Use the `-c` flag to load a custom configuration file, and validate URLs before scanning to avoid errors. Monitor progress tracking metrics to estimate completion times for large-scale tasks.
What it can do
- web screenshot tool
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/FortyNorthSecurity/EyeWitness
- license: GPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
- Dependent on Chromium’s compatibility with modern web standards, which may introduce rendering inconsistencies
- Limited support for dynamic JavaScript-heavy websites that require user interaction
- Potential false positives in credential detection due to heuristic-based matching algorithms
- Requires manual setup of dependencies, which may be time-consuming for novice users
Understanding the result
Webscreenshot tool for reconnaissance that captures screenshots of multiple websites for analysis.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (GPL-3.0).
- Built with
- (FortyNorthSecurity/EyeWitness)
- License
- GPL-3.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with FortyNorthSecurity/EyeWitness. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- GPL-3.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-3.0 License
Upstream project
Frequently asked
What types of websites can EyeWitness analyze?
EyeWitness can analyze websites that are accessible via standard HTTP/HTTPS protocols. It supports static and dynamic content rendered by Chromium, but may struggle with highly interactive JavaScript-heavy sites or those requiring user authentication beyond basic credentials. The tool is optimized for public-facing assets but requires manual adjustments for private or protected resources.
How does EyeWitness handle server header information?
EyeWitness uses Chromium’s network stack to intercept and parse HTTP/HTTPS headers during screenshot generation. It captures headers such as `Server`, `Content-Type`, and `X-Powered-By` to provide insights into the underlying infrastructure. This data is saved alongside screenshots, enabling users to correlate visual and technical details for analysis.
How do I scan multiple URLs at once?
To scan multiple URLs, create a text file with each URL on a separate line and use the `-u` flag followed by the file path. For example: `python eyewitness.py -u targets.txt`. The tool processes all URLs sequentially, displaying progress updates and saving results in a structured format.
How does EyeWitness compare to commercial tools like SiteCrawler or Screaming Frog?
EyeWitness focuses on screenshot capture and header analysis, whereas tools like Screaming Frog prioritize comprehensive crawl data and SEO metrics. Commercial alternatives often offer advanced features like authentication support or real-time reporting, which EyeWitness lacks due to its open-source constraints. However, EyeWitness excels in simplicity and integration with Chromium for reliable visual verification.
What should I do if EyeWitness fails to load a URL?
If a URL fails to load, verify its validity using the URL validation feature. Check for typos or unreachable domains. If the site requires authentication, ensure you’ve configured proxy settings or modified the tool’s configuration file to bypass restrictions. Review error logs for specific issues like network timeouts or CORS policy violations.