Skip to content

Feroxbuster

Fast, simple, recursive content discovery tool written in Rust.

Self-hostedNot yet verified
Report issue
MIT★ 6800Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Feroxbuster?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Feroxbuster?

Feroxbuster is an open-source, fast, and recursive content discovery tool written in Rust, designed for forced browsing attacks. It enables security professionals and ethical hackers to enumerate unlinked resources on target websites by leveraging brute-force techniques combined with custom wordlists. The tool systematically scans directories and files to uncover sensitive information such as source code, credentials, or internal network details that may not be explicitly referenced in a website’s structure. Its primary purpose is to identify predictable resource locations, aiding in penetration testing and vulnerability assessments. Feroxbuster is widely used by cybersecurity experts to simulate real-world attacks, helping organizations strengthen their defenses against potential threats. By automating the discovery process, it addresses the challenge of manually sifting through vast web infrastructures to find exploitable assets.

How it works

Feroxbuster is a tool for forced browsing, a technique used to access unlinked resources on a target website. It uses brute-force methods with custom wordlists to discover hidden files and directories, such as configuration files or internal documentation. The tool is primarily used by penetration testers and security researchers to identify vulnerabilities in web applications. It helps uncover sensitive data that may be exposed through unsecured or poorly configured servers. Feroxbuster supports recursive scanning, allowing it to explore nested directories efficiently. It can handle large-scale targets and provides real-time output for quick analysis. The tool also includes options for customizing wordlists, setting recursion depth, and specifying output formats like JSON or plain text.

How to use it

  1. 1Install Feroxbuster via package managers (e.g., Kali Linux tools) or download binaries from official repositories. 2. Run the tool with a target URL and a wordlist: `feroxbuster -u https://target.com -w /path/to/wordlist.txt`. 3. Use options like `--recursive` to enable deep scanning and `--output` to specify the results format. 4. Monitor the output for discovered files or directories, and verify their accessibility through follow-up checks. Practical tips include using the latest version for improved features, avoiding overly large wordlists to prevent timeouts, and combining results with other tools like DirBuster for cross-verification.

What it can do

  • recursive content discovery

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/epi052/feroxbuster
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Requires a comprehensive and relevant wordlist for effective results
  • May generate false positives, necessitating manual verification of findings
  • Resource-intensive for extremely large or complex web infrastructures
  • Depends on the target’s server configuration and response behavior

Understanding the result

Fast, simple, recursive content discovery tool written in Rust.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(epi052/feroxbuster)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with epi052/feroxbuster. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Feroxbuster used for?

Feroxbuster is used for forced browsing attacks to discover unlinked files and directories on a target website. It helps security professionals identify sensitive data, such as configuration files or credentials, that may be exposed through unsecured or misconfigured servers. This tool is essential for penetration testing and vulnerability assessments.

How does Feroxbuster work?

Feroxbuster works by using brute-force techniques combined with a wordlist to guess potential file and directory names. It sends requests to the target server and analyzes responses to identify accessible resources. The tool recursively scans directories, allowing it to uncover hidden content that may not be referenced in the website’s HTML. Its Rust-based design ensures efficiency and speed, even for large-scale targets.

How do I run Feroxbuster with a custom wordlist?

To run Feroxbuster with a custom wordlist, use the `-w` flag followed by the path to your wordlist file. For example: `feroxbuster -u https://target.com -w /path/to/wordlist.txt`. Ensure the wordlist contains potential directory and file names. You can also customize recursion depth with `--recursive` and specify output formats using `--output`.

How does Feroxbuster compare to alternatives like DirBuster?

Feroxbuster is faster and more efficient than DirBuster due to its Rust-based architecture, which allows for better performance. It also supports recursive scanning and customizable wordlists, making it more versatile for large-scale targets. DirBuster, written in Java, is older and less optimized for modern web infrastructures. Feroxbuster’s integration with Kali Linux and other repositories also simplifies deployment for security professionals.

How do I troubleshoot common errors in Feroxbuster?

Common errors include connection timeouts, which can be resolved by checking the target URL and network stability. If the tool fails to find results, verify the wordlist’s relevance and try a different one. For permission issues, ensure the target server allows access to the scanned resources. Updating to the latest version via GitHub or package managers can also resolve compatibility or bug-related problems.

Spotted something wrong with Feroxbuster, or want to maintain it? See how to help.