Skip to content

Go Witness

Web screenshot utility that uses Chrome headless to capture screenshots of websites at scale for recon.

Self-hostedNot yet verified
Report issue
GPL-3.0★ 2500Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Go Witness?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Go Witness?

GoWitness is an open-source tool written in Golang designed to capture screenshots of web interfaces using Chrome Headless. Its primary purpose is to automate the process of generating visual records of websites, enabling users to analyze web assets efficiently. Security professionals, penetration testers, and developers leverage GoWitness to streamline tasks such as vulnerability assessments, documentation of web applications, and forensic analysis. The tool addresses the challenge of manually capturing and documenting web interfaces by providing a command-line interface for batch processing URLs, CIDRs, and scan results from tools like Nmap and Nessus. It also collects metadata such as request logs, headers, and cookies, offering a comprehensive view of web interactions without requiring manual intervention.

How it works

GoWitness is a command-line utility that leverages Chrome Headless to generate screenshots of websites, supporting Linux and macOS with partial Windows compatibility. It is designed for users who need to automate the capture of web interfaces for analysis, auditing, or documentation. The tool's core purpose is to simplify the process of taking screenshots while gathering additional data such as HTTP headers, cookies, and console logs. This makes it valuable for tasks requiring both visual and technical insights into web resources. GoWitness can process URLs, CIDR ranges, Nmap scan results, and Nessus reports to generate screenshots and metadata. It supports batch processing, allowing users to scan multiple targets simultaneously. The tool also saves request logs, console outputs, and headers, providing a detailed record of web interactions.

How to use it

  1. 1Install Go and dependencies, then clone the repository from GitHub. 2. Build the tool using `go build` or a provided Dockerfile. 3. Run GoWitness with a list of URLs, CIDRs, or scan results as input. 4. Use the report viewer to analyze generated screenshots and metadata. Practical tips include using Docker for cross-platform consistency, specifying output directories for organized results, and leveraging configuration files for repeated tasks.

What it can do

  • web screenshot tool

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/sensepost/gowitness
  • license: GPL-3.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Limited Windows support may require additional configuration or dependencies.
  • Dependence on Chrome Headless could introduce compatibility issues with complex web frameworks.
  • No built-in GUI limits real-time interaction with generated screenshots.
  • Metadata collection may be incomplete for websites with heavy client-side rendering.
  • Batch processing large datasets may require optimization for performance.

Understanding the result

Web screenshot utility that uses Chrome headless to capture screenshots of websites at scale for recon.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (GPL-3.0).
Built with
(sensepost/gowitness)
License
GPL-3.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with sensepost/gowitness. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
GPL-3.0
View source on GitHub

Open-source project

License: GPL-3.0Source: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is the primary use case for GoWitness?

GoWitness is primarily used for automating the capture of web interface screenshots and metadata collection. It is ideal for security professionals conducting audits, developers documenting web applications, and testers analyzing web assets. Its ability to process URLs, CIDR ranges, and scan results makes it a versatile tool for tasks requiring both visual and technical data.

How does GoWitness handle complex web pages?

GoWitness uses Chrome Headless to render web pages, which supports modern web standards and JavaScript execution. However, highly dynamic or heavily client-side rendered pages may require additional configuration or dependencies to ensure accurate rendering. The tool prioritizes speed and accuracy but may need manual adjustments for edge cases.

How do I generate a report with GoWitness?

After running GoWitness with a list of URLs or scan results, the tool automatically generates a structured report. To view it, navigate to the output directory and open the HTML report file. The report includes screenshots, request logs, headers, cookies, and other metadata. Use command-line flags to customize the report's format or output location.

How does GoWitness compare to tools like Selenium or Puppeteer?

GoWitness is optimized for speed and simplicity, using Chrome Headless for screenshot generation without requiring extensive scripting. Unlike Selenium or Puppeteer, which offer broader automation capabilities, GoWitness focuses on capturing and analyzing web interfaces with minimal configuration. It is better suited for tasks prioritizing rapid batch processing over complex browser automation.

What should I do if GoWitness fails to render a page?

If a page fails to render, check for dependencies like Chrome Headless and ensure the target URL is accessible. Verify that the page does not rely on non-standard JavaScript or external resources that may cause rendering issues. Use the `--debug` flag to enable verbose logging and identify specific errors. For complex pages, consider manual intervention or alternative tools for deeper analysis.

Spotted something wrong with Go Witness, or want to maintain it? See how to help.