Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
feroxbuster — A fast, simple, recursive content discovery tool written in Rust. | Kitploit
Tools/GitHubGitHub/epi052/feroxbuster
ReconnaissanceInformation GatheringWeb SecurityPenetration Testing
GitHubepi052/feroxbuster

feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

View RepositoryWebsite
8.0k6314 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

[!WARNING] Security Notice – Domain Impersonation

The domain feroxbuster.com is NOT affiliated with this project, its maintainers, or any official feroxbuster releases.

Official feroxbuster downloads are distributed ONLY through:

  • https://github.com/epi052/feroxbuster (open source)
  • https://www.feroxbuster.pro (commercial)
  • package repositories listed in this README
  • package repositories listed in the installation docs

We do not distribute software from feroxbuster.com, and we cannot vouch for the authenticity or safety of files hosted there. If you downloaded feroxbuster from any other domain, we strongly recommend deleting it and reinstalling from an official source.


feroxbuster

A simple, fast, recursive content discovery tool written in Rust

github downloads

demo

Releases  Example Usage  Contributing  Documentation  Pro


[!TIP] Documentation has moved! — Instead of having a 1300 line README.md (sorry...), feroxbuster's documentation has moved to GitHub Pages. The move to hosting documentation on Pages should make it a LOT easier to find the information you're looking for, whatever that may be. Please check it out for anything you need beyond a quick-start.

View the full documentation →

What the heck is a ferox anyway?

Ferox is short for Ferric Oxide. Ferric Oxide, simply put, is rust. The name rustbuster was taken, so I decided on a variation.

What's it do tho?

feroxbuster is a tool designed to perform Forced Browsing.

Forced browsing is an attack where the aim is to enumerate and access resources that are not referenced by the web application, but are still accessible by an attacker.

feroxbuster uses brute force combined with a wordlist to search for unlinked content in target directories. These resources may store sensitive information about web applications and operational systems, such as source code, credentials, internal network addressing, etc...

This attack is also known as Predictable Resource Location, File Enumeration, Directory Enumeration, and Resource Enumeration.

Quick Start

This section will cover the minimum amount of information to get up and running with feroxbuster. Please refer the the documentation, as it's much more comprehensive.

Installation

There are quite a few other installation methods, but these snippets should cover the majority of users.

Kali

If you're using kali, this is the preferred install method. Installing from the repos adds a ferox-config.toml in /etc/feroxbuster/, adds command completion for bash, fish, and zsh, includes a man page entry, and installs feroxbuster itself.

root@kitploit:~
sudo apt update && sudo apt install -y feroxbuster

Linux (32 and 64-bit) & MacOS

Install to a particular directory

root@kitploit:~
curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash -s $HOME/.local/bin

Install to current working directory

root@kitploit:~
curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash

MacOS via Homebrew

root@kitploit:~
brew install feroxbuster

Windows x86_64

root@kitploit:~
Invoke-WebRequest https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-windows-feroxbuster.exe.zip -OutFile feroxbuster.zip
Expand-Archive .\feroxbuster.zip
.\feroxbuster\feroxbuster.exe -V

Windows via Winget

root@kitploit:~
winget install epi052.feroxbuster

Windows via Chocolatey

root@kitploit:~
choco install feroxbuster

All others

Please refer the the documentation.

Updating feroxbuster (new in v2.9.1)

root@kitploit:~
./feroxbuster --update

Example Usage

Here are a few brief examples to get you started. Please note, feroxbuster can do a lot more than what's listed below. As a result, there are many more examples, with demonstration gifs that highlight specific features, in the documentation.

Multiple Values

Options that take multiple values are very flexible. Consider the following ways of specifying extensions:

root@kitploit:~
./feroxbuster -u http://127.1 -x pdf -x js,html -x php txt json,docx

The command above adds .pdf, .js, .html, .php, .txt, .json, and .docx to each url

All of the methods above (multiple flags, space separated, comma separated, etc...) are valid and interchangeable. The same goes for urls, headers, status codes, queries, and size filters.

Include Headers

root@kitploit:~
./feroxbuster -u http://127.1 -H Accept:application/json "Authorization: Bearer {token}"

IPv6, non-recursive scan with INFO-level logging enabled

root@kitploit:~
./feroxbuster -u http://[::1] --no-recursion -vv

Read urls from STDIN; pipe only resulting urls out to another tool

root@kitploit:~
cat targets | ./feroxbuster --stdin --silent -s 200 301 302 --redirects -x js | fff -s 200 -o js-files

Proxy traffic through Burp

root@kitploit:~
./feroxbuster -u http://127.1 --insecure --proxy http://127.0.0.1:8080

Proxy traffic through a SOCKS proxy (including DNS lookups)

root@kitploit:~
./feroxbuster -u http://127.1 --proxy socks5h://127.0.0.1:9050

Pass auth token via query parameter

root@kitploit:~
./feroxbuster -u http://127.1 --query token=0123456789ABCDEF

Set the Content-Type of the body automatically with --data-json --data-urlencoded

root@kitploit:~
./feroxbuster -u http://127.1 --data-json '{"some": "payload"}'
./feroxbuster -u http://127.1 --data-json @payload.json
./feroxbuster -u http://127.1 --data-urlencoded 'some=payload'
./feroxbuster -u http://127.1 --data-urlencoded @file.payload

[!TIP] For realsies, there used to be over 1300 lines in this README, but it's all been moved to the new documentation site. Go check it out!

View the full documentation →

Contributors

Thanks goes to these wonderful people (emoji key):

This project follows the all-contributors specification. Contributions of any kind welcome!

Download Tool
Joona Hoikkala
Joona Hoikkala

📖
J Savage
J Savage

🚇 📖
Thomas Gotwig
Thomas Gotwig

🚇 📖
Spike
Spike

🚇 📖
Evan Richter
Evan Richter

💻 📖
AG
AG

🤔 📖
Nicolas Thumann
Nicolas Thumann

💻 📖
Tom Matthews
Tom Matthews

📖
bsysop
bsysop

📖
Brian Sizemore
Brian Sizemore

💻
Alexandre ZANNI
Alexandre ZANNI

🚇 📖
Craig
Craig

🚇
EONRaider
Tib3rius
Tib3rius

🐛 🤔
0xdf
0xdf

🐛
secure-77
secure-77

🐛
Sophie Brun
Sophie Brun

🚇
black-A
black-A

🤔
Nicolas Krassas
mchill
mchill

🐛
Naman
Naman

🐛
Ayoub Elaich
Ayoub Elaich

🐛
Henry
Henry

🐛
SleepiPanda
SleepiPanda

🐛
Bad Requests
Muhammad Ahsan
Muhammad Ahsan

🐛
cortantief
cortantief

🐛 💻
Daniel Saxton
Daniel Saxton

🤔 💻
n0kovo
n0kovo

🤔 🐛
Justin Steven
Justin Steven

🤔
0x08
0x08

🤔
kusok
kusok

🤔 💻
godylockz
godylockz

🤔 💻
Ryan Montgomery
Ryan Montgomery

🤔
ippsec
ippsec

🤔
James
Limn0
Limn0

🐛
0xdf
0xdf

🐛 🤔
Flangyver
Flangyver

🤔
PeakyBlinder
PeakyBlinder

🤔
Postmodern
Postmodern

🤔
O
O

kmanc
kmanc

🐛 💻
hakdogpinas
hakdogpinas

🤔
多可悲
多可悲

🤔
Aidan Hall
Aidan Hall

💻 🚇
João Ciocca
João Ciocca

🐛 🤔
f3rn0s
xaeroborg
xaeroborg

🤔
Luoooio
Luoooio

🤔
Aan
Aan

💻 🚇 🤔
Simon
Simon

🐛
Nicolas Christin
Nicolas Christin

🐛
DrDv
Himadri Bhattacharjee
Himadri Bhattacharjee

💻 🤔
Samy Lahfa
Samy Lahfa

🤔
sectroyer
sectroyer

🐛 🤔
ktecv2000
ktecv2000

🐛
Andrea De Murtas
Andrea De Murtas

💻
sawmj
Olivier Cervello
Olivier Cervello

🤔
RavySena
RavySena

🤔
Florian Stuhlmann
Florian Stuhlmann

🐛
Mister7F
Mister7F

🤔
manugramm
manugramm

🐛
ArthurMuraro
ArthurMuraro

🐛
dirhamgithub
dirhamgithub

🐛
FieldOfRice
FieldOfRice

🚇
Matt
Matt

🤔
Sam Leonard
Sam Leonard

💻
Rewinter
Rewinter

🤔
deadloot
deadloot

🤔
Julián Gómez
Julián Gómez

🤔 🚇 📖
Petros
Petros

🐛
Ryan
Ryan

🚇 📖
wikamp-collaborator
wikamp-collaborator

🤔 🚇
Lino
Lino

🐛 🤔
Patrick Klein
Patrick Klein

🤔
Raymond
Raymond

🤔
zer0x64
zer0x64

💻
zar3bski
zar3bski

💻 🤔
karanabe
karanabe

📖 💻
h121h
Wilco
Wilco

🐛
HenriBom
HenriBom

🐛
R̝͖̱͖͕̤̰̯͙ͫ͒̀ͮȁ̤͔̝̘̪̻͕̝̖ͧͪͤu̗̠̜̩̗͇͑̀ͣ̃͂̔͂c̫͔͚̲̬̓̂̿͌̿͊̐͗h͚̲̤̟͓̟̥̊ͬͪ̏̍̍ T̟̜̞͉͙̙ͣ́ͪ͗̓̇ͭo͍̰͎̼͓̟̽ͧ̓̉ͬ̐͐b͇̖̳̫̰̗̭͍ͧ̄̄̌̈i̙̪̤̝̟͓̹̋̽͋̀ͧ̒a͕̭̱͎̪̦̤ͤ͊̊̑ͣ̄s̪̯͖̰̯͍ͫ̋͑̄ͭͅͅ
R̝͖̱͖͕̤̰̯͙ͫ͒̀ͮȁ̤͔̝̘̪̻͕̝̖ͧͪͤu̗̠̜̩̗͇͑̀ͣ̃͂̔͂c̫͔͚̲̬̓̂̿͌̿͊̐͗h͚̲̤̟͓̟̥̊ͬͪ̏̍̍ T̟̜̞͉͙̙ͣ́ͪ͗̓̇ͭo͍̰͎̼͓̟̽ͧ̓̉ͬ̐͐b͇̖̳̫̰̗̭͍ͧ̄̄̌̈i̙̪̤̝̟͓̹̋̽͋̀ͧ̒a͕̭̱͎̪̦̤ͤ͊̊̑ͣ̄s̪̯͖̰̯͍ͫ̋͑̄ͭͅͅ

🐛 🤔 📖
4FunAndProfit
4FunAndProfit

🤔
lidorelias3
lidorelias3
pg9051
pg9051

📖
Sebastiaan Speck
Sebastiaan Speck

🐛 📖
OpenSourceKyle
OpenSourceKyle

📖 🐛
Antonio
Antonio

💻 🐛
Redacean
Redacean

EONRaider

🚇
wtwver
wtwver

🚇
Nicolas Krassas

🤔
N0ur5
N0ur5

🤔 🐛

Bad Requests

🐛
Dominik Nakamura
Dominik Nakamura

🚇
7047payloads

7047payloads

💻
unkn0wnsyst3m
unkn0wnsyst3m

🤔
James

🐛
Jason Haddix
Jason Haddix

🤔 🐛
💻
John-John Tedro
John-John Tedro

💻

f3rn0s

🐛
LongCat
LongCat

🤔

DrDv

🐛
Antoine Roly
Antoine Roly

🤔

sawmj

🐛
Zach Hanson
Zach Hanson

🐛
Shadow
Shadow

🐛
Spidle
Spidle

🤔
Dan Salmon
Dan Salmon

🤔
swordfish0x0
swordfish0x0

🤔

h121h

🤔
s0i37
s0i37

🤔

🤔
Adnan Ullah Khan (auk0x01)
Adnan Ullah Khan (auk0x01)

💻
Martin Žember
Martin Žember

🐛

🐛
ghsdpolley
ghsdpolley

🐛
Daniel Aldam
Daniel Aldam

💻