Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dalfox — Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via CLI, pipeline, or REST API. | Kitploit
Tools/GitHubGitHub/hahwul/dalfox
Web Vulnerability ScannersVulnerability AnalysisDynamic Code Analysis (DAST)Web Application ExploitationWAF BypassWeb SecurityPenetration TestingDevSecOps
GitHubhahwul/dalfox

dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via CLI, pipeline, or REST API.

View Repository
5.2k55691 day agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

dalfox

Looking for the Go (v2.x) version? Dalfox v3 is a complete rewrite in Rust. The Go codebase is preserved on the v2 branch and continues to receive security backports. See SECURITY.md for the support policy, and the migration guide for what changed in v3.

Dalfox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities.

Key features

  • Subcommands: scan (URL / file / pipe / raw-HTTP, auto-detected), server, payload, mcp
  • Discovery: Parameter analysis, static analysis, BAV testing, parameter mining
  • XSS Scanning: Reflected, Stored (SXSS), DOM-based, with optimization and DOM/AST verification
  • WAF: Fingerprinting with confidence scoring, bypass tracking, and tunable --waf-min-confidence
  • HTTP Options: Custom headers, cookies, methods, proxy, and more
  • Output: JSON/JSONL/Plain/Markdown/SARIF/TOML formats, silence mode, detailed reports
  • Extensibility: REST API, MCP stdio server, custom payloads, remote wordlists

And the various options required for the testing :D

Installation

Homebrew (macOS/Linux)

root@kitploit:~
brew install dalfox

# https://formulae.brew.sh/formula/dalfox

Snapcraft (Ubuntu)

root@kitploit:~
sudo snap install dalfox

Arch Linux (AUR)

root@kitploit:~
yay -S dalfox
# or
paru -S dalfox

See the Installation guide for manual build instructions.

Nixpkgs (NixOS)

A package is available for Nix or NixOS users. Keep in mind that the latest releases might only be present in the unstable channel.

root@kitploit:~
nix-shell -p dalfox

Nix Flakes

For Nix users with flakes enabled:

root@kitploit:~
# Run directly
nix run github:hahwul/dalfox -- scan https://example.com

# Install
nix profile install github:hahwul/dalfox

# Development environment for hacking on Dalfox itself
git clone https://github.com/hahwul/dalfox && cd dalfox && nix develop

The flake also exposes overlays.default, so NixOS and home-manager users can build Dalfox against their own nixpkgs. See the Installation guide for that module snippet and the rest of the details.

Prebuilt binaries (including statically-linked musl variants for Linux) are available on the GitHub Releases page.

Usage

root@kitploit:~
dalfox [mode] [target] [flags]
  • Single URL: dalfox scan http://example.com -b https://callback
  • File Mode: dalfox scan urls.txt --custom-payload mypayloads.txt
  • Pipeline: cat urls.txt | dalfox scan --headers "AuthToken: xxx"
  • Custom injection point (query): dalfox scan 'https://example.com/?q=FUZZ&page=1' --inject-marker FUZZ
  • Custom injection point (header): dalfox scan https://example.com -H 'X-Search: FUZZ' --inject-marker FUZZ

Check the CLI reference and Quick start documents for more examples.

Contributing

if you want to contribute to this project, please see CONTRIBUTING.md and Pull-Request with cool your contents.

About the Name

The name comes from 'Dal' (달) 🌙, the Korean word for 'moon', combined with 'Fox' 🦊.

Download Tool