
Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities.

Panoptic is an open source penetration testing tool that automates the search and retrieval of common log and config files through path traversal vulnerabilities.

--concurrency)FUZZ
in any --header or --data value--base64)/etc/passwd for home directory
files, mysql-bin.index for binlog files--output-format)--resume-file)--config)0600 permissions on
POSIX and final-component symlink protection where the OS supports it--update)httpx[socks], rich, rich-argparse, and
tomli on Python 3.10git clone https://github.com/lightos/Panoptic.git
cd Panoptic
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -e .
panoptic --version
On Windows Command Prompt, activate with .venv\Scripts\activate.bat;
in PowerShell, use .venv\Scripts\Activate.ps1. The editable install keeps
Panoptic connected to this checkout for --update, so keep the directory
in place. Do not run pip install panoptic: that PyPI name belongs to an
unrelated project.
For development:
python -m pip install -e ".[dev]"
panoptic --url "http://target/include.php?file=test.txt"
panoptic --url "http://target/include.php?file=test.txt"
panoptic --url "http://target/include.php?file=test.txt&id=1" \
--param file
panoptic --url "http://target/include.php" \
--data "file=test.txt&id=1" --param file
panoptic --url "http://target/view.php/test.txt" --path-based
panoptic --url "http://target/load.php?file=dGVzdC50eHQ=" \
--base64 --auto
panoptic --url "http://target/page.php" \
--header "Cookie: lang=FUZZ" --auto
panoptic --url "http://target/api/load" \
--data '{"file":"FUZZ"}' --auto
panoptic --url "http://target/page.php" \
--header "X-Template: FUZZ" --auto
panoptic --url "http://target/view.php?file=test&type=txt" \
--param file --ext-param type
panoptic --url "http://target/filtered.php?file=test.txt" \
--prefix "....//....//....//....//"
panoptic --url "http://target/include.php?file=test.txt" \
--os "*NIX" --type conf
panoptic --url "http://target/include.php?file=test.txt" \
--software PostgreSQL
panoptic --url "http://target/include.php?file=test.txt" \
--output-format json --output-file results.json \
--resume-file scan.checkpoint
panoptic --url "https://target/include.php?file=test.txt" \
--proxy "socks5://127.0.0.1:9050" --invalid-ssl
panoptic --list software
panoptic --list category
panoptic --list os
panoptic --url "http://target/include.php?file=test.txt" \
--auto --all-versions --concurrency 8
Place FUZZ anywhere in --header or --data values to mark
the injection point. Panoptic replaces FUZZ with each file path
during scanning. This enables testing injection points that
--param can't reach:
| Injection Type | Example |
|---|---|
| Cookie value | --header "Cookie: theme=FUZZ" |
| Custom header | --header "X-Include: FUZZ" |
| JSON body | --data '{"template":"FUZZ"}' |
| Nested value | --header "Cookie: sid=abc; lang=FUZZ" |
When FUZZ is present, --param is not required.
Panoptic supports TOML config files for persistent settings:
panoptic --url "http://target/include.php?file=test.txt" \
--config ~/.config/panoptic/config.toml
Default config location: ~/.config/panoptic/config.toml (loaded
automatically when present, even without --config).
[defaults]
# Any long option name (with dashes as underscores) is accepted here,
# including the target and output destinations.
url = "http://target/include.php?file=test.txt"
concurrency = 8
verbose = true
automatic = true
all_versions = true
output_format = "json"
output_file = "results.json"
log_file = "scan.log"
resume_file = "scan.checkpoint"
[proxy]
url = "socks5://127.0.0.1:9050"
[headers]
user_agent = "Mozilla/5.0"
cookie = "sid=foobar; auth=1"
values = ["X-Forwarded-For: 127.0.0.1"]
Priority: CLI args > config file > built-in defaults.
The [defaults] table accepts any scan option, not just performance
tuning. In particular you can persist:
url — the default target (override per-run with --url)output_format, output_file — where machine-readable results golog_file — mirror console output to a fileresume_file — checkpoint location for resumable scansSensitive artifacts written by Panoptic — the log file, the results/list
output file, and any files saved with --write-files — are forced to
owner-only 0600 permissions on POSIX. Platforms exposing O_NOFOLLOW
also atomically refuse a pre-existing symlink at the final path component.
On platforms without O_NOFOLLOW, Panoptic performs a best-effort
pre-open symlink/junction check, but the check cannot eliminate a race.
Windows mode bits do not configure NTFS ACLs, so use an appropriately
restricted directory when artifacts may contain sensitive data.