Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
insect — High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable wordlists, filters, and recursive scanning for penetration testing. | Kitploit
Tools/GitHubGitHub/nu11secur1ty/insect
ReconnaissanceVulnerability ScannersInformation GatheringWeb SecurityFuzzingPenetration Testing
GitHubnu11secur1ty/insect

insect

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable wordlists, filters, and recursive scanning for penetration testing.

View Repository
1513 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

insect - Web path discovery

Current Release: v1.4 (20222.09.03)

An advanced command-line tool designed to brute force directories and files in webservers, AKA web path scanner

Idea by @maurosoria and @shelld3v

Developement-2022 is being actively developed by @nu11secur1ty

Table of Contents

  • Installation
  • Wordlists
  • Options
  • Configuration
  • How to use
    • Simple usage
    • Pausing progress
    • Recursion
    • Threads
    • Prefixes / Suffixes
    • Blacklist
    • Filters
    • Raw request
    • Wordlist formats
    • Exclude extensions
    • Scan sub-directories
    • Proxies
    • Reports
    • More example commands
  • Support Docker
    • Install Docker Linux
    • Build Image insect
    • Using insect
  • References
  • Tips
  • Contribution
  • License

Tools:

  • Attack-Modules-2022

Installation & Usage

Requirement: python 3.10.5 or higher

Choose one of these installation options:

  • Install with git: git clone https://github.com/nu11secur1ty/insect.git --depth 1 (RECOMMENDED)
  • Install with ZIP file: Download here
  • Install with Docker: docker build -t "insect:latest" . (more information can be found here)

Installing from a package manager:

  • Install with PyPi: pip3 install dirsearch
  • Install with Kali Linux: sudo apt-get install dirsearch (deprecated)

Wordlists (IMPORTANT)

Summary:

  • Wordlist is a text file, each line is a path.
  • About extensions, unlike other tools, dirsearch and insect only replaces the %EXT% keyword with extensions from -e flag.
  • For wordlists without %EXT% (like SecLists), -f | --force-extensions switch is required to append extensions to every word in wordlist, as well as the /.
  • To apply your extensions to wordlist entries that have extensions already, use -O | --overwrite-extensions (Note: some extensions are excluded from being overwritted such as .log, .json, .xml, ... or media extensions like .jpg, .png)
  • To use multiple wordlists, you can separate your wordlists with commas. Example: wordlist1.txt,wordlist2.txt.

Examples:

  • Normal extensions:
index.%EXT%

Passing asp and aspx as extensions will generate the following dictionary:

index
index.asp
index.aspx
  • Force extensions:
admin

Passing php and html as extensions with -f/--force-extensions flag will generate the following dictionary:

admin
admin.php
admin.html
admin/
  • Overwrite extensions:
login.html

Passing jsp and jspa as extensions with -O/--overwrite-extensions flag will generate the following dictionary:

login.html
login.jsp
login.jspa

Options

Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]

Options:
  --version             show program's version number and exit
  -h, --help            show this help message and exit

  Mandatory:
    -u URL, --url=URL   Target URL(s), support multiple flags
    -l PATH, --url-file=PATH
                        URL list file
    --stdin             Read URL(s) from STDIN
    --cidr=CIDR         Target CIDR
    --raw=PATH          Load raw HTTP request from file (use `--scheme` flag
                        to set the scheme)
    -s SESSION_FILE, --session=SESSION_FILE
                        Session file
    --config=PATH       Full path to config file, see 'config.ini' for
                        example (Default: config.ini)

  Dictionary Settings:
    -w WORDLISTS, --wordlists=WORDLISTS
                        Customize wordlists (separated by commas)
    -e EXTENSIONS, --extensions=EXTENSIONS
                        Extension list separated by commas (e.g. php,asp)
    -f, --force-extensions
                        Add extensions to the end of every wordlist entry. By
                        default insect only replaces the %EXT% keyword with
                        extensions
    -O, --overwrite-extensions
                        Overwrite other extensions in the wordlist with your
                        extensions (selected via `-e`)
    --exclude-extensions=EXTENSIONS
                        Exclude extension list separated by commas (e.g.
                        asp,jsp)
    --remove-extensions
                        Remove extensions in all paths (e.g. admin.php ->
                        admin)
    --prefixes=PREFIXES
                        Add custom prefixes to all wordlist entries (separated
                        by commas)
    --suffixes=SUFFIXES
                        Add custom suffixes to all wordlist entries, ignore
                        directories (separated by commas)
    -U, --uppercase     Uppercase wordlist
    -L, --lowercase     Lowercase wordlist
    -C, --capital       Capital wordlist
Download Tool