
High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable wordlists, filters, and recursive scanning for penetration testing.
Current Release: v1.4 (20222.09.03)
An advanced command-line tool designed to brute force directories and files in webservers, AKA web path scanner
Idea by @maurosoria and @shelld3v
Developement-2022 is being actively developed by @nu11secur1ty
Requirement: python 3.10.5 or higher
Choose one of these installation options:
git clone https://github.com/nu11secur1ty/insect.git --depth 1 (RECOMMENDED)docker build -t "insect:latest" . (more information can be found here)pip3 install dirsearchsudo apt-get install dirsearch (deprecated)Summary:
%EXT% keyword with extensions from -e flag.%EXT% (like SecLists), -f | --force-extensions switch is required to append extensions to every word in wordlist, as well as the /.wordlist1.txt,wordlist2.txt.Examples:
index.%EXT%
Passing asp and aspx as extensions will generate the following dictionary:
index
index.asp
index.aspx
admin
Passing php and html as extensions with -f/--force-extensions flag will generate the following dictionary:
admin
admin.php
admin.html
admin/
login.html
Passing jsp and jspa as extensions with -O/--overwrite-extensions flag will generate the following dictionary:
login.html
login.jsp
login.jspa
Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]
Options:
--version show program's version number and exit
-h, --help show this help message and exit
Mandatory:
-u URL, --url=URL Target URL(s), support multiple flags
-l PATH, --url-file=PATH
URL list file
--stdin Read URL(s) from STDIN
--cidr=CIDR Target CIDR
--raw=PATH Load raw HTTP request from file (use `--scheme` flag
to set the scheme)
-s SESSION_FILE, --session=SESSION_FILE
Session file
--config=PATH Full path to config file, see 'config.ini' for
example (Default: config.ini)
Dictionary Settings:
-w WORDLISTS, --wordlists=WORDLISTS
Customize wordlists (separated by commas)
-e EXTENSIONS, --extensions=EXTENSIONS
Extension list separated by commas (e.g. php,asp)
-f, --force-extensions
Add extensions to the end of every wordlist entry. By
default insect only replaces the %EXT% keyword with
extensions
-O, --overwrite-extensions
Overwrite other extensions in the wordlist with your
extensions (selected via `-e`)
--exclude-extensions=EXTENSIONS
Exclude extension list separated by commas (e.g.
asp,jsp)
--remove-extensions
Remove extensions in all paths (e.g. admin.php ->
admin)
--prefixes=PREFIXES
Add custom prefixes to all wordlist entries (separated
by commas)
--suffixes=SUFFIXES
Add custom suffixes to all wordlist entries, ignore
directories (separated by commas)
-U, --uppercase Uppercase wordlist
-L, --lowercase Lowercase wordlist
-C, --capital Capital wordlist