
Scanner web de próxima geração
Desenvolvido por Andrew Horton urbanadventurer e Brendan Coles bcoles
Último lançamento: v0.6.4. 3 de abril de 2026
Licença: GPLv2
Este produto está sujeito aos termos detalhados no contrato de licença. Para mais informações sobre WhatWeb, visite https://github.com/urbanadventurer/
Wiki: https://github.com/urbanadventurer/WhatWeb/wiki/
Se você tiver alguma dúvida, comentário ou preocupação sobre o WhatWeb, consulte a documentação antes de entrar em contato com um dos desenvolvedores. Seu feedback é sempre bem-vindo.
O WhatWeb identifica sites. Seu objetivo é responder à pergunta: "O que é esse site?". O WhatWeb reconhece tecnologias web, incluindo sistemas de gerenciamento de conteúdo (CMS), plataformas de blog, pacotes de estatísticas/analytics, bibliotecas JavaScript, servidores web e dispositivos embarcados. O WhatWeb possui mais de 1800 plugins, cada um para reconhecer algo diferente. O WhatWeb também identifica números de versão, endereços de e-mail, IDs de conta, módulos de framework web, erros SQL e muito mais.
O WhatWeb pode ser furtivo e rápido, ou completo mas lento. O WhatWeb suporta um nível de agressão para controlar o equilíbrio entre velocidade e confiabilidade. Quando você visita um site no seu navegador, a transação inclui muitas pistas sobre quais tecnologias web estão alimentando aquele site. Às vezes, uma única visita a uma página web contém informações suficientes para identificar um site, mas quando não contém, o WhatWeb pode interrogar o site ainda mais. O nível padrão de agressão, chamado 'furtivo', é o mais rápido e requer apenas uma requisição HTTP de um site. Isso é adequado para escanear sites públicos. Modos mais agressivos foram desenvolvidos para uso em testes de penetração.
A maioria dos plugins do WhatWeb são completos e reconhecem uma variedade de pistas, desde sutis até óbvias. Por exemplo, a maioria dos sites WordPress pode ser identificada pela meta tag HTML, ex.: '', mas uma minoria de sites WordPress remove essa tag de identificação, mas isso não impede o WhatWeb. O plugin WordPress do WhatWeb tem mais de 15 testes, que incluem verificar o favicon, arquivos de instalação padrão, páginas de login e verificar por "/wp-content/" em links relativos.
Usando o WhatWeb para escanear reddit.com.``` $ ./whatweb reddit.com http://reddit.com [301 Moved Permanently] Country[UNITED STATES][US], HTTPServer[snooserv], IP[151.101.65.140], RedirectLocation[https://www.reddit.com/], UncommonHeaders[retry-after,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish] https://www.reddit.com/ [200 OK] Cookies[edgebucket,eu_cookie_v2,loid,rabt,rseor3,session_tracker,token], Country[UNITED STATES][US], Email[[email protected],[email protected]], Frame, HTML5, HTTPServer[snooserv], HttpOnly[token], IP[151.101.37.140], Open-Graph-Protocol[website], Script[text/javascript], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Title[reddit: the front page of the internet], UncommonHeaders[fastly-restarts,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish], X-Frame-Options[SAMEORIGIN]
## Uso```
.$$$ $. .$$$ $.
$$$$ $$. .$$$ $$$ .$$$$$$. .$$$$$$$$$$. $$$$ $$. .$$$$$$$. .$$$$$$.
$ $$ $$$ $ $$ $$$ $ $$$$$$. $$$$$ $$$$$$ $ $$ $$$ $ $$ $$ $ $$$$$$.
$ `$ $$$ $ `$ $$$ $ `$ $$$ $$' $ `$ `$$ $ `$ $$$ $ `$ $ `$ $$$'
$. $ $$$ $. $$$$$$ $. $$$$$$ `$ $. $ :' $. $ $$$ $. $$$$ $. $$$$$.
$::$ . $$$ $::$ $$$ $::$ $$$ $::$ $::$ . $$$ $::$ $::$ $$$$
$;;$ $$$ $$$ $;;$ $$$ $;;$ $$$ $;;$ $;;$ $$$ $$$ $;;$ $;;$ $$$$
$$$$$$ $$$$$ $$$$ $$$ $$$$ $$$ $$$$ $$$$$$ $$$$$ $$$$$$$$$ $$$$$$$$$'
WhatWeb - Next generation web scanner version 0.6.4.
Developed by Andrew Horton (urbanadventurer) and Brendan Coles (bcoles)
Homepage: https://morningstarsecurity.com/research/whatweb
Usage: whatweb [options] <URLs>
TARGET SELECTION:
<TARGETs> Enter URLs, hostnames, IP addresses, filenames or
IP ranges in CIDR, x.x.x-x, or x.x.x.x-x.x.x.x
format.
--input-file=FILE, -i Read targets from a file. You can pipe
hostnames or URLs directly with -i /dev/stdin.
TARGET MODIFICATION:
--url-prefix Add a prefix to target URLs.
--url-suffix Add a suffix to target URLs.
--url-pattern Insert the targets into a URL. Requires --input-file,
eg. www.example.com/%insert%/robots.txt
AGGRESSION:
The aggression level controls the trade-off between speed/stealth and
reliability.
--aggression, -a=LEVEL Set the aggression level. Default: 1.
Aggression levels are:
1. Stealthy Makes one HTTP request per target. Also follows redirects.
3. Aggressive If a level 1 plugin is matched, additional requests will be
made.
4. Heavy Makes a lot of HTTP requests per target. Aggressive tests from
all plugins are used for all URLs.
HTTP OPTIONS:
--user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.6.3.
--header, -H Add an HTTP header. eg "Foo:Bar". Specifying a default
header will replace it. Specifying an empty value, eg.
"User-Agent:" will remove the header.
--follow-redirect=WHEN Control when to follow redirects. WHEN may be `never',
`http-only', `meta-only', `same-site', or `always'.
Default: always.
--max-redirects=NUM Maximum number of contiguous redirects. Default: 10.
AUTHENTICATION:
--user, -u=<user:password> HTTP basic authentication.
--cookie, -c=COOKIES Provide cookies, e.g. 'name=value; name2=value2'.
--cookiejar=FILE Read cookies from a file.
--no-cookies Disable automatic cookie handling (improves performance
with high thread counts).
### Cookie Handling
WhatWeb automatically handles cookies across redirects by default. This improves fingerprinting accuracy on sites requiring session management.