
新发布Sep 10, 2026
scilla v1.3.4
信息收集工具 - DNS/子域名/端口/目录枚举

🏴☠️ 信息收集工具 🏴☠️ - DNS / 子域名 / 端口 / 目录枚举
由 edoardottt 用 💙 编写
分享到 Twitter!
安装 • 快速开始 • 示例 • 更新日志 • 贡献 • 许可证
安装 📡
Homebrew
brew install scilla
Snap
sudo snap install scilla
Golang
go install -v github.com/edoardottt/scilla/cmd/scilla@latest
从源码构建
你需要 Go (>=1.23)
从源码构建(适用于 Linux 和 Windows)
Linux
git clone https://github.com/edoardottt/scilla.git
cd scilla
go get ./...
make linux # (to install)
make unlinux # (to uninstall)
如果你想使用 API 密钥,请编辑 ~/.config/scilla/keys.yaml 文件。
一行命令:git clone https://github.com/edoardottt/scilla.git && cd scilla && go get ./... && make linux
Windows
请注意,该可执行文件仅在 cariddi 文件夹中有效(别名?)。
git clone https://github.com/edoardottt/scilla.git
cd scilla
.\make.bat windows # (to install)
.\make.bat unwindows # (to uninstall)
如果你想使用 API 密钥,请创建一个 keys.yaml 文件。
使用 Docker
docker build -t scilla .
docker run scilla help
示例 💡
-
DNS 枚举:
scilla dns -target example.comscilla dns -oj output -target example.comscilla dns -oh output -target example.comscilla dns -ot output -target example.comscilla dns -plain -target example.com
-
子域名枚举:
scilla subdomain -target example.comscilla subdomain -w wordlist.txt -target example.comscilla subdomain -oj output -target example.comscilla subdomain -oh output -target example.comscilla subdomain -ot output -target example.comscilla subdomain -i 400 -target example.comscilla subdomain -i 4** -target example.comscilla subdomain -c -target example.comscilla subdomain -db -target example.comscilla subdomain -plain -target example.comscilla subdomain -db -no-check -target example.comscilla subdomain -db -vt -target example.comscilla subdomain -db -bw -target example.comscilla subdomain -ua "CustomUA" -target example.comscilla subdomain -rua -target example.comscilla subdomain -dns 8.8.8.8 -target example.comscilla subdomain -alive -target example.com
-
目录枚举:
scilla dir -target example.comscilla dir -w wordlist.txt -target example.comscilla dir -oj output -target example.comscilla dir -oh output -target example.comscilla dir -ot output -target example.comscilla dir -i 500,401 -target example.comscilla dir -i 5**,401 -target example.comscilla dir -c -target example.comscilla dir -plain -target example.comscilla dir -nr -target example.comscilla dir -ua "CustomUA" -target example.comscilla dir -rua -target example.com
-
端口枚举:
- 默认(所有端口,即 1-65635)
scilla port -target example.com - 指定端口范围
scilla port -p 20-90 -target example.com - 指定起始端口(直到最后一个)
scilla port -p 20- -target example.com - 指定结束端口(从第一个开始)
scilla port -p -90 -target example.com - 指定多个端口
scilla port -p 21,25,80 -target example.com - 指定常见端口
scilla port -common -target example.com - 指定单个端口
scilla port -p 80 -target example.com - 指定输出格式(json)
scilla port -oj output -target example.com - 指定输出格式(html)
scilla port -oh output -target example.com - 指定输出格式(txt)
scilla port -ot output -target example.com - 仅打印结果
scilla port -plain -target example.com
- 默认(所有端口,即 1-65635)
-
完整报告:
- 默认(所有端口,即 1-65635)
scilla report -target example.com - 指定端口范围
scilla report -p 20-90 -target example.com - 指定起始端口(直到最后一个)
scilla report -p 20- -target example.com - 指定结束端口(从第一个开始)
scilla report -p -90 -target example.com - 指定单个端口
scilla report -p 80 -target example.com - 指定多个端口
scilla report -p 21,25,80 -target example.com - 指定输出格式(json)
scilla report -oj output -target example.com - 指定输出格式(html)
scilla report -oh output -target example.com - 指定输出格式(txt)
scilla report -ot output -target example.com - 指定目录字典
scilla report -wd dirs.txt -target example.com - 指定子域名字典
scilla report -ws subdomains.txt -target example.com - 指定在目录扫描中要忽略的状态码
scilla report -id 500,501,502 -target example.com - 指定在子域名扫描中要忽略的状态码
scilla report -is 500,501,502 -target example.com - 指定在目录扫描中要忽略的状态码类别
scilla report -id 5**,4** -target example.com - 指定在子域名扫描中要忽略的状态码类别
scilla report -is 5**,4** -target example.com - 同时使用网络爬虫进行目录枚举
scilla report -cd -target example.com - 同时使用网络爬虫进行子域名枚举
scilla report -cs -target example.com - 同时使用公共数据库进行子域名枚举
scilla report -db -target example.com - 指定常见端口
scilla report -common -target example.com - 不跟随重定向
scilla report -nr -target example.com - 使用 VirusTotal 作为子域名来源
scilla report -db -vt -target example.com - 设置 User Agent
scilla report -ua "CustomUA" -target example.com - 为每个请求生成随机 user agent
scilla report -rua -target example.com - 设置用于解析子域名的 DNS IP
scilla report -dns 8.8.8.8 -target example.com - 同时检查子域名是否存活
scilla report -alive -target example.com
- 默认(所有端口,即 1-65635)
快速开始 🎉
scilla help 在命令行中打印帮助信息。
usage: scilla subcommand { options }