
🏴☠️ 信息收集工具 🏴☠️ - DNS / 子域名 / 端口 / 目录枚举
由 edoardottt 用 💙 编码
在 Twitter 上分享!
安装 • 快速开始 • 示例 • 更新日志 • 贡献 • 许可证
brew install scilla
sudo snap install scilla
go install -v github.com/edoardottt/scilla/cmd/scilla@latest
你需要 Go (>=1.23)
git clone https://github.com/edoardottt/scilla.git
cd scilla
go get ./...
make linux # (安装)
make unlinux # (卸载)
如果你想使用 API 密钥,请编辑 ~/.config/scilla/keys.yaml 文件。
一行命令:git clone https://github.com/edoardottt/scilla.git && cd scilla && go get ./... && make linux
注意:可执行文件仅在 cariddi 文件夹中工作(别名?)。
git clone https://github.com/edoardottt/scilla.git
cd scilla
.\make.bat windows # (安装)
.\make.bat unwindows # (卸载)
如果你想使用 API 密钥,请创建一个 keys.yaml 文件。
docker build -t scilla .
docker run scilla help
DNS 枚举:
scilla dns -target example.comscilla dns -oj output -target example.comscilla dns -oh output -target example.comscilla dns -ot output -target example.comscilla dns -plain -target example.com子域名枚举:
scilla subdomain -target example.comscilla subdomain -w wordlist.txt -target example.comscilla subdomain -oj output -target example.comscilla subdomain -oh output -target example.comscilla subdomain -ot output -target example.comscilla subdomain -i 400 -target example.comscilla help 会打印命令行帮助信息。
usage: scilla subcommand { options }
Available subcommands:
- dns [-oj JSON output file]
[-oh HTML output file]
[-ot TXT output file]
[-plain Print only results]
-target <target (URL/IP)> REQUIRED
- port [-p <start-end> or ports divided by comma]
[-oj JSON output file]
[-oh HTML output file]
[-ot TXT output file]
[-common scan common ports]
[-plain Print only results]
-target <target (URL/IP)> REQUIRED
- subdomain [-w wordlist]
[-oj JSON output file]
[-oh HTML output file]
[-ot TXT output file]
[-i ignore status codes]
[-c use also a web crawler]
[-db use also a public database]
[-plain Print only results]
[-db -no-check Don't check status codes for subdomains]
[-db -vt Use VirusTotal as subdomains source]
[-db -bw Use BuiltWith as subdomains source]
[-ua Set the User Agent]
[-rua Generate a random user agent for each request]
[-dns Set DNS IP to resolve the subdomains]
[-alive Check also if the subdomains are alive]
-target <target (URL)> REQUIRED
- dir [-w wordlist]
[-oj JSON output file]
[-oh HTML output file]
[-ot TXT output file]
[-i ignore status codes]
[-c use also a web crawler]
[-plain Print only results]
[-nr No follow redirects]
[-ua Set the User Agent]
[-rua Generate a random user agent for each request]
-target <target (URL/IP)> REQUIRED
- report [-p <start-end> or ports divided by comma]
[-ws subdomains wordlist]
[-wd directories wordlist]
[-oj JSON output file]
[-oh HTML output file]
[-ot TXT output file]
[-id ignore status codes in directories scanning]
[-is ignore status codes in subdomains scanning]
[-cd use also a web crawler for directories scanning]
[-cs use also a web crawler for subdomains scanning]
[-db use also a public database for subdomains scanning]
[-common scan common ports]
[-nr No follow redirects]
[-db -vt Use VirusTotal as subdomains source]
[-ua Set the User Agent]
[-rua Generate a random user agent for each request]
[-dns Set DNS IP to resolve the subdomains]
[-alive Check also if the subdomains are alive]
-target <target (URL)> REQUIRED
- help
- examples
每次发布的详细变更记录在 发行说明 中。
在发起拉取请求之前,请下载 golangci-lint 并运行
golangci-lint run
如果没有错误,就可以继续进行 :)
待办事项:
添加更多测试
Tor 支持
代理支持
本仓库采用 GNU General Public License v3.0 许可。
edoardottt.com 联系我。
scilla subdomain -i 4** -target example.comscilla subdomain -c -target example.comscilla subdomain -db -target example.comscilla subdomain -plain -target example.comscilla subdomain -db -no-check -target example.comscilla subdomain -db -vt -target example.comscilla subdomain -db -bw -target example.comscilla subdomain -ua "CustomUA" -target example.comscilla subdomain -rua -target example.comscilla subdomain -dns 8.8.8.8 -target example.comscilla subdomain -alive -target example.com目录枚举:
scilla dir -target example.comscilla dir -w wordlist.txt -target example.comscilla dir -oj output -target example.comscilla dir -oh output -target example.comscilla dir -ot output -target example.comscilla dir -i 500,401 -target example.comscilla dir -i 5**,401 -target example.comscilla dir -c -target example.comscilla dir -plain -target example.comscilla dir -nr -target example.comscilla dir -ua "CustomUA" -target example.comscilla dir -rua -target example.com端口枚举:
scilla port -target example.comscilla port -p 20-90 -target example.comscilla port -p 20- -target example.comscilla port -p -90 -target example.comscilla port -p 21,25,80 -target example.comscilla port -common -target example.comscilla port -p 80 -target example.comscilla port -oj output -target example.comscilla port -oh output -target example.comscilla port -ot output -target example.comscilla port -plain -target example.com完整报告:
scilla report -target example.comscilla report -p 20-90 -target example.comscilla report -p 20- -target example.comscilla report -p -90 -target example.comscilla report -p 80 -target example.comscilla report -p 21,25,80 -target example.comscilla report -oj output -target example.comscilla report -oh output -target example.comscilla report -ot output -target example.comscilla report -wd dirs.txt -target example.comscilla report -ws subdomains.txt -target example.comscilla report -id 500,501,502 -target example.comscilla report -is 500,501,502 -target example.comscilla report -id 5**,4** -target example.comscilla report -is 5**,4** -target example.comscilla report -cd -target example.comscilla report -cs -target example.comscilla report -db -target example.comscilla report -common -target example.comscilla report -nr -target example.comscilla report -db -vt -target example.comscilla report -ua "CustomUA" -target example.comscilla report -rua -target example.comscilla report -dns 8.8.8.8 -target example.comscilla report -alive -target example.com