Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
urx — 从 OSINT 档案中提取 URL,用于安全洞察 | Kitploit
工具/GitHubGitHub/hahwul/urx
OSINT (开源情报)侦察信息收集Web安全网络爬虫
GitHubhahwul/urx

urx

从 OSINT 档案中提取 URL,用于安全洞察

查看仓库
19020495天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站
Urx Logo

从 OSINT 档案中提取 URL,助力安全洞察。

Urx 是一款命令行工具,专为从 OSINT 档案(如 Wayback Machine 和 Common Crawl)中收集 URL 而设计。它使用 Rust 构建以追求高效,利用异步处理快速查询多个数据源。该工具简化了为指定域名收集 URL 信息的过程,提供全面的数据集,可用于多种用途,包括安全测试和分析。

功能特性

  • 并行从多个来源获取 URL(Wayback Machine、Common Crawl、OTX、Arquivo.pt)
  • 通过 --cdx-endpoint URL 接入任何其他 CDX 索引服务器——国家网络档案、私有 pywb、OutbackCDX——无需修改代码
  • 默认无需密钥:Wayback、Common Crawl、OTX、Arquivo.pt 和 URLScan(匿名)均可无需 API 密钥使用
  • BeVigil 提供者:从解包的 Android 应用中提取的 URL——网络档案从未抓取过的端点
  • 支持 VirusTotal 和 URLScan 提供者的 API 密钥轮换,以缓解速率限制
  • 认证测试:-H、--cookie 和 --user-agent 应用于 urx 对目标发起的每个请求(--check-status、--extract-links、--extract-js-endpoints、--expand-specs),并且刻意从不发送到档案
  • 按文件扩展名、子字符串模式或完整正则表达式过滤结果(--match-regex / --filter-regex)
  • 预定义预设,既可按文件类别("no-images"、"only-js"),也可按安全关注点("only-secrets"、"only-backup"、"only-config"、"only-api")
  • 档案侧过滤:将状态码、MIME 类型和日期范围推入 CDX 查询本身,因此被过滤掉的捕获记录永远不会经过网络
  • 客户端元数据过滤(--meta-*):在收集后,对所有提供者统一按首次/最后捕获日期、记录的 MIME 类型和记录的状态进行过滤
  • 路径范围目标:urx example.com/shop 将范围推入 CDX 查询本身(url=example.com/shop*),因此大型站点的子树只需花费整个索引的一小部分成本,而不是在客户端被过滤掉
  • 漏洞赏金范围文件(--scope-file):直接使用项目自身的 *.example.com / !admin.example.com 列表,可重复并取并集,排除项始终优先
  • URL 规范化与去重:排序查询参数、移除尾部斜杠、合并语义相同的 URL,并折叠仅在 id、哈希或日期上不同的近似重复项(--dedup-similar)
  • 支持多种输出格式:纯文本、JSON、JSON Lines、CSV 和 wordlist——即目标所构建自的路径段和参数名,省略 id、哈希和日期
  • 参数与模糊测试视图:--params(整个目标的参数清单)、--params-by-endpoint(哪个端点接受什么参数),以及 --fuzz-placeholder FUZZ(每个参数签名一个模板化 URL,可直接用于 ffuf 或 dalfox)
  • 档案捕获元数据:CDX 档案报告的每个 URL 都会返回 first_seen、last_seen、mime、archive_status 和 digest,且无额外网络开销
  • 流式输出(--stream):URL 在每个提供者报告时即被写出,因此管道可立即开始工作,而无需等待最慢的档案
  • 直接文件输入支持:直接从 WARC 文件、URLTeam 压缩文件和文本文件读取 URL
  • 将结果输出到控制台或文件,或通过 stdin 流式传输以集成到管道中
  • URL 测试:
    • 基于 HTTP 状态码和模式过滤并验证 URL。
    • 从收集的 URL 中提取额外链接——锚点、脚本、样式表、表单操作、iframe、图像、媒体源、对象、嵌入内容和 meta-refresh 目标
    • 挖掘收集到的 URL 的已归档响应体(--archive-body),因此已不存在的页面仍能交出它们曾包含的链接——得益于 CDX 摘要去重,每个不同响应体仅需一次请求
    • 使用 --extract-js-endpoints,还可挖掘已归档的 JavaScript:一个以构建哈希命名的 bundle 在站点重新部署的瞬间就会 404,而档案是其 API 表面仍然存在的唯一地方
    • 保留重放的响应体(--archive-body-dir)作为语料库,用于 grep 任何链接提取器都不会寻找的内容——开发者注释、内联凭据、内部主机名——且无额外请求
    • 展开 API 规范(--expand-specs):OpenAPI 3.x、Swagger 2.0 和 GraphQL introspection 文档,JSON 或 YAML,转换为它们所描述的每条路由——一次请求即可获得整个已文档化的表面
    • 响应元数据:--check-status 还会记录 Location、Content-Length 和 Content-Type,而 --check-title 会添加 HTML <title>
  • 已归档的 robots.txt 和 sitemap.xml 发现(--archived-discovery):Wayback Machine 持有的每个不同版本,因此 2015 年的 Disallow: 仍会指出站点此后不再提及的路径
  • 缓存与增量扫描:
    • 本地 SQLite 或远程 Redis 缓存,以避免重复扫描域名
    • 增量模式,仅发现自上次扫描以来的新 URL
    • 可配置的缓存 TTL 和过期条目的自动清理
    • urx cache 子命令用于检查和维护缓存:stats、list、prune、drop <domain>、clear

Preview

安装

通过 Cargo```bash

https://crates.io/crates/urx

cargo install urx

### 通过 Homebrew 安装```bash
# https://formulae.brew.sh/formula/urx
brew install urx

从源码```bash

git clone https://github.com/hahwul/urx.git cd urx cargo build --release

编译后的二进制文件将位于 `target/release/urx`。

### 通过 Docker

[ghcr.io/hahwul/urx](https://github.com/hahwul/urx/pkgs/container/urx)

### Shell 补全

`urx` 会生成自己的补全脚本,因此它始终与你实际安装的二进制文件的标志相匹配。```bash
# zsh — any directory on your $fpath works
urx --completions zsh > ~/.zfunc/_urx
# (make sure ~/.zfunc is on the fpath, then `compinit`)

# bash
urx --completions bash > ~/.local/share/bash-completion/completions/urx

# fish
urx --completions fish > ~/.config/fish/completions/urx.fish

powershell 和 elvish 也受支持。该标志无需目标域名。

手册页```bash

urx --manpage > ~/.local/share/man/man1/urx.1 man urx

## 用法

### 基本用法```bash
# Scan a single domain
urx example.com

# Scan multiple domains
urx example.com example.org

# Scan domains from a file
cat domains.txt | urx

选项```

Usage: urx [OPTIONS] [DOMAINS]... [COMMAND]

Commands: cache Inspect and maintain the URL cache: stats, list, prune, drop ..., clear

Arguments: [DOMAINS]... Domains to fetch URLs for

Options: -c, --config Config file to load --provider-config Separate provider config file holding only API keys (default: $XDG_CONFIG_HOME/urx/provider-config.toml). CLI/env > provider-config > main config. --completions Print a shell completion script (bash, zsh, fish, powershell, elvish) to stdout and exit --manpage Print the roff man page to stdout and exit -h, --help Print help -V, --version Print version

Input Options: --files ... Read URLs directly from files (supports WARC, URLTeam compressed, and text files) --domain-list File of newline-separated domains to scan (repeatable; merged with positional DOMAINS and stdin; # comments allowed)

Output Options: -o, --output Output file to write results --output-dir Write one file per domain into this directory (extension matches --format). Coexists with --output / stdout. -f, --format Output format: "plain", "json" (one array), "jsonl" (one JSON object per line), "csv", "wordlist" (path segments and parameter names, deduplicated and sorted) [default: plain] --stream Write URLs as each provider reports them instead of once at the end (unsorted; bypasses cache; rejects options needing the full result set) --merge-endpoint Merge endpoints with the same path and merge URL parameters --normalize-url Normalize URLs for better deduplication (sorts query parameters, removes trailing slashes) --dedup-similar Collapse URLs that differ only in variable data (numeric ids, UUIDs, hashes, dates, query values) --params Replace the URL list with every query parameter name the run saw, once each --params-by-endpoint One line per endpoint: the endpoint and the comma-separated union of the parameter names seen on it (id-looking path segments collapse to {id}) --fuzz-placeholder Replace every query parameter value with VALUE, keeping one URL per parameter signature — output you can feed straight to ffuf or dalfox

下载工具