Web Application
Gobuster
Directory/DNS/vhost brute-forcing tool written in Go.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Classic content discovery and DNS subdomain brute force.
How
Pick mode (dir/dns/vhost), wordlist, extensions; review hits.
Why
Reliable, simple, widely documented in training material.
Commands & usage
gobuster dir -u https://example.com -w wordlist.txt -x php,txt,html
gobuster dns -d example.com -w subdomains.txt
gobuster vhost -u https://example.com -w vhosts.txt
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
Tags
Related in Web Application
ffuf
Fast web fuzzer for directories, vhosts, parameters, and more.
Feroxbuster
Recursive content discovery tool with smart filtering.
dirsearch
Feature-rich web path scanner in Python.
Wfuzz
Flexible web application fuzzer for params, headers, auth, etc.
Nuclei
Template-based vulnerability scanner with huge community template set.
Nikto
Classic web server scanner for dangerous files, misconfigs, outdated software.