How to Use the Feroxbuster in Kali Linux 2026.2

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2

Feroxbuster is a fast and lightweight content discovery tool used by penetration testers and security researchers to find hidden directories and files in web applications. It can help identify resources such as backup files, administrative panels, configuration files, test directories, and other web content that may not be directly linked from a website.

In this tutorial, you will learn how to use Feroxbuster in Kali Linux 2026.2 and explore some of its most useful options for web application security testing.

Note: Perform content discovery only against websites and applications that you own or have explicit permission to test. The examples in this tutorial use DVWA in a local XAMPP lab environment.

What Is Feroxbuster?

Feroxbuster is a fast, simple, and recursive content discovery tool. It uses wordlists to make requests to a target web application and identify valid directories and files.

During a security assessment, it can help discover resources such as:

  • Hidden directories
  • Login and administration panels
  • Backup files
  • Configuration files
  • Debug and test directories
  • JavaScript and HTML files
  • Other files with commonly used extensions

Feroxbuster also supports recursion, custom wordlists, file extensions, HTTP status code filtering, response-size filtering, authentication headers, and output formats.

Installing Feroxbuster on Kali Linux

Feroxbuster is generally available in Kali Linux. First, check whether it is already installed:

feroxbuster

If it is not installed, you can install it using:

sudo apt install feroxbuster

After installation, verify the installed version :

feroxbuster --version

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-1

Check the Feroxbuster Help

Before starting a scan, you can use the help option to view the available commands and options:

feroxbuster --help

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-2

The help output provides information about wordlists, recursion, filtering, headers, extensions, output options, and other features.

Basic Feroxbuster Syntax

The basic syntax for scanning a web application is:

feroxbuster -u <Target-URL>

For example:

feroxbuster -u http://10.228.12.57/DVWA/

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-3

In this example, DVWA is being used as a sample testing application hosted on a local XAMPP server.

The -u option specifies the target URL.

By default, Feroxbuster can use its bundled wordlist, such as: /usr/share/feroxbuster/raft-medium-directories.txt

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-4

You can also specify your own wordlist when you want to perform more targeted content discovery.

Understanding Feroxbuster Output

A typical result may look similar to:

200 GET 56l 334w 2194c http://10.228.12.57/DVWA/config/config.inc.php.dist

The output contains several useful fields.

HTTP Status Code

200 : This is the HTTP response status code returned by the web server.

For example: 200, 301, 302, 403, 404

HTTP Method

GET : This shows the HTTP method used for the request.

Lines

56l : This indicates the number of lines in the response.

Words

334w : This represents the number of words in the response.

Characters

2194c :This indicates the approximate number of characters in the response.

Discovered URL

The final part of the result shows the discovered resource: http://10.228.12.57/DVWA/config/config.inc.php.dist

Feroxbuster can continue discovering content recursively depending on the options used.

Using a Custom Wordlist

A custom wordlist can be useful when you want more targeted results or want to reduce unnecessary requests.

Use the -w option:

feroxbuster -u http://10.228.12.57/DVWA/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-5

The selected wordlist is used to generate directory and file requests against the target.

Choosing an appropriate wordlist can improve both scan efficiency and the quality of discovered results.

Scanning Specific File Extensions

The -x option allows you to append file extensions to each wordlist entry.

For example:

feroxbuster -u http://10.228.12.57/DVWA/ -x php,html,js,txt,bak

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-6

For a word such as: login

Feroxbuster can test variations such as: login.php,login.html,login.js,login.txt,login.bak.

You can also specify a single extension:

feroxbuster -u http://10.228.12.57/DVWA/ -x php

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-7

Control Recursion Depth

Feroxbuster can recursively scan discovered directories. You can control how deep the scan should continue with the –depth option.

For example:

feroxbuster -u http://10.228.12.57/DVWA/ --depth 2

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-8

This limits recursive discovery to the specified depth.

Controlling recursion can help keep scans focused and reduce unnecessary requests.

Filter HTTP Status Codes

You can specify which status codes should be displayed using –status-codes.

For example:

feroxbuster -u http://10.228.12.57/DVWA/ --status-codes 200,404

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-9

This tells Feroxbuster to display responses matching the specified status codes.

You can also exclude a status code using –filter-status.

For example:

feroxbuster -u http://10.228.12.57/DVWA/ --filter-status 301

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-10

This removes HTTP 301 responses from the displayed results, which can make the output easier to review.

Use Authentication Cookies

Some web applications require authentication before certain resources can be accessed.

You can provide an HTTP cookie using the -H option:

feroxbuster -u http://10.228.12.57/DVWA/ -H "Cookie: PHPSESSID=YOUR_SESSION_ID"

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-11

Replace YOUR_SESSION_ID with a valid session value from your authorized test environment.

Authenticated content discovery can be useful when important directories or files are available only after login.

Use an Authorization Token

If the application uses a bearer token for authentication, you can provide it through an HTTP header:

feroxbuster -u http://10.228.12.57/DVWA/ -H "Authorization: Bearer YOUR_TOKEN"

Replace YOUR_TOKEN with a valid token from your authorized testing environment.

Save Feroxbuster Results

You can save scan results to a text file using the -o option:

feroxbuster -u http://10.228.12.57/DVWA/ -o feroxbuster_output.txt

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-12

You can then view the saved results using:

cat feroxbuster_output.txt

Saving scan results is useful when you need to review or document your findings later.

Save Results in JSON Format

Feroxbuster also supports JSON output.

For example:

feroxbuster -u http://10.228.12.57/DVWA/ --json -o feroxbuster_output.json

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-13

You can view the generated file with:

cat feroxbuster_output.json

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-14

JSON output can be useful when integrating scan results into other tools or processing the results programmatically.

Display Only Discovered URLs

The –silent option can be used when you want cleaner output:

feroxbuster -u http://10.228.12.57/DVWA/ --silent

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-15

This is particularly useful when you are interested mainly in the discovered URLs rather than the complete scan information.

Use a Custom User-Agent

Feroxbuster uses its own User-Agent by default. In some authorized testing environments, a web server or WAF may treat automated requests differently based on the User-Agent.

You can specify a custom User-Agent using the -a option:

feroxbuster -u http://10.228.12.57/DVWA/ -a "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-16

Use a User-Agent that accurately represents your testing setup and do not use this option to bypass security controls without authorization.

Disable Recursion

If you do not want Feroxbuster to recursively scan discovered directories, use:

feroxbuster -u http://10.228.12.57/DVWA/ --no-recursion

How-to-Use-the-Feroxbuster-in-Kali-Linux-2026-2-17

The –no-recursion option keeps the scan focused on the specified target level.

Filter Responses by Size

Sometimes an application returns similar responses for nonexistent and existing resources. Response-size filtering can help reduce this type of noise.

You can exclude responses with a specific size using:

feroxbuster -u http://10.228.12.57/DVWA/ --filter-size 123

You can also filter based on the number of words:

feroxbuster -u http://10.228.12.57/DVWA/ --filter-words 30

Or the number of lines:

feroxbuster -u http://10.228.12.57/DVWA/ --filter-lines 9

These options can be helpful when tuning a scan and removing repetitive or unwanted responses.

Conclusion

Feroxbuster is a useful content discovery tool included in Kali Linux that can help security testers identify hidden directories and files in web applications. Its support for custom wordlists, file extensions, recursion, authentication headers, status-code filtering, response filtering, and multiple output formats makes it useful for web application security testing.

In this tutorial, you learned how to install and verify Feroxbuster, perform a basic scan, use custom wordlists, scan specific file extensions, control recursion, filter responses, provide authentication headers, save results, and customize the output.

When used responsibly against authorized targets, Feroxbuster can be a valuable part of a web application penetration testing and security assessment workflow.

Related Posts