📂 Fuzzing & Parameter Discovery
Fuzzing and parameter discovery allow penetration testers to map hidden routes, variables, and administrative files that are not visible in standard web links.
Tool Catalog
Select a tool below to view detailed specifications, mechanics, and cheatsheet commands.
FFUF
An extremely fast, multi-threaded web fuzzer in Go designed for path, directory, vhost, and JSON parameter fuzzing.
Gobuster
A robust, high-performance brute-forcer written in Go for directories, files, DNS subdomains, and virtual hosts.
Arjun
HTTP parameter discovery suite utilizing smart batch querying and binary splits to quickly find hidden query inputs.
x8
An ultra-fast Rust-based utility optimized for large wordlist parameter scans and custom HTTP header discovery.