About this project

Gobuster is a high-performance brute-forcing tool written in Go, aimed at security professionals and penetration testers. It performs directory/file enumeration, DNS subdomain discovery, virtual host detection, cloud storage bucket enumeration and custom fuzzing through a mode-based command-line interface. Key capabilities: - Directory/file mode (dir): discovers hidden paths on web servers, with support for file extensions, custom headers and cookies, status-code filtering, response length display and output to file. - DNS mode (dns): resolves subdomains using custom wordlists and optional custom DNS servers, with configurable thread counts. - Virtual host mode (vhost): identifies virtual hosts, including an --append-domain option and warnings when it may be omitted. - Cloud storage modes: enumerates public Amazon S3 and Google Cloud Storage buckets. - TFTP mode: searches for files on TFTP servers. - Fuzz mode: substitutes the FUZZ keyword in URLs, query parameters, headers, POST bodies and basic auth. Operational features include multi-threaded scanning with configurable concurrency, pattern-based scanning where {GOBUSTER} is replaced per wordlist entry, wordlist offset, status-code ranges and blacklists, exclude-length ranges, TLS client certificates/mTLS, TLS renegotiation, custom outgoing interface and local IP, retry on timeout, color output, quiet mode, and automatic progress suppression when output is redirected. Installation options include go install, pre-compiled binaries and a Docker image. The README also documents troubleshooting, best practices and recommended wordlists such as SecLists and FuzzDB. The project is licensed under Apache 2.0 and accepts donations through Open Collective, with proceeds donated to charity.