offensive-tools/recon/dirsearch/SKILL.md
Web path scanning and directory brute-forcing with recursive scanning and multi-extension support. Use when enumerating web server content, finding hidden endpoints, and discovering backup or config files.
npx skillsauth add aeondave/malskill dirsearchInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Web directory and file brute-forcer with recursion, extensions, and proxy support.
pip install dirsearch
# Basic scan
dirsearch -u https://target.com
# With extensions
dirsearch -u https://target.com -e php,asp,aspx,bak,txt
# Recursive
dirsearch -u https://target.com -r
# Output to file
dirsearch -u https://target.com -o results.txt
| Flag | Purpose |
|------|---------|
| -u URL | Target URL |
| -e EXT | Extensions (comma-separated) |
| -w FILE | Custom wordlist |
| -r | Recursive scanning |
| -R N | Max recursion depth |
| -t N | Threads (default: 25) |
| -x CODES | Exclude status codes |
| --proxy URL | HTTP proxy |
| -o FILE | Output file |
| --format FORMAT | plain/json/xml/md |
PHP app scan with backups:
dirsearch -u https://target.com -e php,bak,old,txt,zip -r -t 30
Exclude 404s and noise:
dirsearch -u https://target.com -x 404,403,301
API path discovery:
dirsearch -u https://api.target.com -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt
| File | When to load |
|------|--------------|
| references/ | Wordlist selection and recursion tuning |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.