dalfox

Dalfox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities. ## Key features * Subcommands: `scan` (URL / file / pipe / raw-HTTP, auto-detected), `server`, `payload`, `mcp` * Discovery: Parameter analysis, static analysis, BAV testing, parameter mining * XSS Scanning: Reflected, Stored (SXSS), DOM-based, with optimization and DOM/AST verification * WAF: Fingerprinting with confidence scoring, bypass tracking, and tunable `--waf-min-confidence` * HTTP Options: Custom headers, cookies, methods, proxy, and more * Output: JSON/JSONL/Plain/Markdown/SARIF/TOML formats, silence mode, detailed reports * Extensibility: REST API, MCP stdio server, custom payloads, remote wordlists And the various options required for the testing :D ## Installation ### Homebrew (macOS/Linux) ```bash brew install dalfox # https://formulae.brew.sh/formula/dalfox ``` ### Snapcraft (Ubuntu) ```bash sudo snap install dalfox ``` ### Arch Linux (AUR) ```bash yay -S dalfox # or paru -S dalfox ``` ### Chocolatey (Windows) ```powershell choco install dalfox ``` See the [Installation guide](https://dalfox.hahwul.com/getting-started/installation/) for manual build instructions. ### Nixpkgs (NixOS) A package is available for Nix or NixOS users. Keep in mind that the latest releases might only be present in the `unstable` channel. ```bash nix-shell -p dalfox ``` ### Nix Flakes For Nix users with flakes enabled: ```bash # Run directly nix run github:hahwul/dalfox -- scan https://example.com # Install nix profile install github:hahwul/dalfox # Development environment for hacking on Dalfox itself git clone https://github.com/hahwul/dalfox && cd dalfox && nix develop ``` The flake also exposes `overlays.default`, so NixOS and home-manager users can build Dalfox against their own `nixpkgs`. See the [Installation guide](https://dalfox.hahwul.com/getting-started/installation/) for that module snippet and the rest of the details. Prebuilt binaries (including statically-linked musl variants for Linux) are available on the [GitHub Releases](https://github.com/hahwul/dalfox/releases) page. ## Usage ```bash dalfox [mode] [target] [flags] ``` * Single URL: `dalfox scan http://example.com -b https://callback` * File Mode: `dalfox scan urls.txt --custom-payload mypayloads.txt` * Pipeline: `cat urls.txt | dalfox scan --headers "AuthToken: xxx"` * Custom injection point (query): `dalfox scan 'https://example.com/?q=FUZZ&page=1' --inject-marker FUZZ` * Custom injection point (header): `dalfox scan https://example.com -H 'X-Search: FUZZ' --inject-marker FUZZ` Check the [CLI reference](https://dalfox.hahwul.com/reference/cli/) and [Quick start](https://dalfox.hahwul.com/getting-started/quick-start/) documents for more examples. ## V2 Looking for the Go (v2.x) version? Dalfox v3 is a complete rewrite in Rust. The Go codebase is preserved on the [`v2` branch](https://github.com/hahwul/dalfox/tree/v2) and continues to receive security backports. See [SECURITY.md](./.github/SECURITY.md) for the support policy, and the [migration guide](https://dalfox.hahwul.com/getting-started/migration/) for what changed in v3. ## Contributing if you want to contribute to this project, please see [CONTRIBUTING.md](https://github.com/hahwul/dalfox/blob/main/.github/CONTRIBUTING.md) and Pull-Request with cool your contents. [![](docs/static/images/CONTRIBUTORS.svg)](https://github.com/hahwul/dalfox/graphs/contributors) ## About the Name The name comes from 'Dal' ([달](https://en.wiktionary.org/wiki/달)) 🌙, the Korean word for 'moon', combined with 'Fox' 🦊. ![](docs/static/images/illust2.webp)