
Gobuster
Fast open-source Go tool for directory, DNS, virtual-host and cloud-bucket brute-forcing during authorised web and infrastructure assessments.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
Gobuster is a high-performance brute-forcing tool written in Go by OJ Reeves and maintainers. It is a long-standing staple for discovering web paths, DNS names and virtual hosts during penetration tests and Hack The Box-style labs. Modes cover directory and file enumeration, DNS, virtual hosts, fuzzing, TFTP and public cloud storage bucket checks.
What it helps with
- Enumerating hidden directories and files on web servers with wordlists and optional extensions.
- Discovering subdomains through DNS mode with configurable resolvers and concurrency.
- Finding virtual hosts on shared web servers.
- Running flexible FUZZ-based requests against URLs, headers or POST bodies.
- Checking for reachable Amazon S3 and Google Cloud Storage bucket names from wordlists.
- Installing via Go, release binaries or the official container image for repeatable lab setups.
Who it's for
Penetration testers, bug bounty researchers and students who need fast content and name discovery on targets they are authorised to assess.
Worth knowing
Use Gobuster only against systems you are explicitly authorised to test. Aggressive enumeration can generate high request volume and may trigger rate limits or defensive controls. Gobuster is free under the Apache Licence 2.0. Prefer the OJ/gobuster repository and GitHub releases for current builds. Attribution: framing from the Gobuster README; licence from the repository LICENSE file.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.