Comparison · neutral framing
ffuf vs gobuster
Two content-discovery tools that solve the same first problem — 'what answers on this path?' — with different ergonomics around filtering and templating.
Attributes
Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.
Scope
HTTP path discovery
- ffuf
- Documented
- gobuster
- Documented
Subdomain brute force via DNS
- ffuf
- Not a feature
- gobuster
- Documented
Virtual host discovery
- ffuf
- Documented
- gobuster
- Documented
Arbitrary fuzz positions (body, header, cookie)
- ffuf
- Full support
- gobuster
- fuzz modeTemplated syntax differs from ffuf's FUZZ
Filtering
Soft-404 handling
- ffuf
- Automatic calibration-recalibrate
- gobuster
- ManualSuppress status codes / compare sizes yourself
Regex match
- ffuf
- Documented
- gobuster
- Not a feature
Word transformations
- ffuf
- Replacer chain
- gobuster
- Limited
Operation
Concurrency control
- ffuf
- Threads + per-request pause
- gobuster
- Threads + timeout
Both need explicit lowering against shared systems.
Output formats
- ffuf
- JSON, CSV, HTML, MD, eJSON
- gobuster
- Plain text file
Learning
Flag surface to learn
- ffuf
- Broad
- gobuster
- Small
Documentation stability
- ffuf
- Check `ffuf -h` for your versionFlags moved between major releases
- gobuster
- Stable within v3
ffuf
A fuzzer first: a FUZZ position anywhere in the request, plus a filtering language that makes noisy applications survivable.
Strengths
- Match/suppress filters on status, size, words, lines and regex
- Auto-calibration against soft-404 responses
- Multiple wordlists and replacer chain (URL encoding, case, append)
- JSON/CSV/HTML output suited to archiving results
Limitations
- Flag surface is larger, so tutorials drift out of date
- No DNS or SMB mode — it is HTTP-shaped
Consider ffuf when
- — The application returns 200 for everything
- — You need to fuzz headers, bodies or several positions at once
- — Results must be re-filtered later without re-running
Gobuster
A brute forcer with modes: dir, vhost, dns, fuzz, smb. Fewer concepts to hold in your head, easy to drop into a script.
Strengths
- One binary, several protocols including DNS subdomain brute forcing
- Simple status suppression and extension lists
- Widely packaged in distribution repositories
- Small, stable flag surface per mode
Limitations
- Filtering is less expressive for weird soft-404 behaviour
- No calibrate equivalent; you tune suppression yourself
Consider Gobuster when
- — You want subdomain and directory work in one tool
- — A pipeline step needs predictable exit and output
- — The target's baseline is simple enough for status filtering
The same job, both ways
Same job, two invocations
ffuf
ffuf -u https://app.internal/FUZZ -w common.txt -recalibrate -t 10 -p 0.1 -o out.json
gobuster
gobuster dir -u https://app.internal -w common.txt -t 10 -o out.txt
The ffuf run is self-calibrating and archiveable; the Gobuster run is simpler to read on screen.
Sources
Both columns should be checkable against upstream documentation.