Skip to content

Comparison · neutral framing

ffuf vs gobuster

Two content-discovery tools that solve the same first problem — 'what answers on this path?' — with different ergonomics around filtering and templating.

ffufGobusterrevised 19 Jan 2026

Attributes

Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.

Scope

  • HTTP path discovery

    ffuf
    Documented
    gobuster
    Documented
  • Subdomain brute force via DNS

    ffuf
    Not a feature
    gobuster
    Documented
  • Virtual host discovery

    ffuf
    Documented
    gobuster
    Documented
  • Arbitrary fuzz positions (body, header, cookie)

    ffuf
    Full support
    gobuster
    fuzz modeTemplated syntax differs from ffuf's FUZZ

Filtering

  • Soft-404 handling

    ffuf
    Automatic calibration-recalibrate
    gobuster
    ManualSuppress status codes / compare sizes yourself
  • Regex match

    ffuf
    Documented
    gobuster
    Not a feature
  • Word transformations

    ffuf
    Replacer chain
    gobuster
    Limited

Operation

  • Concurrency control

    ffuf
    Threads + per-request pause
    gobuster
    Threads + timeout

    Both need explicit lowering against shared systems.

  • Output formats

    ffuf
    JSON, CSV, HTML, MD, eJSON
    gobuster
    Plain text file

Learning

  • Flag surface to learn

    ffuf
    Broad
    gobuster
    Small
  • Documentation stability

    ffuf
    Check `ffuf -h` for your versionFlags moved between major releases
    gobuster
    Stable within v3

ffuf

A fuzzer first: a FUZZ position anywhere in the request, plus a filtering language that makes noisy applications survivable.

Strengths

  • Match/suppress filters on status, size, words, lines and regex
  • Auto-calibration against soft-404 responses
  • Multiple wordlists and replacer chain (URL encoding, case, append)
  • JSON/CSV/HTML output suited to archiving results

Limitations

  • Flag surface is larger, so tutorials drift out of date
  • No DNS or SMB mode — it is HTTP-shaped

Consider ffuf when

  • — The application returns 200 for everything
  • — You need to fuzz headers, bodies or several positions at once
  • — Results must be re-filtered later without re-running
Open ffuf documentation

Gobuster

A brute forcer with modes: dir, vhost, dns, fuzz, smb. Fewer concepts to hold in your head, easy to drop into a script.

Strengths

  • One binary, several protocols including DNS subdomain brute forcing
  • Simple status suppression and extension lists
  • Widely packaged in distribution repositories
  • Small, stable flag surface per mode

Limitations

  • Filtering is less expressive for weird soft-404 behaviour
  • No calibrate equivalent; you tune suppression yourself

Consider Gobuster when

  • — You want subdomain and directory work in one tool
  • — A pipeline step needs predictable exit and output
  • — The target's baseline is simple enough for status filtering

The same job, both ways

Same job, two invocations

ffuf

ffuf -u https://app.internal/FUZZ -w common.txt -recalibrate -t 10 -p 0.1 -o out.json

gobuster

gobuster dir -u https://app.internal -w common.txt -t 10 -o out.txt

The ffuf run is self-calibrating and archiveable; the Gobuster run is simpler to read on screen.

Sources

Both columns should be checkable against upstream documentation.