Chocolatey
RecommendedchocoNeeds elevated privileges (sudo / Administrator).
choco install gobuster
Directory, DNS and vhost brute forcer
Gobuster drives lists at a target through purpose-built modes: `dir` for paths, `vhost` for Host headers, `dns` for subdomains, `fuzz` for templated positions, `smb` for shares. It is deliberately simple to run and easy to script.
It reports what a server answered; interpreting that answer — a redirect chain, a 403 that is actually a WAF, a 200 of size zero — is the work of the analyst.
Supported platforms
8
Documented install or usage guidance
Learning curve
beginner
Difficulty of becoming productive, not of the underlying theory
Tags
content discovery, directories, dns, vhost, wordlist
Dataset entry
gobuster.ts
Reviewed 2026-01-13
Grouped by platform. Elevation requirements are marked per method.
Needs elevated privileges (sudo / Administrator).
choco install gobuster
brew install gobuster
Needs elevated privileges (sudo / Administrator).
sudo apt install gobuster
go install github.com/OJ/gobuster/v3@latest
Package availability follows your distribution and enabled repositories. Entry revised 13 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Requests each word as a path and prints the ones that are not suppressed by status.
gobuster dir -u http://192.0.2.20 -w /usr/share/wordlists/dirb/common.txt -t 20
Notes
Explicit status handling is the difference between 40 lines and 4,000.
gobuster dir -u https://app.internal -w wordlist.txt -s 301,302 --status-code-list 200,401,403
Notes
Resolves each word as a name and keeps the ones that answer.
gobuster dns -d example.internal -w subdomains-top1million-5000.txt -i
Notes
Sends each word in the Host header to one IP.
gobuster vhost -u http://192.0.2.20 -w hosts.txt -s 404
v3's generic mode: FUZZ can sit in the path, query, header or cookie.
gobuster fuzz -u 'https://app.internal/asset/{{FILE}}' -w files.txt -H 'X-Debug: {{DEBUG}}'Notes
Enumerate paths and hosts within an agreed window.
Record subdomains per environment for continuous comparison.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Compare against a deliberately random path (`-u .../gobuster-baseline-xyz`) and suppress that size with `--status-code`/filtering; or switch to ffuf with `-fs`/`-recalibrate`.
Possible causes
Usual fix
Raise `--timeout`, lower `-t`, and unset `HTTP_PROXY` if a stale environment value is set.
Not documented yet: feroxbuster. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
ffuf cover adjacent parts of the same job.