Skip to content

httpx

HTTP probe that turns a host list into live web surface

CommunityPentesting· Web Application TestingBeginnerMITOpen sourceEntry revised 18 Dec 2025
  • Linux
  • macOS
  • Windows
  • Kali
  • Docker
  • Source

Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

3 commands documented

httpx connects to a list of hosts, records which respond over HTTP/HTTPS, and captures status, title, technology hints, TLS data and redirect chains. It is the standard bridge between 'these names exist' and 'these applications are reachable'.

The `-sc -title -server -tech-detect` style output is usually enough to prioritise; everything deeper belongs in an interactive tool.

Supported platforms

6

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

http, probe, screenshots, tls, pipeline

Dataset entry

httpx.ts

Reviewed 2025-12-18

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install httpx

Package availability follows your distribution and enabled repositories. Entry revised 18 Dec 2025 — confirm the current release on the project's own download page.

Commands

3 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Probe a host list

bash

Reports which inputs respond and with what status.

httpx -list hosts.txt -silent -status-code -title

Notes

  • `-silent` removes the banner, which is what makes the output pipeable.

02Add TLS and technology hints

bash

Extra columns for a prioritisation table.

httpx -list hosts.txt -sc -sr -server -tech-detect -tls-probe -json

Notes

  • `-sr` prints the redirect chain — often the difference between a 301 and a real finding.

03Check one path across many hosts

bash

Path probing over a list, with filters so the interesting answers surface.

httpx -list hosts.txt -path /.well-known/security.txt -filter-status-code 200 -silent

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

All hosts report 200 with the same titleCause 1/2

Possible causes

  • A wildcard/landing vhost answers everything.

Usual fix

Compare content length and match against a known-invalid host; use `-fc`/`-fs` style suppression or handle it downstream with a hash of the body.

Timeouts on hosts you can open in a browserCause 2/2

Possible causes

  • Non-standard ports, IPv6 preference, or a proxy in the environment.

Usual fix

Add `-ipv6`, raise `-timeout`, set `-http2` when the endpoint requires ALPN, and confirm no `HTTP_PROXY` is inherited.

Tips

  • Output JSON (`-json`) into a notebook and keep the run date; the same list next quarter is a different list.
  • Chain it: `subfinder -d corp -silent -resolve | httpx -silent` is a two-line surface baseline.

Alternatives & comparisons

Not documented yet: curl. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

Nuclei cover adjacent parts of the same job.

Compare side by side