httpx
fast HTTP toolkit for probing web servers
TLDR
SYNOPSIS
httpx [options]
DESCRIPTION
httpx is a fast, multi-purpose HTTP toolkit built on Go's `retryablehttp` library for running many probes against a list of hosts at once. It checks which hosts are alive and can report status codes, titles, response headers, TLS data, detected technologies, screenshots, and more.By default it probes with the HTTPS scheme first and falls back to HTTP only if HTTPS is unreachable; -no-fallback shows both. The tool is built for reconnaissance and security testing workflows, processing large host lists concurrently and integrating with the rest of the ProjectDiscovery toolchain (nuclei, subfinder, etc.).
PARAMETERS
-l, -list FILE
Input file containing the list of hosts to process.-u, -target HOST
Probe a specific target host directly instead of reading a list.-title
Display the page title.-sc, -status-code
Display the response status code.-td, -tech-detect
Display detected technologies (based on the Wappalyzer dataset).-ip
Display the resolved host IP.-p, -ports PORTS
Ports to probe, using nmap-style syntax (e.g. `http:1,2-10,https:443`).-x METHOD
HTTP method(s) to probe; use `all` to try every method.-H HEADER
Custom HTTP header to send with each request.-fr, -follow-redirects
Follow HTTP redirects.-mc, -match-code CODES
Only show responses matching the given status codes (e.g. `-mc 200,301`).-fc, -filter-code CODES
Exclude responses matching the given status codes.-t, -threads N
Number of concurrent threads (default 50).-rl, -rate-limit N
Maximum requests per second (default 150).-timeout SECONDS
Request timeout (default 10).-retries N
Number of retries on failure.-silent
Only print results, suppressing the banner and stats.-json
Store output in JSONL(ines) format.-o, -output FILE
File to write results to.-help
Display help information.
INSTALL
CAVEATS
Intended for reconnaissance and security testing against systems you're authorized to test. Requires Go to build from source; prebuilt binaries are available. Flags are single-dash (e.g. `-json`, not `--json`).
HISTORY
httpx was created by ProjectDiscovery as part of its open-source security reconnaissance toolkit, alongside tools like nuclei and subfinder.