Ultimate Katana Cheat Sheet



Ultimate Katana Cheat Sheet

Next-generation crawling and spidering framework. Discover endpoints, parameters, and attack surface with speed.

1. Basic Crawling

Discover URLs and endpoints from web applications.

Single URL Crawl

katana -u https://example.com

Multiple URLs

katana -u https://example.com,https://example.org

From File

katana -list urls.txt

Pipe from Stdin

echo "https://example.com" | katana

Verbose Output

katana -u https://example.com -v

Silent Mode

katana -u https://example.com -silent

Input Methods

  • -u <url> : Single URL
  • -list <file> : URL list file
  • stdin : Pipe input
  • -u <url1,url2> : Multiple URLs

Basic Flags

  • -v : Verbose mode
  • -silent : Silent mode
  • -d <depth> : Crawl depth
  • -jc : JavaScript crawling

2. Scope & Filters

Set Crawl Depth

katana -u https://example.com -d 5

Scope by Domain

katana -u https://example.com -cs example.com

Scope by Subdomain

katana -u https://example.com -cs "*.example.com"

Exclude Scope

katana -u https://example.com -cos "*.test.example.com"

Filter Extensions

katana -u https://example.com -fe jpg,jpeg,png,gif,css

Match Extensions

katana -u https://example.com -em php,asp,aspx,jsp

Filter by Regex

katana -u https://example.com -fr "\.(css|js|png)$"
FlagDescriptionExample
-d <num>Crawl depth-d 5
-cs <scope>Crawl scope-cs example.com
-cos <scope>Out of scope-cos test.com
-fe <ext>Filter extensions-fe jpg,png
-em <ext>Match extensions-em php,asp
-fr <regex>Filter by regex-fr "\.css$"
Pro Tip: Scope Configuration
Always define proper scope to avoid crawling external domains:
katana -u https://example.com -cs example.com -d 10
Exclude static files for faster results:
katana -u https://example.com -fe jpg,jpeg,png,gif,css,woff,ttf

3. Headers & Auth

Set Custom Header

katana -u https://example.com -H "Authorization: Bearer TOKEN"

Set Cookie

katana -u https://example.com -H "Cookie: session=abc123"

Set User-Agent

katana -u https://example.com -H "User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1)"

Multiple Headers

katana -u https://example.com -H "Cookie: a=b" -H "X-API-Key: 123" -H "Accept: application/json"

Use Proxy

katana -u https://example.com -proxy http://127.0.0.1:8080

Set Rate Limit

katana -u https://example.com -rl 10

Set Timeout

katana -u https://example.com -timeout 30

Set Retries

katana -u https://example.com -retry 3

Header Flags

  • -H <header> : Custom header
  • -proxy <url> : Proxy server
  • -timeout <sec> : Timeout
  • -retry <num> : Retries

Rate Control

  • -rl <num> : Rate limit
  • -c <num> : Concurrency
  • -delay <ms> : Delay
  • -p <sec> : Pause

4. Output Formats

Default Output

katana -u https://example.com

Save to File

katana -u https://example.com -o urls.txt

JSON Output

katana -u https://example.com -json -o results.json

JSON Lines (NDJSON)

katana -u https://example.com -jsonl -o results.jsonl

With Fields

katana -u https://example.com -fields url,status_code,content_length

Store Responses

katana -u https://example.com -sr -srd responses/

Output Flags

  • -o <file> : Save output
  • -json : JSON format
  • -jsonl : JSON Lines
  • -fields <list> : Custom fields

Response Storage

  • -sr : Store responses
  • -srd <dir> : Response directory
  • -srr : Store request/response
  • -srd <dir> : Store directory

5. Advanced Features

JavaScript Crawling

katana -u https://example.com -jc

JavaScript with Scope

katana -u https://example.com -jc -jcs example.com

Parse JavaScript Files

katana -u https://example.com -jc -js

Extract Endpoints from JS

katana -u https://example.com -jc -js -jsm "api|endpoint|url"

Form Crawling

katana -u https://example.com -fc

Headless Crawling

katana -u https://example.com -hl

Automatic Form Filling

katana -u https://example.com -aff

Passive Crawling

katana -u https://example.com -ps
FlagDescriptionUse Case
-jcJavaScript crawlingSPA applications
-jsParse JS filesFind endpoints
-jsmJS match regexFilter JS findings
-fcForm crawlingDiscover forms
-hlHeadless modeDynamic content
-affAuto form fillForm interaction
-psPassive sourcesExternal discovery
Pro Tip: JavaScript Crawling
For modern SPA applications:
katana -u https://example.com -jc -js -d 10
Extract API endpoints from JS:
katana -u https://example.com -jc -js -jsm "api|endpoint|fetch|axios"

6. Automation Scripts

Endpoint Discovery Pipeline

#!/bin/bash # endpoint-discovery.sh - Complete endpoint discovery DOMAIN=$1 OUTPUT_DIR="recon-$DOMAIN" mkdir -p $OUTPUT_DIR echo "[+] Finding subdomains..." subfinder -d "$DOMAIN" | httprobe > $OUTPUT_DIR/live-subs.txt echo "[+] Crawling with Katana..." katana -list $OUTPUT_DIR/live-subs.txt -d 5 -jc -js -o $OUTPUT_DIR/endpoints.txt echo "[+] Extracting parameters..." cat $OUTPUT_DIR/endpoints.txt | grep -E "\?.*=" | sort -u > $OUTPUT_DIR/parameterized-urls.txt echo "[+] Complete! Results in $OUTPUT_DIR/"

API Endpoint Extractor

#!/bin/bash # api-extract.sh - Extract API endpoints from JavaScript URL=$1 echo "[+] Crawling $URL..." katana -u "$URL" -jc -js -silent | grep -E "(api|v[0-9]|endpoint)" | sort -u > api-endpoints.txt echo "[+] Found $(wc -l < api-endpoints.txt) API endpoints" cat api-endpoints.txt

Parameter Discovery

#!/bin/bash # param-discovery.sh - Discover URLs with parameters while read -r url; do echo "[+] Crawling $url..." katana -u "$url" -silent -d 3 | grep -E "\?.*=" >> parameterized-urls.txt done < urls.txt echo "[+] Found $(wc -l < parameterized-urls.txt) URLs with parameters" sort -u parameterized-urls.txt -o parameterized-urls.txt

XSS Target Finder

#!/bin/bash # xss-targets.sh - Find potential XSS targets DOMAIN=$1 echo "[+] Crawling for XSS targets..." katana -u "https://$DOMAIN" -silent -d 5 -jc | grep -E "\?.*=" | while read -r url; do # Test each parameter with Dalfox dalfox url "$url" --silence --format json >> xss-results.json done echo "[+] XSS scanning complete" jq -r '.[] | "\(.type): \(.param)"' xss-results.json

Full Recon Pipeline

#!/bin/bash # full-recon.sh - Complete reconnaissance pipeline DOMAIN=$1 OUTPUT="recon-$DOMAIN" mkdir -p $OUTPUT # Subdomain enumeration echo "[+] Enumerating subdomains..." subfinder -d "$DOMAIN" -o $OUTPUT/subs.txt assetfinder --subs-only "$DOMAIN" >> $OUTPUT/subs.txt sort -u $OUTPUT/subs.txt -o $OUTPUT/subs.txt # Check live hosts echo "[+] Checking live hosts..." cat $OUTPUT/subs.txt | httprobe > $OUTPUT/live.txt # Crawl with Katana echo "[+] Crawling live hosts..." katana -list $OUTPUT/live.txt -silent -d 5 -jc -js -o $OUTPUT/urls.txt # Extract interesting endpoints echo "[+] Extracting interesting endpoints..." grep -E "(admin|api|upload|login|dashboard)" $OUTPUT/urls.txt > $OUTPUT/interesting.txt # Scan with Nuclei echo "[+] Scanning with Nuclei..." cat $OUTPUT/live.txt | nuclei -t ~/nuclei-templates/ -o $OUTPUT/nuclei-results.txt echo "[+] Complete! Results in $OUTPUT/"

Continuous Crawling

#!/bin/bash # continuous-crawl.sh - Monitor for new endpoints URL=$1 PREVIOUS="previous-urls.txt" CURRENT="current-urls.txt" while true; do katana -u "$URL" -silent -d 5 -jc > "$CURRENT" if [ -f "$PREVIOUS" ]; then echo "[+] New endpoints found:" diff "$PREVIOUS" "$CURRENT" | grep "^>" | sed 's/^> //' fi mv "$CURRENT" "$PREVIOUS" sleep 86400 done
Pro Tip: Integration with ProjectDiscovery Tools

Combine Katana with other ProjectDiscovery tools:
subfinder -d example.com | httpx | katana | nuclei -t ~/nuclei-templates/
Or with parameter discovery:
katana -u https://example.com -silent | grep "?" | sort -u | tee params.txt
Then test parameters:
cat params.txt | dalfox pipe --silence

⇧