Ultimate Katana Cheat Sheet
Ultimate Katana Cheat Sheet
Next-generation crawling and spidering framework. Discover endpoints, parameters, and attack surface with speed.
1. Basic Crawling
Discover URLs and endpoints from web applications.
Single URL Crawl
katana -u https://example.com
Multiple URLs
katana -u https://example.com,https://example.org
From File
katana -list urls.txt
Pipe from Stdin
echo "https://example.com" | katana
Verbose Output
katana -u https://example.com -v
Silent Mode
katana -u https://example.com -silent
Input Methods
-u <url>: Single URL-list <file>: URL list filestdin: Pipe input-u <url1,url2>: Multiple URLs
Basic Flags
-v: Verbose mode-silent: Silent mode-d <depth>: Crawl depth-jc: JavaScript crawling
2. Scope & Filters
Set Crawl Depth
katana -u https://example.com -d 5
Scope by Domain
katana -u https://example.com -cs example.com
Scope by Subdomain
katana -u https://example.com -cs "*.example.com"
Exclude Scope
katana -u https://example.com -cos "*.test.example.com"
Filter Extensions
katana -u https://example.com -fe jpg,jpeg,png,gif,css
Match Extensions
katana -u https://example.com -em php,asp,aspx,jsp
Filter by Regex
katana -u https://example.com -fr "\.(css|js|png)$"
| Flag | Description | Example |
|---|---|---|
-d <num> | Crawl depth | -d 5 |
-cs <scope> | Crawl scope | -cs example.com |
-cos <scope> | Out of scope | -cos test.com |
-fe <ext> | Filter extensions | -fe jpg,png |
-em <ext> | Match extensions | -em php,asp |
-fr <regex> | Filter by regex | -fr "\.css$" |
Pro Tip: Scope Configuration
Always define proper scope to avoid crawling external domains:
Exclude static files for faster results:
Always define proper scope to avoid crawling external domains:
katana -u https://example.com -cs example.com -d 10Exclude static files for faster results:
katana -u https://example.com -fe jpg,jpeg,png,gif,css,woff,ttf
3. Headers & Auth
Set Custom Header
katana -u https://example.com -H "Authorization: Bearer TOKEN"
Set Cookie
katana -u https://example.com -H "Cookie: session=abc123"
Set User-Agent
katana -u https://example.com -H "User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1)"
Multiple Headers
katana -u https://example.com -H "Cookie: a=b" -H "X-API-Key: 123" -H "Accept: application/json"
Use Proxy
katana -u https://example.com -proxy http://127.0.0.1:8080
Set Rate Limit
katana -u https://example.com -rl 10
Set Timeout
katana -u https://example.com -timeout 30
Set Retries
katana -u https://example.com -retry 3
Header Flags
-H <header>: Custom header-proxy <url>: Proxy server-timeout <sec>: Timeout-retry <num>: Retries
Rate Control
-rl <num>: Rate limit-c <num>: Concurrency-delay <ms>: Delay-p <sec>: Pause
4. Output Formats
Default Output
katana -u https://example.com
Save to File
katana -u https://example.com -o urls.txt
JSON Output
katana -u https://example.com -json -o results.json
JSON Lines (NDJSON)
katana -u https://example.com -jsonl -o results.jsonl
With Fields
katana -u https://example.com -fields url,status_code,content_length
Store Responses
katana -u https://example.com -sr -srd responses/
Output Flags
-o <file>: Save output-json: JSON format-jsonl: JSON Lines-fields <list>: Custom fields
Response Storage
-sr: Store responses-srd <dir>: Response directory-srr: Store request/response-srd <dir>: Store directory
5. Advanced Features
JavaScript Crawling
katana -u https://example.com -jc
JavaScript with Scope
katana -u https://example.com -jc -jcs example.com
Parse JavaScript Files
katana -u https://example.com -jc -js
Extract Endpoints from JS
katana -u https://example.com -jc -js -jsm "api|endpoint|url"
Form Crawling
katana -u https://example.com -fc
Headless Crawling
katana -u https://example.com -hl
Automatic Form Filling
katana -u https://example.com -aff
Passive Crawling
katana -u https://example.com -ps
| Flag | Description | Use Case |
|---|---|---|
-jc | JavaScript crawling | SPA applications |
-js | Parse JS files | Find endpoints |
-jsm | JS match regex | Filter JS findings |
-fc | Form crawling | Discover forms |
-hl | Headless mode | Dynamic content |
-aff | Auto form fill | Form interaction |
-ps | Passive sources | External discovery |
Pro Tip: JavaScript Crawling
For modern SPA applications:
Extract API endpoints from JS:
For modern SPA applications:
katana -u https://example.com -jc -js -d 10Extract API endpoints from JS:
katana -u https://example.com -jc -js -jsm "api|endpoint|fetch|axios"
6. Automation Scripts
Endpoint Discovery Pipeline
#!/bin/bash
# endpoint-discovery.sh - Complete endpoint discovery
DOMAIN=$1
OUTPUT_DIR="recon-$DOMAIN"
mkdir -p $OUTPUT_DIR
echo "[+] Finding subdomains..."
subfinder -d "$DOMAIN" | httprobe > $OUTPUT_DIR/live-subs.txt
echo "[+] Crawling with Katana..."
katana -list $OUTPUT_DIR/live-subs.txt -d 5 -jc -js -o $OUTPUT_DIR/endpoints.txt
echo "[+] Extracting parameters..."
cat $OUTPUT_DIR/endpoints.txt | grep -E "\?.*=" | sort -u > $OUTPUT_DIR/parameterized-urls.txt
echo "[+] Complete! Results in $OUTPUT_DIR/"
API Endpoint Extractor
#!/bin/bash
# api-extract.sh - Extract API endpoints from JavaScript
URL=$1
echo "[+] Crawling $URL..."
katana -u "$URL" -jc -js -silent | grep -E "(api|v[0-9]|endpoint)" | sort -u > api-endpoints.txt
echo "[+] Found $(wc -l < api-endpoints.txt) API endpoints"
cat api-endpoints.txt
Parameter Discovery
#!/bin/bash
# param-discovery.sh - Discover URLs with parameters
while read -r url; do
echo "[+] Crawling $url..."
katana -u "$url" -silent -d 3 | grep -E "\?.*=" >> parameterized-urls.txt
done < urls.txt
echo "[+] Found $(wc -l < parameterized-urls.txt) URLs with parameters"
sort -u parameterized-urls.txt -o parameterized-urls.txt
XSS Target Finder
#!/bin/bash
# xss-targets.sh - Find potential XSS targets
DOMAIN=$1
echo "[+] Crawling for XSS targets..."
katana -u "https://$DOMAIN" -silent -d 5 -jc | grep -E "\?.*=" | while read -r url; do
# Test each parameter with Dalfox
dalfox url "$url" --silence --format json >> xss-results.json
done
echo "[+] XSS scanning complete"
jq -r '.[] | "\(.type): \(.param)"' xss-results.json
Full Recon Pipeline
#!/bin/bash
# full-recon.sh - Complete reconnaissance pipeline
DOMAIN=$1
OUTPUT="recon-$DOMAIN"
mkdir -p $OUTPUT
# Subdomain enumeration
echo "[+] Enumerating subdomains..."
subfinder -d "$DOMAIN" -o $OUTPUT/subs.txt
assetfinder --subs-only "$DOMAIN" >> $OUTPUT/subs.txt
sort -u $OUTPUT/subs.txt -o $OUTPUT/subs.txt
# Check live hosts
echo "[+] Checking live hosts..."
cat $OUTPUT/subs.txt | httprobe > $OUTPUT/live.txt
# Crawl with Katana
echo "[+] Crawling live hosts..."
katana -list $OUTPUT/live.txt -silent -d 5 -jc -js -o $OUTPUT/urls.txt
# Extract interesting endpoints
echo "[+] Extracting interesting endpoints..."
grep -E "(admin|api|upload|login|dashboard)" $OUTPUT/urls.txt > $OUTPUT/interesting.txt
# Scan with Nuclei
echo "[+] Scanning with Nuclei..."
cat $OUTPUT/live.txt | nuclei -t ~/nuclei-templates/ -o $OUTPUT/nuclei-results.txt
echo "[+] Complete! Results in $OUTPUT/"
Continuous Crawling
#!/bin/bash
# continuous-crawl.sh - Monitor for new endpoints
URL=$1
PREVIOUS="previous-urls.txt"
CURRENT="current-urls.txt"
while true; do
katana -u "$URL" -silent -d 5 -jc > "$CURRENT"
if [ -f "$PREVIOUS" ]; then
echo "[+] New endpoints found:"
diff "$PREVIOUS" "$CURRENT" | grep "^>" | sed 's/^> //'
fi
mv "$CURRENT" "$PREVIOUS"
sleep 86400
done
Pro Tip: Integration with ProjectDiscovery Tools
Combine Katana with other ProjectDiscovery tools:
subfinder -d example.com | httpx | katana | nuclei -t ~/nuclei-templates/
Or with parameter discovery:
katana -u https://example.com -silent | grep "?" | sort -u | tee params.txt
Then test parameters:
cat params.txt | dalfox pipe --silence
Post a Comment