A fast, multi-threaded HTTP endpoint scanner designed to discover exposed files, misconfigurations, backups, and common sensitive paths on web servers — with low false positives and smart 404 detection.
🚀 Built for speed
🎯 Smarter than basic directory brute-forcers
🧵 Fully multi-threaded
🧪 Fake-200 detection included
- 🔍 Scans hundreds of common and sensitive endpoints
- 🧠 Dynamic 404 fingerprinting to reduce false positives
- ⚡ Multi-threaded scanning using
ThreadPoolExecutor - 🔁 Detects redirects, protected endpoints (401/403), and real hits
- 🧾 Global + per-target final scan report
- 🎨 Colorized terminal output for easy reading
- 🧩 Auto-generates backup variants (
.bak,.old,~, etc.)
The scanner checks for:
- Apache & server configs (
.htaccess,httpd.conf,apache2.conf) - Logs (
access.log,error.log,/var/log/...) - Git & VCS leaks (
.git/,.svn/,.hg/) - Environment files (
.env) - Admin & login panels
- Backups & archives (
.zip,.sql,.bak) - Dev & debug files (
phpinfo.php,debug.php) - Package managers (
composer.json,package.json) - And many more…
pip install requests
🚀 Usage
- Create a file with target URLs
example.com https://testsite.local http://192.168.1.10
- Run the scanner
python scanner.py
- Enter the file path when prompted
Enter file with URLs: targets.txt
📊 Output Example
[FOUND] /admin [FOUND] /.git/config [FOUND] /server-status
⚙️ Configuration
TIMEOUT = 6 THREADS = 15 HEADERS = {"User-Agent": "AdvancedEndpointScanner/FAST"}
⚙️ Configuration
TIMEOUT = 6 THREADS = 15 HEADERS = {"User-Agent": "AdvancedEndpointScanner/FAST"} "AdvancedEndpointScanner/FAST"}
Please star.......