HTTPX
Purpose
HTTPX probes scope values for reachable HTTP services and emits WebApp assets with web metadata.
Plugin Information
Plugin ID: httpx
Category: Service Discovery
Plugin Type: http_probe
Execution: active CLI HTTP probe
Default State: enabled
Default Profiles:
quickdefaultdeepstealthvuln_scantls_auditweb_discoveryrecon_expandedscreenshot
Input Scope
Accepted asset types:
- Any scope item currently passed to the plugin by the worker.
Required metadata:
- None
Produces targets:
- Newline-delimited scope values on stdin.
Output
Creates assets:
webapp
Creates vulnerabilities:
- None
May enrich:
- WebApp assets with HTTP and technology metadata.
- WebApp assets with selected response security headers, CSP, safe cookie attributes, and compact fingerprints when HTTPX emits them.
- Service assets indirectly when URL metadata contains a valid
ipandport.
Metadata:
url: probed URL.status_code: HTTP status code from HTTPX.title: page title when available.technologies: normalized technology list.scheme: parsed URL scheme.host: parsed hostname.port: parsed or inferred port.ip: first valid IP found inip,host, orafields.
Canonical observed state:
metadata.asset_info.http.status_code.metadata.asset_info.http.serverwhen HTTPX reports a server/webserver field.metadata.asset_info.http.security_headers.strict_transport_security.metadata.asset_info.http.security_headers.x_content_type_options.metadata.asset_info.http.security_headers.x_frame_options.metadata.asset_info.http.security_headers.referrer_policy.metadata.asset_info.http.security_headers.permissions_policy.metadata.asset_info.http.csp.metadata.asset_info.http.cookieswith cookie name and flags only. Cookie values are never persisted.metadata.asset_info.technologies.metadata.asset_info.fingerprints.favicon_hash.metadata.asset_info.fingerprints.page_fuzzy_hashfrom HTTPX simhash output.
Graph Relations
When WebApp metadata contains an IP and port, the worker ensures a service and derives:
ip -> exposes -> service
service -> serves -> webapp
If no service can be inferred, the worker falls back to a hostname relation when the hostname asset exists:
domain/subdomain -> serves -> webapp
Files / Artifacts
Produces:
- None
Dependencies
Required binary: httpx
Required installer entry: tools.httpx
Command model:
httpx -json -silent -title -status-code -web-server -tech-detect -include-response-header -favicon -hash simhash [-rate-limit <n>]
Example Flow
service or host
-> httpx
url
Notes
The wrapper treats no responsive hosts as an empty successful result unless stderr indicates a command failure and stdout is empty. Header values are stored with bounded length. Set-Cookie values are parsed only for cookie name and security attributes; secret cookie values are not stored. HTTPX observations are partial and do not require Katana output.