Skip to content

HTTPX

Purpose

HTTPX probes scope values for reachable HTTP services and emits WebApp assets with web metadata.

Plugin Information

Plugin ID: httpx

Category: Service Discovery

Plugin Type: http_probe

Execution: active CLI HTTP probe

Default State: enabled

Default Profiles:

  • quick
  • default
  • deep
  • stealth
  • vuln_scan
  • tls_audit
  • web_discovery
  • recon_expanded
  • screenshot

Input Scope

Accepted asset types:

  • Any scope item currently passed to the plugin by the worker.

Required metadata:

  • None

Produces targets:

  • Newline-delimited scope values on stdin.

Output

Creates assets:

  • webapp

Creates vulnerabilities:

  • None

May enrich:

  • WebApp assets with HTTP and technology metadata.
  • WebApp assets with selected response security headers, CSP, safe cookie attributes, and compact fingerprints when HTTPX emits them.
  • Service assets indirectly when URL metadata contains a valid ip and port.

Metadata:

  • url: probed URL.
  • status_code: HTTP status code from HTTPX.
  • title: page title when available.
  • technologies: normalized technology list.
  • scheme: parsed URL scheme.
  • host: parsed hostname.
  • port: parsed or inferred port.
  • ip: first valid IP found in ip, host, or a fields.

Canonical observed state:

  • metadata.asset_info.http.status_code.
  • metadata.asset_info.http.server when HTTPX reports a server/webserver field.
  • metadata.asset_info.http.security_headers.strict_transport_security.
  • metadata.asset_info.http.security_headers.x_content_type_options.
  • metadata.asset_info.http.security_headers.x_frame_options.
  • metadata.asset_info.http.security_headers.referrer_policy.
  • metadata.asset_info.http.security_headers.permissions_policy.
  • metadata.asset_info.http.csp.
  • metadata.asset_info.http.cookies with cookie name and flags only. Cookie values are never persisted.
  • metadata.asset_info.technologies.
  • metadata.asset_info.fingerprints.favicon_hash.
  • metadata.asset_info.fingerprints.page_fuzzy_hash from HTTPX simhash output.

Graph Relations

When WebApp metadata contains an IP and port, the worker ensures a service and derives:

ip -> exposes -> service
service -> serves -> webapp

If no service can be inferred, the worker falls back to a hostname relation when the hostname asset exists:

domain/subdomain -> serves -> webapp

Files / Artifacts

Produces:

  • None

Dependencies

Required binary: httpx

Required installer entry: tools.httpx

Command model:

httpx -json -silent -title -status-code -web-server -tech-detect -include-response-header -favicon -hash simhash [-rate-limit <n>]

Example Flow

service or host
  -> httpx
url

Notes

The wrapper treats no responsive hosts as an empty successful result unless stderr indicates a command failure and stdout is empty. Header values are stored with bounded length. Set-Cookie values are parsed only for cookie name and security attributes; secret cookie values are not stored. HTTPX observations are partial and do not require Katana output.