The Nikto Platform puts complementary scanners behind a single UI. Launch them from the New Scan wizard or a host's tool tab.
Nikto Scanner
Nikto is a classic web server scanner. Point it at HTTP or HTTPS targets and it runs a large library of checks: default files, misconfigurations, headers, SSL issues, outdated components, and other common web weaknesses. Nikto scans can run over HTTP/3 (QUIC) when you opt in — see HTTP/3 scanning. LFIC and Bustah can use the same transport via Scan Defaults; the crawler cannot. Results appear as findings you can triage, add to a report, and export.
See Scans for the wizard and progress monitoring, and Scan options for Nikto modules and MS10-070. The Web Crawler and Bustah can run in the same launch.
LFI Commander
LFI Commander (shown in the UI as LFIC) is for local file inclusion vulnerabilities. You describe how the target includes files (the inject point, encoding, wrappers), confirm the flaw with a probe, then run scans built from modules and filesets to retrieve interesting paths. Retrieved files appear in a browsable tree with extracted content, intel from analysis modules, and zip downloads.
See LFIC for the setup wizard, modules, and results explorer.
Projects, findings, and audit
Projects and hosts organize targets. Findings and Report are where you triage and curate results. The activity log records every HTTP request to a target. A valid license is required to start new work against a target. Start with Getting Started or the User Guide.
Copyright © 2026 Hack LLC. All rights reserved. View the End User License Agreement.