Skip to content

Bustah (content discovery) ​

Bustah brute-forces paths and directories against a target using configurable wordlists. Hits appear in a results tree on the host Bustah tab and are merged into the host Sitemap alongside crawl and Nikto discoveries.

Bustah complements Nikto's module checks and the Web Crawler: use it when you want to probe for hidden admin panels, backup files, and common paths without following links.

Where to launch ​

Entry pointWhat happens
New Scan wizard → Bustah tabBulk or single-host; Bustah is enabled by default alongside Nikto in bulk mode. Select at least one wordlist before Start Scan.
Tools → BustahHosts this tool has scanned; New Scan opens the wizard scoped to Bustah
Host Bustah tab → New ScanSingle-host wizard scoped to Bustah only

LFIC is separate — see LFIC.

The target hostname is resolved when the scan is created. An unresolvable host is refused with a message that names it — the sweep is never queued.

Bustah options (wizard / New Scan) ​

The Bustah panel is the same everywhere Bustah can be configured (bulk wizard, Tools → Bustah → New Scan, and host New Scan). Core fields:

OptionWhat it does
Base pathDirectory prefix for every word (e.g. /app/). This scopes the sweep — Root Path on the wizard Options tab is ignored for Bustah (a note appears under the field).
ExtensionsSuffixes appended to each word in addition to the bare word (e.g. .php .bak). Include the leading dot; each extension multiplies request count.
WordlistsOne or more lists must be selected. A wordlist is preselected when lists load successfully.
HTTP methodUsually GET. Stored and sent uppercase — a lowercase get is accepted and canonicalized. Mutating methods (POST, PUT, DELETE, …) require an explicit Allow unsafe methods acknowledgment.
Skip directoriesDirectory names to skip at any depth (one per line). Prefilled from project/platform defaults. Clearing the box means skip nothing — not a silent inherit.
Pause discovered directoriesSweep the base path immediately; each discovered directory is created paused in the results tree so you review before descending.
Seed from discovered pathsOptional extra sweep roots from prior or concurrent Crawler / Nikto scans (directories they found). Wait for source is Wait until the source scan finishes (default), Start once the source finds anything, or Don’t wait; seed what’s available now. Seed from Crawler is on by default.
Follow redirectsOff by default. Follow up to three in-scope redirects. Redirect targets show in results (→ in the tree; Redirect column in table view) and on the host Sitemap as → plus the Location on 3xx paths. Offsite redirects are highlighted. With follow off, a 3xx still records the Location; it does not report an exhausted hop cap. A chain that is followed and actually exceeds three hops still reports the hop cap.
RecursionHow Bustah expands into discovered directories (strategy and depth limits in the panel).
ExclusionsFilter responses by status code, body size, or regex so soft 404s and noise drop out.
Rate limiting (429)Ignore 429 completely keeps the configured rate with no backoff/stop; Never stop on errors suppresses rate-limit, block, and transport-failure stops (budgets and caps still apply — each suppressed stop becomes a degraded note).
Shared tabsProxy, RPS, and Concurrency live on Throttling & Limits. User-Agent, Virtual Host, and Additional Headers live on Options. Follow Redirects, Secret Detection, and Force IPv6 stay on the Bustah tab.

A sweep that is waiting on a source does not hold a Max concurrent hosts slot, so the source can start. Progress stays at 99% with orange waiting on its seed scan (elapsed minutes after the first). After 15 minutes it stops waiting, is marked degraded, and directories the source finds after that point are not swept.

Uncheck Enable on the Bustah header to launch Nikto/Crawl without a Bustah scan. An enabled Bustah tab with no wordlist selected blocks Start Scan until you pick at least one list.

Host Bustah tab ​

After a scan runs:

  • Bustah Scans — list of bustah runs for this host (New Scan, refresh, row actions). Click a row here to select that sweep (the row highlights). The results tree below is that sweep — it does not open a second copy in a modal. Click a row on Tools → Bustah (Scans toggle) or project Scans to open scan detail; Host view (or Open the full Bustah view for this host) lands here.
  • Sweep strip — scan selector (when there is more than one run), directory count, request and hit totals. sweep paused means the scan itself is paused (resume from the scan list). all jobs paused means every unfinished directory is paused and nothing is being sent.
  • Results — tree or table view toggle:
    • Tree — hierarchical paths with status codes, redirect arrows (including the hop list and why a followed chain stopped), job state badges, and per-directory progress (requests / expected, N hits). Scan on directory nodes queues a follow-up sweep. On a finished sweep that action is new work and needs a valid license. Add to report on hits. Play / pause act on that directory only (child sweeps keep running). Cancel stops that directory and everything under it. Delete asks first (Delete the sweep of …?) and names how many child sweeps go with it; it is not offered while the directory is still running. A cancel that could not stop every descendant still names the ones still sending requests. When bare (/blog) and trailing-slash (/blog/) probes both survive with different responses, each form shows its own status on the same row.
    • Table — sortable, resizable Path, Code, Redirect, Size, and job Status columns; same Scan action where descent is allowed. Status chips apply; directory sweep-state chips do not. See Accessibility → Resizable columns.
    • Expand all / Collapse all (tree only). Screenshot mode (camera icon) hides controls for a clean capture; any click restores the normal view.
    • Filter paths — case-insensitive substring search over hit paths (tree and table).
    • Chips — one per HTTP status in the loaded hits, plus one per directory sweep state (planned is a queued job). A directory shows if either its status or its sweep state is selected. Clear filter when a filter hides every loaded hit.

Use Add to report on a hit to add it to the project Report as File Found Via Discovery evidence (one item per host; many paths attach as separate file evidence rows). Hits already in the report show an indicator instead of the button.

Discovered paths feed the host Sitemap tab (tool badge bustah).

A Bustah scan can finish completed with an orange degraded badge when the sweep ran but skipped or truncated work (calibration failures, caps, rate limits, auth-session loss on authenticated sweeps, and similar). Hover the badge for the first reason; additional notes may appear in Logs → Scan Activity. See Scans → Degraded scans.

Bustah does not auto-create findings for every hit — the results tree and sitemap are the primary triage surfaces. Use Add to report when a discovery should appear in the deliverable.

Defaults: skip directories ​

Under Global Settings or Project Settings → Bustah tab, set default directory names Bustah should skip (e.g. /admin/). Precedence:

Skip directories on the scan  >  Project Settings → Bustah  >  Global Settings → Bustah

An empty saved list means “skip nothing” and overrides inherited defaults. See Settings → Bustah skip directories.

Wordlists ​

Bustah wordlists are managed on Global Settings → Bustah (built-in Default lists plus any you Upload). Each list shows its entry count; custom lists can be deleted. A file may be up to 128 MiB; a cut-off upload stores nothing. Select one or more lists in the New Scan wizard or host Bustah tab before launch — at least one is required when Bustah is enabled.

Uploaded and pasted wordlists are sanitized: lines that look like query strings (contain ? or =) are dropped so accidental URL fragments do not become probe paths. Built-in lists include refreshed common and expanded medium wordlists.

Next steps ​

  • Hosts → Sitemap — unified path tree from all tools
  • Scans — New Scan wizard and Tools menu
  • Scan options — shared Options / Throttling fields
  • Findings — triage findings from other tools; add Bustah hits via Add to report
  • Logs — audit HTTP requests

Proprietary software. Licensed for use under the End User License Agreement.