Security tool · inject
dalfox
Fast, powerful XSS scanner and parameter analyzer. Verifies reflections and builds working payloads.
Overview
Where dalfox fits
Fast, powerful XSS scanner and parameter analyzer. Verifies reflections and builds working payloads.
Detection-first use
Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.
Install
Installation references
Install with goAuthorization required
go install github.com/hahwul/dalfox/v2@latest- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Install with brewAuthorization required
brew install dalfox- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Test safely
Command templates
Scan URL listAuthorization required
Populate placeholders only with assets that are explicitly in scope.
dalfox file {input} -o {output}- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Pipe from gfAuthorization required
Populate placeholders only with assets that are explicitly in scope.
cat {input} | gf xss | qsreplace 'FUZZ' | dalfox pipe- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Related
Continue the workflow
Sources
Attribution and verification
Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.