# chainreactors/spray

最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.

Repository: https://github.com/chainreactors/spray
Canonical: https://ross.abutalabs.com/products/chainreactors-spray
Homepage: https://chainreactors.github.io/wiki/spray/
Language: Go
License: GPL-3.0
License Family: copyleft
Topics: security-tools, redteam, security
Last push: 2026-07-19T20:32:35+00:00

## Health v2 (maintenance only)
Score: 93/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 93, release rhythm 90, longevity 100
- inputs: {"age_days": 1455, "days_push": 45, "days_rel": 65, "gap_med": 21.0, "n_releases_24m": 15}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1058, forks 72 (observed 2026-08-28T04:03:25.096807+00:00)

## What it is
Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to feroxbuster, ffuf, and dirsearch. It combines directory bruteforcing with mask/rule-based wordlist generation, intelligent dynamic filtering, web fingerprinting, sensitive information extraction, and resume support.

## Use cases
- bruteforce hidden directories and files on a web server
- generate wordlists with masks and hashcat-style rules
- fingerprint web technologies during reconnaissance
- scan for backup files and common sensitive files
- bulk scan multiple URLs for interesting paths
- resume an interrupted directory scan
- detect WAF blocking and bans during fuzzing

## When to choose
- you need faster directory bruteforcing than ffuf or feroxbuster, especially across many targets
- you want built-in fingerprinting, crawling, and backup-file discovery in one tool
- you need mask- or rule-based dictionary generation instead of static wordlists
- you want smart automatic filtering of invalid pages with fine-grained control

## When to avoid
- you need a general-purpose HTTP parameter fuzzing tool with complex payload injection (use ffuf)
- you only need a simple, minimal directory scanner with a small feature set
- you require a GUI-driven scanning workflow
- you need a distributed scanning solution today (cloud/distribution features are still on the roadmap)

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, web-scraping, http-client, cli, developer-tools
- domain: security, penetration-testing, web-development
- platform: windows, cli, go
- tags: directory-bruteforce, content-discovery, http-fuzzing, fingerprinting, red-team, wordlist-generation, waf-detection, command-line, linux, macos

## Member repositories
- chainreactors/spray (main) score 93

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:25.096807+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:57:45.518805+00:00, confidence not recorded.
  - readme: https://github.com/chainreactors/spray (fetched 2026-08-28T04:03:25.096807+00:00, sha 32f874104605)
  - homepage: https://chainreactors.github.io/wiki/spray/ (fetched 2026-08-29T12:59:20.213392+00:00, sha 23296d5b0afb)
  - site_page: https://wiki.chainreactors.red/IoM/getting-started (fetched 2026-08-29T12:59:20.222901+00:00, sha d505cd303139)
  - site_page: https://wiki.chainreactors.red/IoM/getting-started/concepts (fetched 2026-08-29T12:59:20.225303+00:00, sha 1f963ba08c60)
  - site_page: https://wiki.chainreactors.red/IoM/getting-started/design (fetched 2026-08-29T12:59:20.227394+00:00, sha 7741cdba9ce1)
  - site_page: https://wiki.chainreactors.red/IoM/getting-started/roadmap (fetched 2026-08-29T12:59:20.229703+00:00, sha 8758eccc1a07)
  - site_page: https://wiki.chainreactors.red/IoM/user-guide/client-quickstart (fetched 2026-08-29T12:59:20.231586+00:00, sha d51ca7e7c06f)
  - site_page: https://wiki.chainreactors.red/IoM/development/mals/quickstart (fetched 2026-08-29T12:59:20.233350+00:00, sha 868defb49d3f)
  - site_page: https://wiki.chainreactors.red/malefic/getting-started (fetched 2026-08-29T12:59:20.235498+00:00, sha 529a7d141f18)
  - site_page: https://wiki.chainreactors.red/malefic/getting-started/architecture (fetched 2026-08-29T12:59:20.237435+00:00, sha 72cb7cbd407c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
