Cariddi is a Go-based web reconnaissance crawler for authorized security testing and application analysis. It accepts one or many domains and recursively explores reachable URLs. During crawling, it can identify interesting endpoints, file extensions, tokens, secrets, API keys, and other potentially sensitive patterns. Custom regular expressions let researchers extend secret detection for organization-specific data. Concurrency, delays, timeouts, caching, user-agent controls, and proxy support provide control over how requests are made. Results can be printed directly or written to text and HTML outputs. The tool is mainly intended for bug bounty, reconnaissance, and defensive web-security workflows where broad content discovery is useful.
Features
- Recursive web crawling
- Endpoint discovery
- Secret, token, and API key detection
- Interesting file extension discovery
- Custom regex-based matching
- Concurrency, caching, proxy, and output controls