Cariddi is a Go-based web reconnaissance crawler for authorized security testing and application analysis. It accepts one or many domains and recursively explores reachable URLs. During crawling, it can identify interesting endpoints, file extensions, tokens, secrets, API keys, and other potentially sensitive patterns. Custom regular expressions let researchers extend secret detection for organization-specific data. Concurrency, delays, timeouts, caching, user-agent controls, and proxy support provide control over how requests are made. Results can be printed directly or written to text and HTML outputs. The tool is mainly intended for bug bounty, reconnaissance, and defensive web-security workflows where broad content discovery is useful.

Features

  • Recursive web crawling
  • Endpoint discovery
  • Secret, token, and API key detection
  • Interesting file extension discovery
  • Custom regex-based matching
  • Concurrency, caching, proxy, and output controls

Project Samples

Project Activity

See All Activity >

Categories

Security

License

GNU General Public License version 3.0 (GPLv3)

Follow Cariddi

Cariddi Web Site

Other Useful Business Software
$300 Free Credits to Build on Google Cloud Icon
$300 Free Credits to Build on Google Cloud

New customers can spin up VMs, build with AI, and query data at no cost.

Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Cariddi!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

Go

Related Categories

Go Security Software

Registered

16 hours ago