ambulo
Finds the paths, parameters and endpoints a web app does not advertise, from a wordlist or by crawling, and resumes exactly where it stopped.
Formerly mach.
- Daemon port
4441- Licence
- Apache-2.0
- Install
crossfyre extension install ambulo
ambulo is a stateful HTTP content-discovery and fuzzing engine. Point it at a URL with a FUZZ marker and a wordlist; it substitutes each word into the marker, fires the requests concurrently, and reports every path that comes back with a status you accept. Because each candidate request is recorded as it runs, a scan you stop resumes exactly where it left off and never re-tests a path it already checked. The same engine also powers wordlist-free crawling.
The FUZZ marker
ambulo replaces a single placeholder, ::FUZZ:: by default, with each word from your wordlist. Put it anywhere in the URL to control what you are fuzzing: leave it out and ambulo appends it to the path for classic directory discovery, or place it inside a path segment or a query value to fuzz there instead. Change the marker with --fuzz-marker if ::FUZZ:: collides with your target.
Standalone usage
ambulo --daemon & # start the engine (port 4441)
# directory / file discovery (the marker is appended if you omit it)
ambulo scan --url https://target.tld --wordlist-path ./common.txt --tasks 20
# place the FUZZ marker to control exactly what you fuzz
ambulo scan --url "https://target.tld/::FUZZ::/login" --wordlist-path ./dirs.txt
ambulo scan --url "https://target.tld/search?q=::FUZZ::" --wordlist-path ./payloads.txtThe live UI shows progress, a found / not-found / error tally, and a table of hits with status code and response size. Press l for logs and q to quit.
Key options
| Option | What it does |
|---|---|
-u, --url | Target URL. Repeatable. The FUZZ marker is appended to the path if absent. |
-w, --wordlist-path | Wordlist file, one candidate per line. |
--fuzz-marker | The placeholder each word replaces. Defaults to ::FUZZ::. |
--http-method | get, post, put, delete or head. Defaults to get. |
--success-status-codes | Comma-separated status codes counted as a hit. Defaults to the 2xx / 3xx range. |
-t, --tasks | Concurrent workers. Higher is faster and louder. |
-i, --interval | Delay in milliseconds between requests per worker. |
--headers--cookies--basic-auth | Request headers, cookies, and HTTP basic auth for reaching authenticated paths. |
--follow-redirects--follow-redirects-depth | Whether to chase redirects, and how deep. Defaults to 5. |
--random-user-agent-request | Rotate a random User-Agent per request, or set one with --user-agent. |
--fresh-start | Ignore saved state and rescan from scratch. The default resumes. |
--adaptive-rate | Let ambulo adapt its concurrency and delay to the target's live health instead of a fixed rate. |
--posture | How aggressive the adaptive controller is: gentle, balanced or throughput. |
Output
Each result records the resolved URL, its scan status (found / not found / error), the HTTP status code, and the response and header sizes. ambulo classifies purely on the status codes you accept, so tune --success-status-codes to your target. Many engagements want 401 and 403 counted as interesting rather than ignored. Results are kept in the toolchain database and stream live; on the platform they land in your Findings explorer.
Crawling
Beyond wordlist fuzzing, ambulo can crawl a web app without a wordlist: it walks the site by following links, forms and the endpoints embedded in pages and JavaScript, mapping the reachable surface. On the platform this is the web-crawl workflow, and its output feeds toolmark and plessor the live URLs to work on.
On the platform
Run a content-discovery or web-crawl workflow from the dashboard and ambulo runs across your nodes against the targets you pass in, with the platform pacing it to the target and reserving credits for the work actually done.