Overview
Nikto runs a broad checklist against a web server: default files, dangerous CGIs, header weaknesses and version-specific known issues.\nIt is deliberately noisy and produces false positives, so it works best as a first sweep rather than a definitive audit.\nCombining it with a targeted tool like Burp gives coverage without drowning in output.
Indicators of Compromise
Signals that suggest this is present on a system.
- High-rate requests to /icons, /cgi-bin and admin paths
- Rapid enumeration of backup and config filenames
- Scanner user-agent strings in access logs