# How to Configure SOCKS5/TOR Proxy for Anonymized Scanning in SpiderFoot

> Learn to configure SOCKS5/TOR proxy for anonymized scanning in SpiderFoot. Enhance your OSINT investigations with secure, private data gathering. Step-by-step guide included.

- Repository: [Steve Micallef/spiderfoot](https://github.com/smicallef/spiderfoot)
- Tags: how-to-guide
- Published: 2026-08-15

---

**SpiderFoot routes all HTTP requests through SOCKS4, SOCKS5, HTTP, or TOR proxies by setting five configuration options (`_socks1type`, `_socks2addr`, `_socks3port`, `_socks4user`, `_socks5pwd`) that propagate from [`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py) through [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) into every `requests.Session` call.**

SpiderFoot is an open-source intelligence (OSINT) automation platform by smicallef/spiderfoot that supports **anonymous scanning** via proxy routing. This guide explains how to configure SOCKS5 and TOR proxies using the command line, configuration files, or web interface, with technical details drawn directly from the source code.

## SOCKS5/TOR Proxy Configuration Options

SpiderFoot defines five proxy-related options in the core configuration ([`sf.py`](https://github.com/smicallef/spiderfoot/blob/main/sf.py)):

| Option | Purpose | Valid Values |
|--------|---------|--------------|
| `_socks1type` | Proxy protocol type | `4`, `5`, `HTTP`, `TOR` |
| `_socks2addr` | Proxy server IP or hostname | e.g., `127.0.0.1` |
| `_socks3port` | Proxy server TCP port | `1080` (SOCKS4/5), `8080` (HTTP), `9050` (TOR) |
| `_socks4user` | Username for SOCKS authentication (optional) | e.g., `myuser` |
| `_socks5pwd` | Password for SOCKS5 authentication (optional) | e.g., `mypass` |

The `socksProxy` property is constructed as a URL string. For TOR, this becomes `socks5h://127.0.0.1:9050`; for SOCKS5 without remote hostname resolution, it uses `socks5://`.

## Three Ways to Enable SOCKS5/TOR Proxy in SpiderFoot

### Command-Line Configuration

Pass proxy options directly when launching [`sf.py`](https://github.com/smicallef/spiderfoot/blob/main/sf.py):

```bash
sf.py -s example.com \
      -o _socks1type=TOR \
      -o _socks2addr=127.0.0.1 \
      -o _socks3port=9050

```

Authenticated SOCKS5 example:

```bash
sf.py -s example.com \
      -o _socks1type=5 \
      -o _socks2addr=127.0.0.1 \
      -o _socks3port=1080 \
      -o _socks4user=myuser \
      -o _socks5pwd=mypass

```

### Configuration File Method

Edit your [`sfconfig.cfg`](https://github.com/smicallef/spiderfoot/blob/main/sfconfig.cfg) (or equivalent JSON/YAML configuration) under the `options` section:

```ini
options:
  _socks1type: TOR
  _socks2addr: 127.0.0.1
  _socks3port: 9050

```

### Web UI Configuration

1. Navigate to **Advanced Settings** in the SpiderFoot web interface.
2. Set **SOCKS Server Type** to `TOR` or `5`.
3. Enter **SOCKS Server IP Address**: `127.0.0.1`.
4. Enter **SOCKS Server TCP Port**: `9050` for TOR.
5. Save and initiate your scan.

## How Proxy Routing Works Internally

The SOCKS5/TOR proxy implementation spans three core files in smicallef/spiderfoot:

**[`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py) (lines 138-176)** — Reads proxy options from `self.__config` and constructs the proxy URL:

```python

# Proxy URL construction logic in sfscan.py

proxy_url = f"socks5h://{socks_addr}:{socks_port}"  # for TOR

self.__sf.socksProxy = proxy_url

```

**[`sf.py`](https://github.com/smicallef/spiderfoot/blob/main/sf.py)** — Holds the global `socksProxy` attribute as part of the core SpiderFoot object options.

**[`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) (line 1268)** — Injects the proxy into every HTTP request by updating the `requests.Session` proxies dictionary:

```python
if self.socksProxy:
    request_log.append(f"proxy={self.socksProxy}")
    session.proxies.update({
        "http": self.socksProxy,
        "https": self.socksProxy,
    })

```

All SpiderFoot modules inherit this proxy-aware request handling through the base class in [`plugin.py`](https://github.com/smicallef/spiderfoot/blob/main/plugin.py).

## Verifying Proxy Activation

Check scan logs for the proxy indicator string. In [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py), successful proxy injection logs:

```

proxy=socks5h://127.0.0.1:9050

```

This confirms your **SOCKS5/TOR anonymized scanning** configuration is active.

## Programmatic Configuration Example

For custom scripts using SpiderFoot as a library:

```python
from spiderfoot import SpiderFoot

sf = SpiderFoot()
sf.opts['_socks1type'] = 'TOR'
sf.opts['_socks2addr'] = '127.0.0.1'
sf.opts['_socks3port'] = '9050'
sf.start()

```

## Key Source Files for SOCKS5/TOR Proxy Support

| File | Role | Location |
|------|------|----------|
| [`sf.py`](https://github.com/smicallef/spiderfoot/blob/main/sf.py) | Core class with global proxy options | [`sf.py`](https://github.com/smicallef/spiderfoot/blob/main/sf.py) |
| [`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py) | Scan driver; builds proxy URL from config | [`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py) |
| [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) | HTTP wrapper; applies proxy to all requests | [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) |
| [`plugin.py`](https://github.com/smicallef/spiderfoot/blob/main/plugin.py) | Base module class inheriting proxy behavior | [`spiderfoot/plugin.py`](https://github.com/smicallef/spiderfoot/blob/main/spiderfoot/plugin.py) |

## Summary

- **Five options** control proxy behavior: `_socks1type`, `_socks2addr`, `_socks3port`, `_socks4user`, `_socks5pwd`.
- **Three activation methods**: command-line flags, configuration file, or web UI Advanced Settings.
- **Proxy URL construction** happens in [`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py) and propagates through `self.__sf.socksProxy`.
- **Universal application** via [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) updating `requests.Session.proxies` for every module request.
- **Verification** through log output showing `proxy=socks5h://...` or equivalent.

## Frequently Asked Questions

### What is the difference between SOCKS5 and TOR proxy types in SpiderFoot?

SpiderFoot treats `TOR` as a specialized SOCKS5 variant that uses `socks5h://` scheme for remote hostname resolution through the proxy, automatically defaulting to port `9050`. Standard `5` uses `socks5://` without forced remote DNS resolution. Both route traffic through your configured endpoint, but `TOR` simplifies setup for the standard TOR browser bundle configuration.

### Does SpiderFoot support authenticated SOCKS5 proxies?

Yes. Set `_socks4user` for the username and `_socks5pwd` for the password. These credentials are embedded in the proxy URL as `socks5://user:pass@host:port` when both fields are populated, as handled in the proxy construction logic within [`sfscan.py`](https://github.com/smicallef/spiderfoot/blob/main/sfscan.py).

### Will all SpiderFoot modules use the configured proxy automatically?

Yes. The base `SpiderFootPlugin` class in [`plugin.py`](https://github.com/smicallef/spiderfoot/blob/main/plugin.py) inherits request methods from the core [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) wrapper. Since [`sflib.py`](https://github.com/smicallef/spiderfoot/blob/main/sflib.py) unconditionally applies `session.proxies.update()` whenever `self.socksProxy` exists, every module's HTTP requests—including DNS lookups passed through `socks5h://`—traverse the configured proxy without individual module changes.

### Can I use an HTTP proxy instead of SOCKS5/TOR?

Yes. Set `_socks1type` to `HTTP` and configure `_socks2addr` and `_socks3port` accordingly (typically port `8080`). The same internal mechanism constructs an `http://` proxy URL rather than `socks5://` or `socks5h://`.