How to Configure SOCKS5/TOR Proxy for Anonymized Scanning in SpiderFoot

SpiderFoot routes all HTTP requests through SOCKS4, SOCKS5, HTTP, or TOR proxies by setting five configuration options (_socks1type, _socks2addr, _socks3port, _socks4user, _socks5pwd) that propagate from sfscan.py through sflib.py into every requests.Session call.

SpiderFoot is an open-source intelligence (OSINT) automation platform by smicallef/spiderfoot that supports anonymous scanning via proxy routing. This guide explains how to configure SOCKS5 and TOR proxies using the command line, configuration files, or web interface, with technical details drawn directly from the source code.

SOCKS5/TOR Proxy Configuration Options

SpiderFoot defines five proxy-related options in the core configuration (sf.py):

Option Purpose Valid Values
_socks1type Proxy protocol type 4, 5, HTTP, TOR
_socks2addr Proxy server IP or hostname e.g., 127.0.0.1
_socks3port Proxy server TCP port 1080 (SOCKS4/5), 8080 (HTTP), 9050 (TOR)
_socks4user Username for SOCKS authentication (optional) e.g., myuser
_socks5pwd Password for SOCKS5 authentication (optional) e.g., mypass

The socksProxy property is constructed as a URL string. For TOR, this becomes socks5h://127.0.0.1:9050; for SOCKS5 without remote hostname resolution, it uses socks5://.

Three Ways to Enable SOCKS5/TOR Proxy in SpiderFoot

Command-Line Configuration

Pass proxy options directly when launching sf.py:

sf.py -s example.com \
      -o _socks1type=TOR \
      -o _socks2addr=127.0.0.1 \
      -o _socks3port=9050

Authenticated SOCKS5 example:

sf.py -s example.com \
      -o _socks1type=5 \
      -o _socks2addr=127.0.0.1 \
      -o _socks3port=1080 \
      -o _socks4user=myuser \
      -o _socks5pwd=mypass

Configuration File Method

Edit your sfconfig.cfg (or equivalent JSON/YAML configuration) under the options section:

options:
  _socks1type: TOR
  _socks2addr: 127.0.0.1
  _socks3port: 9050

Web UI Configuration

  1. Navigate to Advanced Settings in the SpiderFoot web interface.
  2. Set SOCKS Server Type to TOR or 5.
  3. Enter SOCKS Server IP Address: 127.0.0.1.
  4. Enter SOCKS Server TCP Port: 9050 for TOR.
  5. Save and initiate your scan.

How Proxy Routing Works Internally

The SOCKS5/TOR proxy implementation spans three core files in smicallef/spiderfoot:

sfscan.py (lines 138-176) — Reads proxy options from self.__config and constructs the proxy URL:


# Proxy URL construction logic in sfscan.py

proxy_url = f"socks5h://{socks_addr}:{socks_port}"  # for TOR

self.__sf.socksProxy = proxy_url

sf.py — Holds the global socksProxy attribute as part of the core SpiderFoot object options.

sflib.py (line 1268) — Injects the proxy into every HTTP request by updating the requests.Session proxies dictionary:

if self.socksProxy:
    request_log.append(f"proxy={self.socksProxy}")
    session.proxies.update({
        "http": self.socksProxy,
        "https": self.socksProxy,
    })

All SpiderFoot modules inherit this proxy-aware request handling through the base class in plugin.py.

Verifying Proxy Activation

Check scan logs for the proxy indicator string. In sflib.py, successful proxy injection logs:


proxy=socks5h://127.0.0.1:9050

This confirms your SOCKS5/TOR anonymized scanning configuration is active.

Programmatic Configuration Example

For custom scripts using SpiderFoot as a library:

from spiderfoot import SpiderFoot

sf = SpiderFoot()
sf.opts['_socks1type'] = 'TOR'
sf.opts['_socks2addr'] = '127.0.0.1'
sf.opts['_socks3port'] = '9050'
sf.start()

Key Source Files for SOCKS5/TOR Proxy Support

File Role Location
sf.py Core class with global proxy options sf.py
sfscan.py Scan driver; builds proxy URL from config sfscan.py
sflib.py HTTP wrapper; applies proxy to all requests sflib.py
plugin.py Base module class inheriting proxy behavior spiderfoot/plugin.py

Summary

  • Five options control proxy behavior: _socks1type, _socks2addr, _socks3port, _socks4user, _socks5pwd.
  • Three activation methods: command-line flags, configuration file, or web UI Advanced Settings.
  • Proxy URL construction happens in sfscan.py and propagates through self.__sf.socksProxy.
  • Universal application via sflib.py updating requests.Session.proxies for every module request.
  • Verification through log output showing proxy=socks5h://... or equivalent.

Frequently Asked Questions

What is the difference between SOCKS5 and TOR proxy types in SpiderFoot?

SpiderFoot treats TOR as a specialized SOCKS5 variant that uses socks5h:// scheme for remote hostname resolution through the proxy, automatically defaulting to port 9050. Standard 5 uses socks5:// without forced remote DNS resolution. Both route traffic through your configured endpoint, but TOR simplifies setup for the standard TOR browser bundle configuration.

Does SpiderFoot support authenticated SOCKS5 proxies?

Yes. Set _socks4user for the username and _socks5pwd for the password. These credentials are embedded in the proxy URL as socks5://user:pass@host:port when both fields are populated, as handled in the proxy construction logic within sfscan.py.

Will all SpiderFoot modules use the configured proxy automatically?

Yes. The base SpiderFootPlugin class in plugin.py inherits request methods from the core sflib.py wrapper. Since sflib.py unconditionally applies session.proxies.update() whenever self.socksProxy exists, every module's HTTP requests—including DNS lookups passed through socks5h://—traverse the configured proxy without individual module changes.

Can I use an HTTP proxy instead of SOCKS5/TOR?

Yes. Set _socks1type to HTTP and configure _socks2addr and _socks3port accordingly (typically port 8080). The same internal mechanism constructs an http:// proxy URL rather than socks5:// or socks5h://.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →