National Cyber Warfare Foundation (NCWF)

dj for mapping dynamically loaded JavaScript during authorized web reconnaissance


0 user ratings
2026-09-30 05:33:56
milo
Red Team (CNA)
"dj

dj statically analyzes HTML and JavaScript to enumerate dynamically loaded JS files — webpack chunks, import() lazy loads and source maps — for authorized reconnaissance and bug bounty workflows.








Toolejfkdev/dj — a Go-based dynamic JavaScript file extractor that statically detects webpack chunks, import() lazy loads and source maps
CategoryWeb reconnaissance and static JavaScript analysis (Go, MPL-2.0)
Primary UseEnumerating dynamically loaded JS assets on in-scope targets during authorized web assessments, bug bounty recon and supply-chain review
Safe UseUse only against systems you own or have explicit written authorization to assess; ideal for lab environments, sanctioned bug bounty programs and defensive attack-surface audits of your own deployments
Telemetry Notedj generates ordinary HTTP GET traffic against the target; WAF/CDN logs may flag its fixed Chrome TLS/JA3 profile, and its cache reuse means repeat scans on the same site issue zero network requests

Modern web applications rarely ship their entire JavaScript surface in the initial HTML. Bundlers split code into chunks fetched on demand via import(), require() or runtime chunk maps, which means a naive crawl of

 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.