Unfold is a web security tool designed to brute force directories and files names on web application and servers. Unfold is excellent at discovering hidden resources and default installations which can be used to identify vulnerabilities and other security weaknesses.

There are two modes of operations which can run independently or combined for maximum effect. With the spider, Unfold will identify resources by following clues in the application code, such as URLs and forms. With bruteforce, Unfold can be configured to use dictionaries to generate directory and file paths which may exist on the target web application or server.