Documentation
Documentation
Everything you need to get started with your first automated vulnerability scan — from domain verification and authentication options to attack chain reports, evidence exports, and compliance mapping.
Quick start
Get your first simulation running fast.
Move from signup to verified results in minutes.
Create Account
Sign up for free and verify your email address
Add Your Domain
Enter your target URL, confirm you have authorization, and configure your scan options
Launch Simulation
Set an attacker goal and constraints, then start a safe, scope-limited run
Review Results
Review the attack path, proof of impact, and recommended fixes. Export if needed
Getting Started
Platform Overview
Introduction to Nautillo Pro attack simulation workflow
First Attack Simulation
Step-by-step guide to launching your first simulation
Understanding Attack Paths
How to read attack narratives and evidence exports
Account Settings
Manage your profile, subscription, and account
Attack Simulations
Authentication & Access Control Goals
Validate real attacker outcomes like auth bypass and cross-user access
API Attack Paths
Surface mapping plus goal-driven API exploit paths
Credential & Session Attacks
Credential stuffing simulation, MFA signals, session and logout checks
Injection & SSRF Attack Paths
Validate whether common injection paths lead to real impact
JWT Attack Suite
Exploit JWT token vulnerabilities for authentication bypass
XXE Injection Attacks
Exploit XML parsers for file disclosure, SSRF, and data exfiltration
File Upload Security Analysis
Detect file upload forms and flag missing server-side validation signals
Protocol & Infrastructure Attacks
CORS Exploitation
Exploit Cross-Origin Resource Sharing misconfigurations
Open Redirect Attacks
Exploit URL redirect parameters for phishing and token theft
Host Header Injection
Poison password resets, caches, and virtual host routing
HTTP Request Smuggling
Exploit frontend-backend desync for request hijacking
WebSocket Security Attacks
Exploit WebSocket connections for hijacking and injection
Simulation Configuration
Domain Verification
Optional DNS-based domain ownership verification for additional assurance
Authentication Options
Login-then-scan, bearer tokens, session cookies, OAuth/SSO testing, and phased simulation
OAuth / SSO Security Testing
Redirect_uri hijacking, state/nonce/PKCE validation, token-in-URL, logout abuse, SAML RelayState
Simulation Modes
Single URL runs vs full domain discovery and exploration
Intrusive Action Authorization
Typed approval workflow before running high-impact actions
Error Monitoring
Automatic alarms and error threshold detection
Reports & Evidence
Attack Narrative Export
Download multi-step attack chains and evidence in PDF and JSON
Simulation Evidence
HTTP captures, signed audit logs, and step-by-step trails
Attack Path Details
Impact rating, reproduction steps, and remediation guidance
Simulation History
View past runs and track security improvements
Data & Privacy
Data Retention Policies
Plan-based retention periods for simulation data and exports
Privacy & GDPR Compliance
How we protect your data and ensure compliance
Data Deletion & Cleanup
Automated cleanup schedules and manual deletion
Audit Logs & Tracking
View evidence signatures, consent logs, and retention history
Automation & AI
AI-Guided Analysis
Generate business-logic probes and data exposure hypotheses with AI analyst support (Business plan)
AI Code Analysis
AI downloads and analyzes JavaScript bundles to find vulnerabilities (Business plan)
AI Dynamic Payload Generation
AI generates context-aware attack payloads based on target analysis (Business plan)
Target AI Prompt Injection Simulation
Test whether your site's chat or AI endpoints are vulnerable to prompt injection (Business plan, AI-guided Exploration)
Simulation Safety Controls
Configure rate limits, concurrency, and technique toggles for safe production simulations
Credential Stuffing Simulator
Run credential spraying campaigns with built-in dictionaries and throttling
Related content
Attack Simulator
Learn how our web attack simulation platform works.
Pricing
Plan details, retention, and team seats.
Security
Security practices, data handling, and controls.
Support
Get help with onboarding and verification.
Need help?
Our support team is here to help you get the most out of Nautillo Pro. Get in touch with any questions or feedback.
Response Times
Starter: 48-72 hours
Professional: 24 hours
Business: 4 hours
Available Hours
Mon-Fri: 9AM-6PM EEST
Email responses by plan tier