Documentation

Documentation

Everything you need to get started with your first automated vulnerability scan — from domain verification and authentication options to attack chain reports, evidence exports, and compliance mapping.

Quick start

Get your first simulation running fast.

Move from signup to verified results in minutes.

1

Create Account

Sign up for free and verify your email address

~30 seconds
2

Add Your Domain

Enter your target URL, confirm you have authorization, and configure your scan options

~1 minute
3

Launch Simulation

Set an attacker goal and constraints, then start a safe, scope-limited run

~5-15 minutes
4

Review Results

Review the attack path, proof of impact, and recommended fixes. Export if needed

~10 minutes

Getting Started

Platform Overview

New User

Introduction to Nautillo Pro attack simulation workflow

First Attack Simulation

Essential

Step-by-step guide to launching your first simulation

Understanding Attack Paths

Guide

How to read attack narratives and evidence exports

Account Settings

Manage your profile, subscription, and account

Attack Simulations

Authentication & Access Control Goals

Popular

Validate real attacker outcomes like auth bypass and cross-user access

API Attack Paths

Advanced

Surface mapping plus goal-driven API exploit paths

Credential & Session Attacks

Critical

Credential stuffing simulation, MFA signals, session and logout checks

Injection & SSRF Attack Paths

High Risk

Validate whether common injection paths lead to real impact

JWT Attack Suite

Critical

Exploit JWT token vulnerabilities for authentication bypass

XXE Injection Attacks

Critical

Exploit XML parsers for file disclosure, SSRF, and data exfiltration

File Upload Security Analysis

Essential

Detect file upload forms and flag missing server-side validation signals

Protocol & Infrastructure Attacks

CORS Exploitation

Critical

Exploit Cross-Origin Resource Sharing misconfigurations

Open Redirect Attacks

High Risk

Exploit URL redirect parameters for phishing and token theft

Host Header Injection

Critical

Poison password resets, caches, and virtual host routing

HTTP Request Smuggling

Critical

Exploit frontend-backend desync for request hijacking

WebSocket Security Attacks

High Risk

Exploit WebSocket connections for hijacking and injection

Simulation Configuration

Domain Verification

Optional

Optional DNS-based domain ownership verification for additional assurance

Authentication Options

Advanced

Login-then-scan, bearer tokens, session cookies, OAuth/SSO testing, and phased simulation

OAuth / SSO Security Testing

Advanced

Redirect_uri hijacking, state/nonce/PKCE validation, token-in-URL, logout abuse, SAML RelayState

Simulation Modes

Guide

Single URL runs vs full domain discovery and exploration

Intrusive Action Authorization

Critical

Typed approval workflow before running high-impact actions

Error Monitoring

New

Automatic alarms and error threshold detection

Reports & Evidence

Attack Narrative Export

Standard

Download multi-step attack chains and evidence in PDF and JSON

Simulation Evidence

Advanced

HTTP captures, signed audit logs, and step-by-step trails

Attack Path Details

Guide

Impact rating, reproduction steps, and remediation guidance

Simulation History

Standard

View past runs and track security improvements

Data & Privacy

Data Retention Policies

New

Plan-based retention periods for simulation data and exports

Privacy & GDPR Compliance

Essential

How we protect your data and ensure compliance

Data Deletion & Cleanup

Guide

Automated cleanup schedules and manual deletion

Audit Logs & Tracking

Advanced

View evidence signatures, consent logs, and retention history

Automation & AI

AI-Guided Analysis

Business

Generate business-logic probes and data exposure hypotheses with AI analyst support (Business plan)

AI Code Analysis

Business

AI downloads and analyzes JavaScript bundles to find vulnerabilities (Business plan)

AI Dynamic Payload Generation

Business

AI generates context-aware attack payloads based on target analysis (Business plan)

Target AI Prompt Injection Simulation

Business

Test whether your site's chat or AI endpoints are vulnerable to prompt injection (Business plan, AI-guided Exploration)

Simulation Safety Controls

Advanced

Configure rate limits, concurrency, and technique toggles for safe production simulations

Credential Stuffing Simulator

Advanced

Run credential spraying campaigns with built-in dictionaries and throttling

Related content

Attack Simulator

Learn how our web attack simulation platform works.

Explore

Pricing

Plan details, retention, and team seats.

Explore

Security

Security practices, data handling, and controls.

Explore

Support

Get help with onboarding and verification.

Explore

Need help?

Our support team is here to help you get the most out of Nautillo Pro. Get in touch with any questions or feedback.

Response Times

Starter: 48-72 hours
Professional: 24 hours
Business: 4 hours

Available Hours

Mon-Fri: 9AM-6PM EEST
Email responses by plan tier