Features
Confirmed findings only. Here's exactly how.
Nautillo Pro is built to prove exploitability, not pad a findings list. Here is exactly what runs, what it tests for, and what evidence it produces.
HTTP proof with every confirmed finding
Every vulnerability includes the exact request and response that proves exploitability, not a theoretical risk. Show it to your team, investors, or auditors.
Core OWASP attack coverage on every plan
SQL injection, XSS, authentication bypass, IDOR, SSRF, and more. Baseline coverage is available on every plan; broader scope and deeper exploit paths expand by tier.
Results in minutes, not consulting cycles
Focused simulations often complete in minutes. Larger authenticated or broader-scope runs take longer, but still fit modern release cadence.
Presets handle the setup — no security engineer required
Pick Recon, Surface, or Intrusive preset and launch. Or configure authentication type, test scope, and concurrency for precision. No dedicated security expert needed to get started.
Multi-step attack chains
The simulator builds realistic sequences such as Credential -> Session -> Data Exposure to show what an attacker could actually chain together, not just isolated findings.
Authenticated scanning — test behind the login wall
Supply a bearer token, API key, or session cookie, or let the scanner log in with form credentials. IDOR, privilege escalation, and access control failures inside authenticated areas are where the most critical findings live.
Core Attack Simulation
Common Exploit Paths (OWASP Top 10)
Goal-driven simulations that attempt common exploit paths like injection, auth abuse, and misconfigurations, with proof when impact is reachable.
Single URL and Full-Domain Scanning
Target a single endpoint or crawl the entire domain — all discovered URLs, subdomains, forms, API routes, and SPA views. Full-domain scope is available on Professional and Business plans.
API Attack Paths
Discover REST and GraphQL endpoints, then attempt realistic API abuse paths including auth bypass and broken authorization. IDOR and advanced exploit paths require Business plan.
Semi-Autonomous Attack Simulation
Runs safe, non-destructive attacker behavior to pursue outcomes like unauthorized access and data exposure, and records the decision trail.
Authenticated Simulation Support
Store bearer tokens, session cookies, and HTTP credentials to explore attacker paths inside authenticated areas.
Login-Then-Scan
Provide credentials and the scanner logs in automatically before the simulation starts, capturing the session and using it across all subsequent attack probes.
Exposure & Context
Sensitive Data Detection
Detect potential exposure of API keys, credentials, tokens, and sensitive data in responses and client-side code.
Hardening Signals
Report defensive posture signals like CSP, HSTS, cookie flags, and TLS settings separately from exploit paths.
Stack Identification
Identify frameworks, libraries, and server components to help teams prioritize fixes and rule out false positives.
Attacker Techniques
Account Takeover & Unauthorized Access
Attempt common attacker paths like privilege escalation, broken access control, token abuse, and session weaknesses.
Input Manipulation Attacks
SQL injection (error-based, union-based, time-based blind with baseline latency comparison across GET params, POST forms, and JSON APIs), active command injection (output-based echo token, error-based, time-based blind), XSS, XXE, and parameter tampering.
Session Abuse & Token Handling
Check session behavior, cookie flags, CSRF defenses, and token handling that attackers abuse to stay logged in or hijack sessions.
JWT Attack Suite
Exploit JWT vulnerabilities including none algorithm bypass, weak secret brute force, signature manipulation, and JWK/kid injection attacks.
Login Rate Limit & Lockout Testing
Send rapid request sequences against authentication endpoints to detect missing rate limiting, absent account lockout policies, and MFA implementation gaps that leave accounts exposed to automated attacks.
Protocol & Infrastructure Attacks
CORS Exploitation
Exploit CORS misconfigurations including origin reflection, null origin bypass, subdomain takeover, and credentials exposure attacks.
Open Redirect Exploitation
Manipulate URL redirect parameters for phishing, OAuth token hijacking, and credential theft through protocol and encoding bypass techniques.
Host Header Injection
Poison password reset flows, exploit cache servers, and bypass virtual host routing through Host header manipulation attacks.
HTTP Request Smuggling
Exploit frontend-backend desync with CL.TE, TE.CL, and TE.TE smuggling attacks, HTTP/2 downgrade, and request hijacking techniques.
WebSocket Security Attacks
Exploit Cross-Site WebSocket Hijacking (CSWSH), Origin bypass, insecure protocol usage, and message injection vulnerabilities.
Exploit Paths & Evidence
Multi-Step Attack Chains
Scanner-built attack chains (Credential -> Session -> Data, OAuth -> Account Takeover, Injection -> Escalation) with labeled steps and proof of impact. Credential chains activate only when a login flow is detected.
Evidence & Control Mapping
Export narratives and evidence. Optional mapping to CVSS and seven compliance frameworks (PCI DSS 4.0, GDPR Art.32, HIPAA, SOC 2, ISO 27001:2022, OWASP Top 10 2021, NIST CSF 2.0) is available on the Business plan.
Risk Scoring & Analytics
Risk scoring with prioritization and trend analysis across simulations, based on what an attacker can achieve.
Evidence Export (PDF + JSON)
Download PDF narratives with evidence and remediation steps. JSON export is available on Professional and Business plans.
Embeddable Security Badge
Generate a 'Secured by Nautillo Pro' badge from your dashboard and embed it on your site. Show prospects, enterprise buyers, and end-users that your app is actively tested.
File Upload, Business Logic & Injection
File Upload Form Detection
Detect file upload forms and flag missing server-side validation signals such as misconfigured form encoding. Identifies pages that require follow-up manual testing of extension, MIME type, and size controls.
Business Logic Flaw Detection
Test for authentication bypass via workflow manipulation, price tampering, limit bypass, and privilege escalation through improper multi-step logic, vulnerabilities that injection scanners routinely miss.
Race Condition Testing
Detect time-of-check to time-of-use (TOCTOU) flaws and concurrent request vulnerabilities that bypass business logic or rate limits — including parallel request attacks on critical operations.
XXE Injection Attacks
Exploit XML parsers to read sensitive files, perform SSRF, and exfiltrate data through external entity injection and blind XXE techniques.
AI-Powered Attack Simulation
AI-Guided Discovery
AI guidance proposes business-logic probes, sensitive data checks, and multi-step exploit hypotheses for review and controlled execution.
AI Code Analysis
AI downloads and analyzes JavaScript bundles to identify authentication bypass, hardcoded secrets, authorization flaws, and API security issues.
AI Dynamic Payload Generation
AI generates context-aware attack payloads based on detected parameters, technologies, and WAF signatures. Simulates how modern attackers use AI.
Target AI Prompt Injection Simulation
When AI-guided Exploration is on, the simulator discovers chat/AI endpoints, confirms LLM behavior with a confidence gate, then runs safe prompt-injection probes (G1-G5) to test for system prompt leakage, policy bypass, user PII extraction, cross-tenant data disclosure, and tool abuse. Stops after first proof; evidence is hashed and redacted.
Simulation Safety Controls
Toggle techniques, throttle concurrency, and set pacing to stay within production rate limits and avoid disruption.
OAuth / SSO Security Checks
Discover OAuth and SAML endpoints, then test redirect_uri hijacking, missing state parameters, weak PKCE, token-in-URL, logout redirect abuse, and SPA client secret exposure.
Phased Attack Simulation
Run unauthenticated probes first (attacker's view before login), then re-run with credentials to reveal what attackers can reach after gaining access. This surfaces two distinct threat models in one scan.
Governance & Audit
Intrusive Action Authorization
Require in-app acknowledgement, typed authorization, and ownership verification before running high-impact techniques.
Immutable Audit Logs
Capture signed evidence, raw HTTP transcripts, and decision trails to support internal review and audit needs.
Domain Ownership Verification
Optional DNS-based domain ownership verification available for teams that want an additional proof layer alongside typed consent and audit logging.
Data Management & Privacy
Automated Data Retention
Plan-based data retention policies automatically purge simulation data, evidence, and logs per your subscription tier (7 days to 24 months).
Scheduled Data Cleanup
Daily automated cleanup of expired data with detailed audit logs. Sensitive data like auth tokens and file uploads purged immediately.
Privacy-First Storage
Configurable retention periods for simulation metadata, exploit paths, HTTP captures, and audit logs to support GDPR compliance.
Additional capabilities
Ready to run your first simulation?
Free plan. No credit card. Start your first simulation in minutes.