Attacker techniques
Attacker techniques library
A clear view of attacker techniques and outcomes: confirmed attack paths, defensive posture signals, and recon outcomes that show where no viable path was found.
OWASP Top 10
Common exploit paths attackers use against modern web applications
SQL Injection
Error-based, union-based, and time-based blind detection across URL parameters, POST form fields, and JSON API endpoints — with baseline latency comparison to confirm blind injection
NoSQL Injection
MongoDB operator injection ($gt, $ne, $regex, $where, JS evaluation) and Redis RESP command injection.
Command Injection
Output-based (unique echo token, id/whoami output, /etc/passwd), error-based (shell error messages), and time-based blind with baseline latency comparison — across GET params, POST forms, and JSON APIs
XXE Injection
XML External Entity attacks for file disclosure, SSRF, and blind data exfiltration
Cross-Site Scripting (XSS)
Reflected, stored, and DOM-based XSS with safe detection payloads
SSRF Attacks
Server-Side Request Forgery to access internal networks and cloud metadata
Unauthorized Access (IDOR)
Insecure Direct Object References, privilege escalation, mass assignment
Data Exposure Paths
Information disclosure via responses, error messages, and stack traces
Hardening Gaps
Security misconfigurations that enable common attacker paths
Authentication & Session Attacks
Attack paths targeting authentication mechanisms and session management
JWT Attack Suite
None algorithm bypass, weak secret brute force, signature manipulation, JWK injection
Credential Stuffing Simulation
Rate-aware password spray with lockout detection and account enumeration signals
Session Hijacking
Session fixation, predictable token detection, and insecure session handling indicators
Authentication Bypass
Login bypass, default credentials, password reset poisoning
MFA Implementation Detection
Detects MFA endpoint presence, checks for missing lockout controls and token expiry weaknesses
Protocol & Infrastructure Attacks
Advanced protocol-level attacks targeting web infrastructure
CORS Exploitation
Origin reflection, null origin bypass, subdomain takeover, credentials exposure
Open Redirect Attacks
URL parameter manipulation, protocol bypass, OAuth redirect hijacking
Host Header Injection
Password reset poisoning, cache poisoning via Host header reflection, virtual host routing bypass
HTTP Request Smuggling
CL.TE, TE.CL, TE.TE desync attacks, HTTP/2 downgrade, request hijacking
WebSocket Security
Cross-Site WebSocket Hijacking, Origin bypass, insecure protocol, message injection
File Upload, Injection & Code Execution
File upload form detection and injection vulnerability testing for code execution paths
File Upload Form Detection
Detect file upload forms and flag missing server-side validation signals such as misconfigured form encoding
Race Condition Testing
Detect time-of-check to time-of-use flaws and concurrent request vulnerabilities that bypass business logic or rate limits
Cryptographic Failures
Weak cipher suites, insecure TLS configuration, missing HSTS, and improper certificate validation
Business Logic Flaws
Authentication bypass via workflow manipulation, price tampering, limit bypass, and privilege escalation through improper multi-step logic
Template Injection
Server-Side Template Injection in Jinja2, Twig, Freemarker, ERB
LDAP Injection
Directory service exploitation via malformed LDAP queries
API Security
Attack paths specific to REST APIs, GraphQL, and web services
API Authentication Abuse
Bearer token misuse, API key exposure, broken authentication
GraphQL Exploitation
Introspection exposure, query depth attacks, batching abuse, DoS patterns
Endpoint Discovery
Hidden endpoint enumeration, admin panel discovery, debug routes
BOLA/IDOR Attacks
Broken Object Level Authorization, resource ID manipulation
Mass Assignment
Privilege escalation via unprotected field injection
Rate Limit Bypass
Circumventing API rate limits for abuse and DoS
Reconnaissance & Configuration
Attack surface mapping and security configuration analysis
TLS/SSL Analysis
Certificate validation, HSTS analysis, cipher suite weaknesses, mixed content
Security Headers
CSP, X-Frame-Options, HSTS, cookie flags, framing protections
Cryptographic Failures
Weak hashes, exposed secrets, insecure random, key exposure
Passive Reconnaissance
DNS enumeration, SSL certificate analysis, technology fingerprinting
Form Analysis
Input validation, CSRF protection, hidden field manipulation
Error Information Disclosure
Stack traces, debug info, internal paths in error responses
AI-Powered Attack Simulation (Business)
AI-guided discovery and adaptive payload generation for advanced attack scenarios
AI Business Logic Analysis
AI maps workflows to uncover authorization flaws, race conditions, and abuse scenarios
AI Code Analysis
JavaScript bundle analysis for hardcoded secrets, auth bypass, and API vulnerabilities
AI Dynamic Payloads
Context-aware attack payload generation with WAF bypass and adaptive mutation
AI Sensitive Data Review
Probes 35+ sensitive paths and uses AI to classify ambiguous responses
AI Social Engineering Surface
Detects external form data exfiltration risks and mixed content loading on HTTPS pages
Target AI Prompt Injection Simulation
Discovers chat/AI endpoints on the target, then runs G1–G5 probes: system prompt disclosure, policy bypass, user PII extraction, cross-tenant data, and tool abuse. Confidence gate, stop after first proof, redacted evidence.
Ready to run a simulation?
Run an authorized, scope-safe attack simulation to see confirmed attack paths with proof of impact, plus defensive posture signals and recon outcomes.