Directives and Validators
Fuzzing Hero implements plenty of great default tests that will fuzz and mutate your requests. Sometimes you need something custom-tailored to your environment, which is where directives and validators come in.
Fuzzing Hero takes a different approach than some of our competitors. We intentionally unlink payloads from reported issues by default. This gives us the most flexibility to broadly capture patterns or to be highly precise in what caused an issue.
Directives
Directives are the mechanism to define custom payloads that are used during a scan. Fuzzing Hero allows you to define conditions for when and how these payloads are used.
These can be incredibly helpful when you find a payload that you need to scan everywhere with. This allows you to bring your domain knowledge into the scan and test for issues on your application's stack that may be highly custom.
Validators
Validators are a pattern for defining response behavior. In the same way as directives, you get unique conditions that you can apply to shape validators.
Vulnerability issues can be created with validators. They allow for you to define the details of the issue and severity. Fuzzing Hero will automatically pull in the matching proof to show what was found.
Contributing
If you have had success with directives and validators and believe sharing your work would benefit the community, please reach out to https://fuzzinghero.com/contact. We may highlight community contributions and give bonus scan credits for suggestions.
Customers own their data by default, which means Fuzzing Hero will not use your directives and validators for improving testing methodologies. This is a secure platform for helping scale automated testing of authorized resources.