Skip to main content

Choose Scan Categories

Customizing your scan categories allows you to tailor Fuzzing Hero to focus on specific vulnerabilities, match your application's architecture, or optimize scan speed.

Configuring Categories​

  1. Navigate to the Collections page from the left sidebar and select the collection you wish to configure.
  2. Click on Settings in the top-right corner of the requests view.
  3. Select the Scan Categories tab in the settings sidebar.
  4. Toggle categories by clicking their main checkboxes:
    • Vulnerability: Comprehensive tests aimed at discovering vulnerabilities (e.g., SQL Injection, XSS).
    • Logical: Input flipping validation to identify unexpected business logic behavior.
    • Structural: Stress tests against formats like JSON and XML to detect parsing bugs and denial-of-service flaws.
  5. Click the Save Changes button at the bottom of the modal to apply your changes.

Granular Vulnerability Checks​

If you want to enable or disable specific types of vulnerability checks:

  1. Click the collapsible icon next to the Vulnerability category title to expand its subcategories.
  2. Toggle the specific vulnerability types you wish to scan for (e.g., SQL Injection, Cross-Site Scripting).
  3. Use the Enable All or Disable All buttons in the top-right of the Scan Categories section to quickly toggle all checks.
note

If you have configured custom Directives and Validators, they can also be enabled or disabled at the bottom of this tab under Directives & Validators. Read Enable Custom Checks for more details.