Skip to main content

Create a Directive

Directives are your way to customize the fuzzing payloads used during scanning.

Setting Up A New Directive​

  1. Head over to the Directives tab on the left side-bar.
  2. Click on the New Directive button.
  3. Give the directive a name and description.
  4. Add your list of payloads. Each payload should be on a new line.
  5. You can select the modification mode, which determines how the engine uses the payload. The engine can replace an existing parameter value, append to it, or prepend data.
  6. Select the visibility setting depending on the type of collection you wish to use the directive with. A directive can only be shared with one organization at a time.
  7. Consider if you want to enforce any conditions on when the directive is used. You can filter by location (query, headers, body, etc.), detected heuristic, and parameter value.
  8. Click on the Create Directive button to save it.

Using a Directive​

  1. Head over to the Collections tab on the left side-bar.
  2. Click on the collection you want to use the directive with.
  3. Click on the Scan Categories tab.
  4. Look for the Directives & Validators section. If it doesn't appear, then check that your directive has the same privacy setting as the collection you are editing.
  5. Check All Applicable Directives or select the individual directive you wish to add.
  6. Click the Save Changes button.
  7. Kick off a scan by clicking the Start Scan button in the top-right corner. Your directive payloads will be used in the scan if the filtered conditions apply.

Filter Conditions​

Some payloads need to be tested everywhere. Others have precise criteria for when they should be used. Filter conditions allow you to control when a directive is used. Conditions use an AND statement to combine multiple criteria.

Location​

Users can select to include or exclude a list of parameter locations.

  • Query: Parameters found in the URI query, such as ?id=1&name=abc
  • Header: Parameters found in the request headers, such as X-User-Id: 1234
  • Cookie: Parameters found in the request cookies, such as session_id=abc
  • Path: Parameters found in the URI path, such as /users/{id}
  • Body: The entire HTTP body, regardless of if it's structured.
    • Use Form, Json, Multipart, and XML if you want to be more granular.
  • Form: Parameters found in the request body with application/x-www-form-urlencoded content, such as name=abc&email=test%40example.com
  • Json: Parameters found in the request body with application/json content, such as {"name": "abc"}
  • Multipart: Parameters found in the request body with multipart/form-data content, such as:
-----------------------------0000000000000000000000000000
Content-Disposition: form-data; name="file"; filename="test.txt"
Content-Type: text/plain

Fuzzing Hero!
-----------------------------0000000000000000000000000000
  • XML: Parameters found in the request body with application/xml content, such as <name>abc</name>

Heuristics​

The engine tries to detect common formats and data types in your requests. Directives can allow you to ensure that certain payloads are only used when that format is detected.

  • Email Address
  • Phone Number
  • File Path
  • Markdown
  • Timestamp
  • URL
  • UUID

Parameter Name​

Apply payloads to a subset of parameters by matching against the parameter name by string or regular expression. Note that these will only match against the literal name and not any structural components.

Parameter Value​

Apply payloads to parameters by matching against the parameter value by string or regular expression.