Inspect Discovered Parameters
Fuzzing Hero's scan engine parses every HTTP request to identify input entry points. Once a scan is complete, you can review the parameters discovered and fuzzed by the engine.
Note that this isn't neccasarily a comprehensive list of parameters that are fuzzed, but rather a starting point.
Viewing Discovered Parameters
- Navigate to the Scans page from the left sidebar and select the completed scan you wish to inspect.
- Select the Discovered Parameters tab from the scan tabs row. Scans are a point-in-time test, so these will reflect the requests and values that were in the collection at the time the scan was started.
- On the left side, you will see the Discovered Requests list:
- Each request is labeled with its HTTP Method (e.g.
GET,POST). - An Authentication Check Request will display a Key icon next to its name, indicating it was designated to verify session credentials.
- Each request is labeled with its HTTP Method (e.g.
- Click on any request in the list to open its details in the right-hand preview panel.
Using the Interactive Request Viewer
In the right-hand Raw Request viewer, fuzzed parameters are highlighted in the HTTP request block.
- Hover your mouse cursor over any highlighted parameter value.
- A tooltip will pop up displaying the parameter's metadata:
- Name: The identifier or key of the parameter.
- Type: The location where the parameter was discovered (e.g.,
Query,Header,Cookie,Path,Json,Xml,Form,Multipart, etc.). - Value: The parameter value before fuzzing.