Skip to main content

Inspect Discovered Parameters

Fuzzing Hero's scan engine parses every HTTP request to identify input entry points. Once a scan is complete, you can review the parameters discovered and fuzzed by the engine.

Note that this isn't neccasarily a comprehensive list of parameters that are fuzzed, but rather a starting point.

Viewing Discovered Parameters​

  1. Navigate to the Scans page from the left sidebar and select the completed scan you wish to inspect.
  2. Select the Discovered Parameters tab from the scan tabs row. Scans are a point-in-time test, so these will reflect the requests and values that were in the collection at the time the scan was started.
  3. On the left side, you will see the Discovered Requests list:
    • Each request is labeled with its HTTP Method (e.g. GET, POST).
    • An Authentication Check Request will display a Key icon next to its name, indicating it was designated to verify session credentials.
  4. Click on any request in the list to open its details in the right-hand preview panel.

Using the Interactive Request Viewer​

In the right-hand Raw Request viewer, fuzzed parameters are highlighted in the HTTP request block.

  1. Hover your mouse cursor over any highlighted parameter value.
  2. A tooltip will pop up displaying the parameter's metadata:
    • Name: The identifier or key of the parameter.
    • Type: The location where the parameter was discovered (e.g., Query, Header, Cookie, Path, Json, Xml, Form, Multipart, etc.).
    • Value: The parameter value before fuzzing.