Skip to main content

Run a Scan

Launching a Scan​

  1. Navigate to the Collections page and select the collection you wish to scan.
  2. Review scan settings by selecting the Settings tab on the lefthand sidebar. Here you can update authentication, scan categories, or specific scan settings. Save any changes.
  3. Click the Start Scan button in the top-right corner of the requests view.

Step 1: Health Check​

Fuzzing Hero automatically initiates a dry-run health check to ensure target connectivity:

The scanner verifies the HTTP endpoint's availability and attempt to send each request in the collection. It lists endpoints, status codes, response times, and if any errors ocurred.

If an Authentication Check Request is designated and returns an unauthorized code (such as a 401), the health check fails and will fail all requests in the collection. You must resolve the credentials in settings before you can proceed.

Click Continue to Authorization if all checks pass.

Step 2: Authorization​

Users must certify they have permission to scan target assets before running a scan. Check the authorization checkbox and then the Start Fuzzing button will become active.

Step 3: Credit Cost & Starting​

Under the authorization checkbox, review the credit deduction:

  • Personal Account: If scanning a private collection, 1 Credit will be deducted from your personal user balance.
  • Organization Pays: If the collection belongs to an organization configured with shared billing, the 1 Credit will be deducted from the organization's pooled credit balance. Otherwise, it will be deducted from the personal balance of the user that started the scan.

Click the Start Fuzzing button to queue the scan. The page will automatically transition to the active running scan view.