Directories ¶ Show internal Expand all Path Synopsis cmd vigolium command internal config ingestor logger resources/deparos resources/olium resources/spitolas resources/wordlists runner pkg agent agent/agenttypes agent/authsession agent/extensions agent/input agent/llm agent/parsing agent/prompt agent/recon agent/source anomaly anomaly/htmlutils audit audit/claudecost audit/stream authentication cftbrowser cli cli/configcmd cli/internal/clicommon cli/tui core core/hosterrors core/network core/ratelimit core/services core/stats database dbimport dedup deparos/casesense deparos/config deparos/discovery deparos/discovery/module deparos/discovery/module/builtin deparos/discovery/module/wildcard deparos/discovery/payload deparos/discovery/queue deparos/discovery/testutil deparos/discovery/tracker deparos/fingerprint deparos/html deparos/http deparos/internal/dedup deparos/jsscan deparos/jsscan/linkfinder deparos/reqcache deparos/responsechain deparos/scope deparos/spider deparos/spider/formparser deparos/storage deparos/tag deparos/waf deparos/wordlist diagnostics gitutil harvester http httpmsg input/formats input/formats/burpraw input/formats/burpxml input/formats/curl input/formats/deparos input/formats/detect input/formats/har input/formats/nuclei input/formats/openapi input/formats/postman input/formats/urls input/source jsext jsext/api jsext/api/parse knownissuescan metrics modules modules/active/angular_template_injection modules/active/api_key_url_exposure modules/active/api_rate_limit_bypass modules/active/api_spec_ingest modules/active/aspnet_blazor_exposure modules/active/aspnet_health_exposure modules/active/aspnet_identity_probe modules/active/aspnet_misconfig modules/active/aspnet_sensitive_files modules/active/aspnet_service_exposure modules/active/aspnet_viewstate_scan modules/active/authz_compare modules/active/backslash_transformation modules/active/backup_file_discovery modules/active/bfla_detection modules/active/cache_deception modules/active/client_prototype_pollution modules/active/cloud_bucket_takeover modules/active/cloud_origin_bypass modules/active/cloud_public_read modules/active/cloud_storage_listing modules/active/cms_installer_exposure modules/active/code_exec modules/active/common_directory_listing modules/active/cors_misconfiguration modules/active/crlf_injection modules/active/csrf_verify modules/active/csti_detection modules/active/default_credentials modules/active/django_admin_exposure modules/active/django_browsable_api_exposure modules/active/django_debug_exposure modules/active/django_debug_toolbar_exposure modules/active/drupal_misconfig modules/active/drupal_user_enum modules/active/express_debug_probe modules/active/express_directory_listing modules/active/express_trust_proxy_misconfig modules/active/fastapi_auth_inconsistency modules/active/fastapi_docs_exposure modules/active/fastify_hono_probe modules/active/file_upload_scan modules/active/firebase_auth_misconfig modules/active/firebase_functions_exposure modules/active/firebase_misconfig modules/active/firebase_rtdb_exposure modules/active/firebase_storage_exposure modules/active/flask_werkzeug_debugger modules/active/forbidden_bypass modules/active/graphql_scan modules/active/host_header_injection modules/active/http_method_tampering modules/active/http_request_smuggling modules/active/idor_detection modules/active/idor_guid modules/active/iis_shortname_discovery modules/active/input_behavior_probe modules/active/insecure_deserialization modules/active/java_appserver_console modules/active/java_sensitive_files modules/active/joomla_misconfig modules/active/joomla_user_enum modules/active/js_devserver_exposure modules/active/jsonp_callback modules/active/jwt_vulnerability modules/active/laravel_admin_exposure modules/active/laravel_devtool_exposure modules/active/laravel_ignition_rce modules/active/laravel_misconfig modules/active/laravel_sensitive_files modules/active/ldap_injection modules/active/lfi_generic modules/active/lfi_path_traversal modules/active/log4shell_probe modules/active/magento_misconfig modules/active/mass_assignment modules/active/mcp_batch_abuse modules/active/mcp_completion_enum modules/active/mcp_method_enum modules/active/mcp_origin_rebinding modules/active/mcp_prompt_fuzz modules/active/mcp_resource_fuzz modules/active/mcp_server_probe modules/active/mcp_session_checks modules/active/mcp_tool_fuzz modules/active/metaframework_probe modules/active/nextjs_chunk_audit modules/active/nextjs_data_leakage modules/active/nextjs_draft_mode_exposure modules/active/nextjs_image_ssrf modules/active/nextjs_middleware_bypass modules/active/nextjs_version_audit modules/active/nginx_off_by_slash modules/active/nginx_path_escape modules/active/nosqli_error_based modules/active/nosqli_operator_injection modules/active/oast_probe modules/active/oauth_misconfiguration modules/active/open_redirect modules/active/path_normalization modules/active/pdf_generation_injection modules/active/php_composer_exposure modules/active/php_debug_exposure modules/active/php_framework_debug modules/active/php_path_info_misconfig modules/active/php_source_disclosure modules/active/prototype_pollution modules/active/proxy_header_trust modules/active/proxy_pingback modules/active/race_interference modules/active/rails_action_mailbox_probe modules/active/rails_active_storage_probe modules/active/rails_admin_dashboard modules/active/rails_info_exposure modules/active/rails_sensitive_files modules/active/reflected_ssti modules/active/response_header_injection modules/active/sensitive_file_discovery modules/active/smart_behavior_detection modules/active/spring_actuator_misconfig modules/active/spring_boot_admin_exposure modules/active/spring_cloud_config_exposure modules/active/spring_data_rest_exposure modules/active/spring_debug_exposure modules/active/spring_gateway_exposure modules/active/spring_h2_console_exposure modules/active/spring_jolokia_exposure modules/active/sqli_boolean_blind modules/active/sqli_error_based modules/active/sqli_time_blind modules/active/ssrf_blind modules/active/ssrf_detection modules/active/ssti_blind modules/active/ssti_detection modules/active/struts_ognl_injection modules/active/subdomain_takeover modules/active/suspect_transform modules/active/swagger_exposure modules/active/symfony_misconfig modules/active/tomcat_manager_exposure modules/active/web_cache_poisoning modules/active/websocket_security modules/active/wp_ajax_exposure modules/active/wp_misconfig modules/active/wp_user_enum modules/active/wp_xmlrpc modules/active/ws_cswsh modules/active/ws_injection modules/active/xml_saml_security modules/active/xss_dom_confirm modules/active/xss_light_scanner modules/active/xxe_generic modules/infra modules/infra/mcp modules/modkit modules/modkit/specutil modules/modtest modules/passive/anomaly_ranking modules/passive/api_pagination_leak modules/passive/api_spec_detect modules/passive/api_version_detect modules/passive/aspnet_fingerprint modules/passive/aspnet_viewstate_detect modules/passive/auth_headers_detect modules/passive/base64_data_detect modules/passive/build_misconfig_detect modules/passive/cache_auth_misconfiguration modules/passive/cache_data_leak modules/passive/cacheable_https_detect modules/passive/client_auth_guard modules/passive/cloud_signed_url_leak modules/passive/cloud_storage_error_info modules/passive/cloud_storage_fingerprint modules/passive/content_type_mismatch modules/passive/cookie_security_detect modules/passive/cors_headers_detect modules/passive/cors_vary_origin_missing modules/passive/crypto_weakness_detect modules/passive/csp_weakness_audit modules/passive/csrf_detect modules/passive/directory_listing_detect modules/passive/django_fingerprint modules/passive/dom_xss_detect modules/passive/drupal_api_detect modules/passive/drupal_fingerprint modules/passive/endpoint_classifier modules/passive/env_secret_exposure modules/passive/error_message_detect modules/passive/express_fingerprint modules/passive/express_session_audit modules/passive/fastapi_fingerprint modules/passive/firebase_fingerprint modules/passive/flask_fingerprint modules/passive/graphql_error_leak modules/passive/graphql_fingerprint modules/passive/graphql_introspection_detect modules/passive/grpc_web_detect modules/passive/hsts_preload_audit modules/passive/idor_params_detect modules/passive/info_disclosure_detect modules/passive/input_reflection_detect modules/passive/insecure_token_storage modules/passive/jackson_deserialize_detect modules/passive/java_server_fingerprint modules/passive/javascript_uri_sink modules/passive/joomla_api_detect modules/passive/joomla_fingerprint modules/passive/js_framework_fingerprint modules/passive/jwt_claims_detect modules/passive/jwt_weak_secret modules/passive/laravel_fingerprint modules/passive/mcp_description_injection modules/passive/mcp_endpoint_detect modules/passive/metaframework_fingerprint modules/passive/mixed_content_detect modules/passive/nextauth_config_audit modules/passive/nextjs_config_audit modules/passive/nextjs_dynamic_param_audit modules/passive/nuxt_config_audit modules/passive/oauth_facebook_detect modules/passive/openredirect_params modules/passive/password_autocomplete_detect modules/passive/permissions_policy_detect modules/passive/php_generic_fingerprint modules/passive/python_debug_detect modules/passive/rails_action_cable_detect modules/passive/rails_active_storage_detect modules/passive/rails_debug_detect modules/passive/rails_fingerprint modules/passive/referrer_policy_detect modules/passive/remix_loader_exposure modules/passive/secret_detect modules/passive/security_headers_missing modules/passive/sensitive_api_fields_detect modules/passive/sensitive_header_leak modules/passive/sensitive_url_params modules/passive/serialized_object_detect modules/passive/server_action_auth modules/passive/server_action_bind_audit modules/passive/server_action_input_audit modules/passive/server_only_boundary_audit modules/passive/software_version_header modules/passive/sourcemap_detect modules/passive/spring_fingerprint modules/passive/sql_syntax_detect modules/passive/ssr_data_exposure modules/passive/ssr_hydration_xss modules/passive/subresource_integrity_detect modules/passive/symfony_fingerprint modules/passive/unsafe_html_sink modules/passive/verbose_error_stacktrace modules/passive/wasm_module_detect modules/passive/wp_fingerprint modules/passive/wp_rest_api_detect modules/shared/authzutil modules/shared/diffscan modules/shared/jsframework mutation notify notify/discord notify/telegram notify/webhook oast olium olium/auth olium/autopilot olium/engine olium/provider olium/skill olium/stream olium/tool olium/toollog olium/tui olium/vigtool output piolium piolium/picost piolium/pistream procutil queue replay replay/jar server spitolas spitolas/internal/action spitolas/internal/auth spitolas/internal/browser spitolas/internal/condition spitolas/internal/config spitolas/internal/crawler spitolas/internal/form spitolas/internal/fragment spitolas/internal/logger spitolas/internal/mab spitolas/internal/metrics spitolas/internal/network spitolas/internal/state spitolas/internal/testutil storage terminal toolexec toolexec/kingfisher types types/severity types/stringslice utils work yamlext public test benchmark/agent benchmark/harness deparos pkg-testdata/anomaly tools/covmerge command Click to show internal directories. Click to hide internal directories.