Objects
AlertModel
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| severity | SEVERITY | True | Severity of the alert | SEVERITY |
| name | string | True | Name of the alert | |
| context | string | True | Context of the alert | |
| category | CATEGORY | False | Category of the alert | CATEGORY |
| description | string | False | Description of the alert | |
| remediation | string | False | Remediation of the alert | |
| compliance | Compliance | False | Compliance standards violated by this alert | Compliance |
Compliance
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| owasp | string | False | ||
| pci-dss | string | False | ||
| gdpr | string | False | ||
| soc2 | string | False | ||
| psd2 | string | False | ||
| iso27001 | string | False | ||
| nist | string | False | ||
| fedramp | string | False | ||
| nis2 | string | False | ||
| hipaa | string | False | ||
| owasp_llm | string | False | ||
| cwe | string | False |
CrudDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | CRUD | False | Condition is the request is this CRUD operation | CRUD |
| is_not | CRUD | False | Condition is the request is not this CRUD operation | CRUD |
| in | CRUD | False | Condition is the request is in this list of CRUD operations (exact match) | CRUD |
| if | Const[helpers.request.crud] | False | Use this to select against the detected CRUD operation of the request. |
HTTPRAWSeeder
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| protocol | Const[http] | False | The HTTP seeder allows you to send a request at the start of the scan. | |
| raw | string | True | The raw HTTP request in nuclei format. | |
| user | string | False | The user to use for the request. If not provided, the request is sent without authentication. |
LogicalAndDetector
| Property | Type | Required | Description | Reference | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| and | `LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector` | False | Logical and on a list of detectors | [LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector](#LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector) |
| if | Const[and] | False | Use this to apply a logical and on a list of detectors. |
LogicalNotDetector
| Property | Type | Required | Description | Reference | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| not | `LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector` | False | Logical not of a detector | [LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector](#LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector) |
| if | Const[not] | False | Use this to apply a logical not on a detector. |
LogicalOrDetector
| Property | Type | Required | Description | Reference | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| or | `LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector` | False | Logical or on a list of detectors | [LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector](#LogicalNotDetector | SchemaNeedAuthenticationDetector | ResponseObjectDetector | CrudDetector | RequestHeadersDetector | SchemaPathRefDetector | ResponseBodyJSONDetector | ResponseStatusCodeDetector | LogicalOrDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestObjectDetector | ScanTypeDetector | ResponseHeadersDetector | ResponseBodyTextDetector | RequestIsAuthenticatedDetector | SchemaUrlDetector | ResponseDurationDetector | ResponseIsSuccessfulDetector | MethodDetector | LogicalAndDetector | RequestUserDetector) |
| if | Const[or] | False | Use this to apply a logical or on a list of detectors. |
MethodDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | HTTP_METHOD | False | Condition is the request is this CRUD operation | HTTP_METHOD |
| is_not | HTTP_METHOD | False | Condition is the request is not this CRUD operation | HTTP_METHOD |
| in | HTTP_METHOD | False | Condition is the request is in this list of CRUD operations (exact match) | HTTP_METHOD |
| if | Const[request.method] | False | Use this to select against the request HTTP method. |
MethodMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| key | Const[request.method] | False | You can use this mutator to change the HTTP method of the | |
| value | HTTP_METHOD | False | The value to set. | HTTP_METHOD |
| values | HTTP_METHOD | False | The values to set, generates multiple queries. | HTTP_METHOD |
Middleware
| Property | Type | Required | Description | Reference | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| trigger | `CrudDetector | LogicalAndDetector | LogicalNotDetector | LogicalOrDetector | MethodDetector | RequestBodyJSONDetector | RequestBodyTextDetector | RequestHeadersDetector | RequestIsAuthenticatedDetector | RequestObjectDetector | RequestUserDetector | ResponseBodyJSONDetector | ResponseBodyTextDetector | ResponseDurationDetector | ResponseHeadersDetector | ResponseIsSuccessfulDetector | ResponseObjectDetector | ResponseStatusCodeDetector | ScanTypeDetector | SchemaNeedAuthenticationDetector | SchemaPathRefDetector | SchemaUrlDetector` | True | The detectors to trigger the transform, on the request or response. See Detectors | |
| mutate | `MethodMutator | RequestBodyJSONMutator | RequestBodyTextMutator | RequestHeadersMutator | RequestObjectMutator | RequestUserMutator | SchemaPathRefMutator | SchemaUrlMutator` | True | The mutations to apply to the request and replay it. See Mutators |
ObjectMatcher
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| type | ObjectTypeMatcher | False | Object scalar type to match | ObjectTypeMatcher |
| name | StringMatcher | False | Object scalar name to match | StringMatcher |
| value | StringMatcher | False | Object scalar value to match | StringMatcher |
ObjectMutate
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
ObjectTypeMatcher
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | OBJECT_TYPE | False | Object type is exactly this type | OBJECT_TYPE |
| is_not | OBJECT_TYPE | False | Object type is any this type except this one | OBJECT_TYPE |
| in | OBJECT_TYPE | False | Object type is in the following list | OBJECT_TYPE |
RESTSeeder
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| protocol | Const[rest] | False | The REST seeder allows you to send a request that adapts to the host of your current scan. | |
| user | string | False | The user to use for the request. If not provided, the request is sent without authentication. | |
| path | string | False | ||
| method | HTTP_METHOD | False | HTTP_METHOD | |
| headers | Dict[string, string] | False | ||
| body | string | False | ||
| params | Dict[string, string] | False |
RegexReplace
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| pattern | string | True | The regex pattern to match. | |
| replacement | string | True | The replacement, use \1, \2, ... to refer capture groups. |
RequestBodyJSONDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | Dict[string, None] | False | Condition is this exact JSON | |
| is_not | Dict[string, None] | False | Condition is not this exact JSON | |
| in | Dict[string, None] | False | Condition is in this list of JSON | |
| jq | string | False | JQ query to match and use as boolean | |
| if | Const[request.body.json] | False | Use this to select and compare the request body when detected as JSON, using jq-like syntax. |
RequestBodyJSONMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| key | Const[request.body.json] | False | You can use this mutator to change the JSON body of the request before resending it. | |
| jq | string | False | JQ query to apply to the JSON body. Seestedolan.github.io |
RequestBodyTextDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch | |
| if | Const[request.body.text] | False | Use this to select and compare the request body as text, using string compare. |
RequestBodyTextMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
| key | Const[request.body.text] | False | You can use this mutator to change the body (as text) of the request before resending it. |
RequestHeadersDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| key | StringMatcher | False | Key to match | StringMatcher |
| value | StringMatcher | False | Value to match | StringMatcher |
| if | Const[request.headers] | False | Use that to select and compare the request headers in a key value dictionary. |
RequestHeadersMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
| key | Const[request.headers] | False | You can use this mutator to change the headers of the request before resending it. | |
| name | string | True | The header name to match, supports regex. | |
| delete | boolean | False | Delete the matched headers. |
RequestIsAuthenticatedDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | boolean | False | Condition is true | |
| is_not | boolean | False | Condition is false | |
| if | Const[request.is_authenticated] | False | Use this to select whether or not whether the request is authenticated. |
RequestObjectDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| type | ObjectTypeMatcher | False | Object scalar type to match | ObjectTypeMatcher |
| name | StringMatcher | False | Object scalar name to match | StringMatcher |
| value | StringMatcher | False | Object scalar value to match | StringMatcher |
| if | Const[request.object] | False | Use this to select and compare the detected object scalars (including custom scalars) in the request, with their kind, name and value. |
RequestObjectMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| key | Const[request.object] | False | The detected object scalars (including custom scalars) in the request, with their kind, name and value. | |
| select | ObjectMatcher | True | ObjectMatcher | |
| mutate | ObjectMutate | True | ObjectMutate |
RequestUserDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch | |
| if | Const[request.user] | False | Use this to string compare the configured user for the request. |
RequestUserMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
| key | Const[request.user] | False | You can use this mutator to change the user of the request before resending it. | |
| drop_user | boolean | False | Remove the user authentication from the request. |
ResponseBodyJSONDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | Dict[string, None] | False | Condition is this exact JSON | |
| is_not | Dict[string, None] | False | Condition is not this exact JSON | |
| in | Dict[string, None] | False | Condition is in this list of JSON | |
| jq | string | False | JQ query to match and use as boolean | |
| if | Const[response.body.json] | False | Use this to select and compare the response body when detected as JSON, using jq-like syntax. |
ResponseBodyTextDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch | |
| if | Const[response.body.text] | False | Use this to select and compare the response body as text, using string compare. |
ResponseDurationDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | integer | False | Condition is this exact integer | |
| is_not | integer | False | Condition is not this exact integer | |
| in | integer | False | Condition is in this list of integers (exact match) | |
| gt | integer | False | Condition is greater than this integer | |
| lt | integer | False | Condition is less than this integer | |
| if | Const[response.duration_ms] | False | Use this to compare the duration of the request in milliseconds. |
ResponseHeadersDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| key | StringMatcher | False | Key to match | StringMatcher |
| value | StringMatcher | False | Value to match | StringMatcher |
| if | Const[response.headers] | False | Use that to select and compare the response headers in a key value dictionary. |
ResponseIsSuccessfulDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | boolean | False | Condition is true | |
| is_not | boolean | False | Condition is false | |
| if | Const[helpers.response.is_successful] | False | Use this to check whether the response is successful. |
ResponseObjectDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| type | ObjectTypeMatcher | False | Object scalar type to match | ObjectTypeMatcher |
| name | StringMatcher | False | Object scalar name to match | StringMatcher |
| value | StringMatcher | False | Object scalar value to match | StringMatcher |
| if | Const[response.object] | False | Use this to select and compare the detected object scalars (including custom scalars) in the response, with their kind, name and value. |
ResponseStatusCodeDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | integer | False | Condition is this exact integer | |
| is_not | integer | False | Condition is not this exact integer | |
| in | integer | False | Condition is in this list of integers (exact match) | |
| gt | integer | False | Condition is greater than this integer | |
| lt | integer | False | Condition is less than this integer | |
| if | Const[response.status_code] | False | Use this to compare the HTTP status code as an integer. |
ScanTypeDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | SCAN_TYPE | False | The scan type is exactly this | SCAN_TYPE |
| is_not | SCAN_TYPE | False | The scan type is not this type | SCAN_TYPE |
| in | SCAN_TYPE | False | The scan type is in this list | SCAN_TYPE |
| if | Const[scan.type] | False | Use this to select against the type of the scan. |
SchemaNeedAuthenticationDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | boolean | False | Condition is true | |
| is_not | boolean | False | Condition is false | |
| if | Const[schema.need_authentication] | False | Use this to select whether or not the schema requires authentication. |
SchemaPathRefDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch | |
| if | Const[schema.path_ref] | False | Use this to string compare the operation name in GraphQL or the path in REST. |
SchemaPathRefMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
| key | Const[schema.path_ref] | False | You can use this mutator to change the operation name in GraphQL or the path in REST (keeping the domain) before resending it. |
SchemaUrlDetector
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch | |
| if | Const[schema.url] | False | Use this to string compare the URL of the request. |
SchemaUrlMutator
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| value | string | False | The value to set. | |
| values | string | False | The values to set, generates multiple queries. | |
| regex_replace | RegexReplace | False | Regex replace pattern. | RegexReplace |
| key | Const[schema.url] | False | You can use this mutator to change the URL of the request before resending it. |
StringMatcher
| Property | Type | Required | Description | Reference |
|---|---|---|---|---|
| is | string | False | Condition is this exact string | |
| is_not | string | False | Condition is not this exact string | |
| in | string | False | Condition is in this list (exact match) | |
| contains | string | False | Contains this string | |
| regex | string | False | Condition is matched on this regex with fullmatch |
Enums
CATEGORY
ACCESS_CONTROLCONFIGURATIONINFORMATION_DISCLOSUREINJECTIONPROTOCOLREQUEST_FORGERYRESOURCE_LIMITATIONSCHEMACUSTOM
CRUD
CREATEREADUPDATEDELETE
HTTP_METHOD
GETPOSTPUTDELETEHEADPATCHOPTIONSTRACECONNECT
OBJECT_TYPE
abbysaleabstractabuseipdbaccuweatheradafruit_api_keyadobe_client_idadobe_client_secretadzuna_privateadzuna_publicaeroworkflow_clientaeroworkflow_privateage_secret_keyagoraairbrakeproject_private_keyairbrakeproject_pub_keyairbrakeuserkeyairship_privateairtable_api_keyairvisualalconostalegraaletheiaapialgolia_api_keyalgoliaadminkeyalibaba_access_key_idalibaba_secret_keyalienvaultallsportsamadeusambeeamountamplitudeapikeyanypointapactaapi2cartapideck_secretapideck_userapiflashapifonicaapifyapimaticapiscienceapolloappcuesappfollowapplicationappsynergyapptivoarea_codeartifactory_secretartsyasana_client_idasana_client_secretasanaoauthasanapersonalaccesstokenassemblyaiatlassian_api_tokenauddauth0managementapitokenauthenticationauthorauthorization_codeauthress_service_client_access_keyautodeskautokloseautopilotavazapersonalaccesstokenaviationstackaws_access_tokenaws_mws_idaws_secret_keyaxonautaylienayrsharebankbank_accountbank_cardbannerbearbaremetricsbase64baseapiiobcryptbeamer_api_tokenbearerbearer_uuidbeebolebesttimebillomatbitbarbitbucket_client_idbitbucket_client_secretbitcoinbitcoinaveragebitfinexbitlyaccesstokenbitmexbittrex_access_keybittrex_secret_keyblazemeterblitappbloggerbody_typebombbombbooleanboolean_wannabeboostnoteborgbasebrandfetchbrowshotbuddynsbugherdbugsnagbuildingbuildkitebulbulbusiness_typebuttercmscafloucalendarificcalendlyapikeycalorieninjacampayncannyiocapsulecrmcaptaindatacarboninterfacecard_typecarriercashboardcaspiocategorycensyscentralstationcrmcexiochatfulecheciochecklyhqcheckvistcicerocirclecicityclearbitclickhelpcliengoclinchpadclockifyclockworksmsclojars_api_tokenclosecrmcloudelementscloudflareapitokencloudflarecakeycloudflareglobalapikeycloudimagecloudmersivecloudplancloverlyclozeclustdoccodacycodecov_access_tokencoinapicoinbase_access_tokencoinlayercoinlibcolumncommandcommercejscommit_hashcommoditiescompanyhubconfirmation_codeconfluent_access_tokenconfluent_secret_keycontent_typecontentful_delivery_api_tokencontentfulpersonalaccesstokenconvertkitconviercountrycountry_codecountrylayercountycoupon_codecouriercoverallscredit_card_numbercrowdincryptocomparecuidcurrency_codecurrencycloudcurrencyfreakscurrencylayercurrencyscoopcurrentsapicustomergurucustomeriocvvd7networkdailycodandeliondashdatabricks_api_tokendatadog_access_tokendatadogtokendatafiredatagovdatedatetimedebouncedeepaideepgramdefined_networking_api_tokendelighteddelivery_methoddepartment_namedetectlanguagedevice_namedevice_typedfusediddiffbotdigitalocean_access_tokendigitalocean_patdigitalocean_refresh_tokendigitaloceantokendirectorydiscountdittodnscheckdocument_typedocumodomaindoppler_api_tokendotmailerdovicodriving_licensedronahqdroneci_access_tokendropbox_api_tokendropbox_long_lived_api_tokendropbox_short_lived_api_tokenduffel_api_tokendurationdwolladynalistdynatrace_api_tokendyspatche_commerce_indicatoreagleeyenetworkseasyinsighteasypost_api_tokeneasypost_test_api_tokenedamamedenaieightxeightelasticemailemailenablexenigmaenvironmentethereumethploreretsy_access_tokenetsyapikeyevent_typeeverhourexchangerateapiexchangeratesapifacebookfacebookoauthfaceplusplusfakejsonfastforexfastly_api_tokenfastlypersonaltokenfeefeedierfetchrssfigmapersonalaccesstokenfilefileiofinagefinancialmodelingprepfindlfinicity_api_tokenfinicity_client_secretfinnhub_access_tokenfixerioflatiofleetbaseflickr_access_tokenflightapiflightstatsfloatflowfluflutterwave_encryption_keyflutterwave_public_keyflutterwave_secret_keyfmfwformformbucketformiofoursquareframeio_api_tokenfrench_phonefreshbooks_access_tokenfreshdeskfrontfulcrumfullstoryfuncfusebillfxmarketgcp_api_keygeckoboardgendergeneric_api_keygengogeoapifygeocodegeocodifygeocodiogeoipifigetemailgetemailsgetgeoapigetgistgetsandboxgithub_app_tokengithub_fine_grained_patgithub_oauthgithub_patgithub_refresh_tokengithubappgitlab_patgitlab_pttgitlab_rrtgitlabv2gitter_access_tokenglassnodegocanvasgocardless_api_tokengooddaygoogle_api_public_keygrafana_api_keygrafana_cloud_api_tokengrafana_service_account_tokengraphcmsgraphhoppergroovehqguardianapigurugyazohappihappyscribeharvesthashhashicorp_tf_api_tokenhashicorp_tf_passwordhellosignhelpcrunchhelpscouthereapiheroku_api_keyhex_color_codehexadecimalhivehiveageholidayapihosthouse_numberhslhslahtml2pdfhtml_bodyhttp_methodhubspot_api_keyhubspotapikeyhuggingface_access_tokenhuggingface_organization_api_tokenhumanityhunterhypertrackibmclouduserkeyiconfinderididentity_numberiexcloudimagekitimaggaimpalainfracost_api_tokeninjectioninsightlyinstagram_oauthintegerinteger32integer64integromatintercom_api_keyintrinioinvoiceoceanipapiipc_patentipgeolocationipifyipinfodbipqualityipstack_tokenipv4ipv6isbnitemjdbcjfrog_api_keyjfrog_identity_tokenjiratokenjoinjotformjsonjumpcloudjurojwtjwt_base64kanbankarmacrmkeeniokey_kmskickboxklipfoliokontentkraken_access_tokenkucoin_access_tokenkucoin_secret_keykylaslanguage_iso_639_1language_iso_639_2languagelayerlastfmlatitudelaunchdarkly_access_tokenleadfeederlegal_namelendflowlessannoyingcrmlexigramlimitlinear_api_keylinear_client_secretlinearapilinemessaginglinenotifylinkedin_client_idlinkedin_client_secretliveagentlivestormllm_inputlob_api_keylob_pub_api_keylocalelocationlocationiqloginradiuslokalisetokenlonglongitudeloyverselunom3omacmacaddressmadkudumagneticmailboxlayermailchimp_api_keymailerlitemailgun_private_api_tokenmailgun_pub_keymailgun_signing_keymailjetbasicauthmailjetsmsmailmodomailsacmandrillmanifestmapbox_api_tokenmapquestmarketstackmaskmattermost_access_tokenmattermostpersonaltokenmavenlinkmaxmindlicensemd5meaningcloudmediastackmeistertaskmerchantmesibomessagebird_api_tokenmessagebird_client_idmetaapimetrilomicrosoft_teams_webhookmicrosoftteamswebhookmidisemime_typemindmeistermitemixmaxmixpanelmoderationmondaymoneromongo_db_object_idmonthmoonclerckmoonclerkmoosendmrticktockmyfreshworksmyintervalsnasdaqdatalinknavigationnethuntnetlify_access_tokenneutrinoapinew_relic_browser_api_tokennew_relic_user_api_idnew_relic_user_api_keynewrelicpersonalapikeynewsapinewscatchernexmoapikeynftportnicereplynimblenitronoticeablenotionnozbeteamsnpm_access_tokennumverifynutritionixnylasnytimes_access_tokenoandaoffsetokta_access_tokenomnisendonedeskoneloginonepagecrmonwateriooopspamopenai_api_keyopencagedataopengraphropenuvopenweatheroptimizelyorganizationowlbotpagerdutyapikeypandadocpandascoreparalleldotspartnerstackpassbasepassportpasswordpastebinpaymoapppaymongopaypaloauthpaystackpdflayerpdfshiftpeopledatalabspepipostpermissionphonepin_codepipedreampipedrivepivotaltrackerpixabayplaid_api_tokenplaid_client_idplaid_secret_keyplaidkeyplanplanetscale_api_tokenplanetscale_oauth_tokenplanetscale_passwordplanviewleankitplanyoplivopolicypoloniexpolygonportpositionpositionstackpostageappposthogpostman_api_tokenpostmarkpowrbotprefect_api_tokenpriceprivate_keyprivatekeyprospectcrmprospectioprotocolprotocolsioproxycrawlpubnubpublishkeypulumi_api_tokenpurestakepushbulletapikeypusherchannelkeypypi_upload_tokenqualarooqubolequickmetricsrapidapi_access_tokenravenrawgrazorpayreadme_api_tokenreallysimplesystemsreason_coderebrandlyreferencerefinerregionrepairshoprrestpackrestpackhtmltopdfapirestpackscreenshotapireturn_typerevrevampcrmrgbrgbaringcentralritekitroaringrocketreachroleroninapproomroute4merowndrubygems_api_tokenrunrunitsalesblinksalescookiesalesflaresatismeterprojectkeysatismeterwritekeysaucelabsscalewaykeyscalingo_api_tokenscrapeowlscraperapiscraperboxscrapersitescrapestackscrapflyscrapingantscrapingbeescreenshotapiscreenshotlayersearchsecretsecuritytrailssegmentapikeyselectpdfsemaphoresendbird_access_idsendbird_access_tokensendbirdorganizationapisendgrid_api_tokensendinblue_api_tokensendinbluev2sentimentsentry_access_tokensentrytokenserial_numberserphouseserpstacksha1sha256sheetysherpadeskshipdayshipping_methodshippo_api_tokenshodankeyshopify_access_tokenshopify_custom_access_tokenshopify_private_app_access_tokenshopify_shared_secretshortcutshotstackshutterstockshutterstockoauthsidekiq_secretsidekiq_sensitive_urlsignalwiresignaturitsignupgeniussigoptsimplesatsimplynotedsimvolysinchmessagesirvsiteleafskrappioskybiometryslack_app_tokenslack_bot_tokenslack_config_access_tokenslack_config_refresh_tokenslack_legacy_bot_tokenslack_legacy_tokenslack_legacy_workspace_tokenslack_user_tokenslack_webhook_urlslackwebhookslugsmartsheetssmartystreetssmoochsnipcartsnyk_api_tokensnykkeysocial_security_numbersoftware_componentsparkpostsplunkobservabilitytokenspoonacularsportsmonkspotifykeysquare_access_tokensquareappsquarespace_access_tokensquareupssh_urlsslmatestatusstatus_codestatus_messagestitchdatastockdatastorecovestormglassstoryblokstorychiefstravastreakstreet_addressstringstripe_access_tokenstripe_public_access_tokenstytchsugestersumologic_access_idsumologic_access_tokensumologickeysupernotesapisurveyanyplacesurveybotsurveysparrowsurvicateswellswiftypetallyfytatumiotaxjarteamgateteamworkcrmteamworkdeskteamworkspacestechnicalanalysisapitelegram_bot_api_tokentelegrambottokentelnyxterraformcloudpersonaltokentext2datatextmagictheoddsapithinkificthousandeyesticketmastertiingotimetimestamptimezoneapititletmetrictodoisttoggltracktomorrowiotomtomtradiertravelpayoutstravisci_access_tokentrelloapikeytrutwelvedatatwilio_api_keytwitch_api_tokentwitter_access_secrettwitter_access_tokentwitter_api_keytwitter_api_secrettwitter_bearer_tokentyntectypeform_api_tokenubidotsunifyidunpluggunsanitized_payloadunsplashupcdatabaseupleaduploadcareupwaveuriurlurlscanus_bank_account_numberus_bank_routing_numberus_zip_codeuser_agentusernameuserstackuuidvatlayervault_batch_tokenvault_service_tokenvehicle_typevercelverifierverimailversionversioneyeviewviewneovirustotalvisualcrossingvoicegainvoucheryvpnapivultrapikeyvytewalkscoreweatherbitweatherstackwebexwebflowwebscraperwebscrapingwebsitewepaywhoxyworksnapsworkstackworldcoinindexworldweatherwrikeyandex_access_tokenyandex_api_keyyandex_aws_access_tokenyearyouneedabudgetyousignyoutubeapikeyzapierwebhookzendesk_secret_keyzendeskapizenkitapizenscrapezenserpzeplinzerobouncezip_codezipapizipbookszipcodeapizonkafeedback
SCAN_TYPE
GRAPHQLREST
SEVERITY
HIGHMEDIUMLOWINFO