checking...
–
Nuclei Version
–
Your Scans (DB)
–
Your Findings (DB)
–
Report Files
πŸ“‹ Recent Reports
FileSizeModified
Loading...
πŸ—„ Recent Scans (MongoDB)
Scan IDDomainLabelTypeAuthStatusFindingsDate
Set user_id in topbar and click β†Ί Ping
🏒 Create Organization

Spins up a tenant with its own login URL and seeds its first Org Admin. The organization is registered against a domain it owns β€” only email addresses on a registered domain can become users. A temporary password is shown here to hand over (or emailed, once SMTP is configured).

🏒 Organizations
NameSlug / Login URLDomain(s)TypeUsersScansLicencesStatusActions
Loading…
πŸ—ƒοΈ All Scan Data

Every user_id holding scans or findings, across all organizations. As Super Admin you can open any of them β€” click View to load that user's findings. Rows marked orphaned have data but no account behind them (usually a pre-auth or deleted identity); their history is still readable and can be transferred to a real account below.

user_idAccountOrgScansFindingsLast scan
Loading…
πŸ“¦ Transfer Scan Data

Scans and findings are owned by the org-namespaced user_id ({slug}__{username}). When someone moves to a different organization, re-home their history here β€” otherwise it stays behind on the old id. Check first, then apply: the check never writes.

🌐 Domain Registry

Every domain registered on the platform and who holds it. One domain belongs to exactly one organization β€” this is what a clash is checked against.

DomainOrganizationRoleClaimed byClaimed
Loading…
πŸ”‘ Platform API Keys

Long-lived keys for API / integration access (e.g. hand to the UI team while there's no login screen). These carry Super Admin scope β€” they bypass org isolation and read all data, so treat each like a password. Shown once at creation; callers send header X-API-Key: cpt_….

PrefixLabelCreatedLast used
No platform keys yet.
πŸ“œ Audit β€” select an organization
WhenActorActionTarget
Click β€œAudit” on an organization above.
πŸ‘‘ Platform Owners (Super Admins)

The .env seed only runs when the database has zero super admins β€” it can't add a second one or rename the first. Use this instead: create your own named owner, sign in as them, then retire the seeded root account. Leave the password blank to get a temporary one that must be changed on first sign-in.

UsernameEmailStatusSessionsScansLast login
Loading…
πŸ”’ Change My Password

Rotate the Super Admin password you were seeded with. Once changed, remove SUPER_ADMIN_PASSWORD from .env β€” it's only read to create the first admin, and leaving it there keeps your password in plaintext on disk. All your other sessions are signed out.

πŸ‘₯ Your organization

Add operators to your console. Their email must be on one of your registered domains (β€”). A random temporary password is generated and shown here to hand over; they must reset it on first sign-in.

🌐 Domains

Email domains your users may sign up on.

DomainRoleUsersRegistered
Loading…
YOUR DOMAIN REQUESTS
DomainRequestedStatusNote
No requests.
πŸ” Roles & Access

Custom roles limit what a member can reach. Tick the pages, then the level on each: View = read only, Write = create, Edit = change (finding status, etc.), Delete = remove. Write/Edit/Delete always include View. Admins and members with no role stay unrestricted. Changes apply on the member's next request β€” no re-login.

Loading pages…
RoleAccessMembersUpdated
Loading…
πŸ‘€ Users
UsernameEmailRoleAccess roleStatusInviteSessionsScansFindingsLast loginActions
Loading…
πŸ“‚ Step 1 β€” Upload Doc & Generate Templates
βš™ Auto-Login Preflight (optional β€” login first, auto-extract a fresh token instead of pasting one above)
πŸš€ Step 2 β€” Start Scan
πŸ“‘ Live Stream
0%
Waiting for scan to start...
🎯 Single Endpoint Scan
πŸ”‘ Bearer Token β€” baked into every attack template automatically; auth-missing check deliberately omits it
βš™ Auto-Login Preflight (optional β€” login first, auto-extract token)
or parse first to review fields
πŸ–₯️ Nuclei Live Terminal
0%
Waiting for scan to start…
πŸ“¦ Batch / Multi-Curl Scan
πŸ”‘ Bearer Token (paste directly)
Leave blank if your curls already have -H 'Authorization: Bearer ...', or use Auto-Login below instead.
βš™ Auto-Login Preflight (optional β€” login first, auto-extract token)
Even endpoints with no parameters β€” adds synthetic q param so SQLi/XSS/etc templates always get generated
⚑ Rate Limit Test β€” API4:2023
🌐 Browser Discovery β€” SPA/JS-aware crawl (Playwright)

Real browser session β€” SPA route traversal, JS bundle/source-map parsing, WebSocket capture, GraphQL detection, full JWT/cookie/localStorage token harvesting. Complements the wordlist-based discovery elsewhere; async job, same shape as a scan.

πŸ“Š All Reports
FileSizeModifiedActions
Loading...
πŸƒ Findings Dashboard
πŸ“€ Manual Findings Upload
Upload findings your team found by manual testing. They are stored exactly like scanner findings, so they get the same report, the same status buttons and the same SLA. Re-uploading is safe β€” matching rows are updated, never duplicated.
Give a scan_id to add these findings into an existing assessment β€” the type is then detected from that scan and the dropdown above is ignored.
Always dry run a new file first β€” it validates every row and shows the references it would assign, without writing anything.

      
πŸ•ΈοΈ Web Scan
Full-site web scan. It runs on the cloud pipeline and saves into your account (web_scans), owned by you and scoped to your org β€” a web scan, alongside your api scans. ⚠️ Launching starts a real cloud scan.
πŸ“‹ My Web Scans
TargetStatusFindingsScoreDate
Loading…
πŸ“‹ Scan Request Logs
Scan ID User Domain Label Techniques Requests Sent Findings Status Report Date
Enter user_id and click Load
πŸ”Œ Installed Plugins
IDNameCategoryTypeTemplatesCWEOWASP
Loading...
⚑ Curl Examples β€” Scan by OWASP Category
user_id from topbar is used automatically
SQLi β€” Known Vulnerable Endpoints Targets query-param endpoints Β· SQLi 6 sub-techniques
Step 1 β€” Test endpoints manually (paste in terminal):

          
Start Scan via Combined_PT

          
πŸ“… Scheduled Scans
One-time and recurring scans persisted server-side β€” they'll still fire even if this browser tab is closed, and survive a server restart. Created from the "πŸ“… Schedule" button on Doc Scanner, Single Endpoint, or Batch pages.
Loading…