Start from the program.
Browse your HackerOne and Bugcrowd programs and import their scope into a project in one step.
Recon turns up a host. Traffic reveals a parameter. A hunch becomes a test. Vigihunt keeps every step connected, and every AI answer points back to the evidence it came from.
Assets
Which endpoints on staging accept a URL?
/api/fetch takes a url parameter and returns the fetched body. It appears in 12 captured requests.
Proposed run
template scan · staging.northstar.example
A full recon pipeline built in, with scope and traffic pulled in from where you already work.
THE WORKFLOW
The useful part is the connection: what changed, what you observed, what you still need to verify. Vigihunt gives that work a place to live, from first signal to finding.
Run subdomain discovery, DNS resolution, HTTP probing, port scans, crawling and template scans from one launcher. When a host appears, it lands next to the target you’re already working.
Capture requests with the browser extension or import a Burp export. Ask questions in plain language; answers link back to the exact requests.
Where does this app fetch user-supplied URLs?
Only /api/fetch. The url value is requested server-side and the body is returned.
Draft a plan for an endpoint, grounded in your methodology library. Work it at your own pace while coverage tracks across every plan.
Promote a test item to a finding. The requests, recon and notes that led you there come with it.
The url parameter is fetched from inside the network and the response body is returned to the caller.
EVIDENCE
GROUNDED ANSWERS
Questions are answered from three places at once: what you captured, what recon found, and the methodology you trust. Each claim carries a citation you can open before you act on it.
GET /api/fetch?url=…POST /api/sessionstaging.northstar.examplenginx 1.25 · 443/tcpWSTG-INPV-19 · SSRFplaybook / url-fetchers.mdANSWER · 3 LAYERS · 4 SOURCES
Is /api/fetch worth testing for SSRF?
Yes. It forwards the url value server-side req 812 on a host that first appeared this week run 024. Start with scheme and internal-range checks WSTG-INPV-19 your playbook.
HUMAN IN THE LOOP
Vigihunt drafts plans and proposes runs. It doesn’t take the keyboard: nothing runs against a target until you confirm it.
Inspect the source. Every answer links to the requests, recon and methodology behind it.
Choose the next action. Plans and runs are proposals. You confirm, edit or dismiss them.
Keep the proof. Notes and evidence travel with the lead, all the way to the finding.
THE REST OF THE KIT
Programs, captured traffic, methodology, coverage and keys sit beside the investigation, not in five other tabs.
Browse your HackerOne and Bugcrowd programs and import their scope into a project in one step.
The browser extension streams requests into your project. Already in Burp? Import the export.
Upload playbooks, checklists and notes. Plans and answers draw on them, with citations.
Coverage rolls up across every test plan, so gaps stand out before the engagement ends.
Platform tokens and recon source keys live once per workspace, not once per project.
READY WHEN YOU ARE
Give your next investigation a home for the details that matter.