Hunt with full context.

Recon turns up a host. Traffic reveals a parameter. A hunch becomes a test. Vigihunt keeps every step connected, and every AI answer points back to the evidence it came from.

northstar / investigationSample data
Recon run 024complete
  1. discover148 subdomains
  2. resolve131 hosts
  3. probe64 live · 1 new

Assets

  • api.northstar.example200
  • cdn.northstar.example200
  • staging.northstar.examplenew
Traffic from your browser
  • GET/200
  • POST/api/session201
  • GET/api/me200
  • GET/api/fetch?url=https://…200
  • GET/static/app.js304
  • GET/api/flags200
Ask grounded in this project

Which endpoints on staging accept a URL?

/api/fetch takes a url parameter and returns the fetched body. It appears in 12 captured requests.

12 requestsrecon run 024WSTG · SSRF

Proposed run

template scan · staging.northstar.example

in scope · 38 validated templates

CancelConfirm Confirmed by you
A sample project: a recon run finds a new host, captured traffic shows a URL parameter, an answer cites the requests behind it, and a proposed scan waits for the researcher to confirm.

A full recon pipeline built in, with scope and traffic pulled in from where you already work.

  • Subdomain discovery
  • DNS resolution
  • HTTP probing
  • Port scanning
  • Crawling
  • URL discovery
  • Template scanning
  • HackerOne
  • Bugcrowd
  • Burp Suite import
  • Chrome extension

THE WORKFLOW

Good work happens
between the tools.

The useful part is the connection: what changed, what you observed, what you still need to verify. Vigihunt gives that work a place to live, from first signal to finding.

  1. 01 / Recon

    Know what changed. Know where to look.

    Run subdomain discovery, DNS resolution, HTTP probing, port scans, crawling and template scans from one launcher. When a host appears, it lands next to the target you’re already working.

    ASSET HISTORYnorthstar.example
    discoverresolveprobeportscrawlscan
    api.northstar.exampleexisting
    staging.northstar.examplenew host
    cdn.northstar.exampleexisting
    auth.northstar.exampleexisting
    RECON RUN 024 · 1 NEW ASSET
  2. 02 / Traffic

    Ask about what you actually saw.

    Capture requests with the browser extension or import a Burp export. Ask questions in plain language; answers link back to the exact requests.

    CAPTURED TRAFFIC1,284 requests
    POST/api/session
    GET/api/fetch?url=https://…
    GET/api/me

    Where does this app fetch user-supplied URLs?

    Only /api/fetch. The url value is requested server-side and the body is returned.

    req #812+11 similar
  3. 03 / Test plan

    Turn a hunch into a deliberate test.

    Draft a plan for an endpoint, grounded in your methodology library. Work it at your own pace while coverage tracks across every plan.

    TEST PLAN · /api/fetchWSTG-INPV-19
    • Review accepted URL schemes
    • Check redirect handling
    • Probe internal address ranges
    • Test DNS rebinding window
    Coverage
    2 / 4
  4. 04 / Finding

    Keep the proof attached.

    Promote a test item to a finding. The requests, recon and notes that led you there come with it.

    FINDING · DRAFTHigh

    Server-side request forgery via /api/fetch

    The url parameter is fetched from inside the network and the response body is returned to the caller.

    EVIDENCE

    req #812GET /api/fetch?url=http://169.254…
    recon run 024staging.northstar.example
    test planProbe internal address ranges

GROUNDED ANSWERS

Every answer
shows its work.

Questions are answered from three places at once: what you captured, what recon found, and the methodology you trust. Each claim carries a citation you can open before you act on it.

  • Your traffic1,284 captured requests
    GET /api/fetch?url=…POST /api/session
  • Your reconrun 024 · 64 live hosts
    staging.northstar.examplenginx 1.25 · 443/tcp
  • Your methodologyWSTG · your playbooks
    WSTG-INPV-19 · SSRFplaybook / url-fetchers.md

ANSWER · 3 LAYERS · 4 SOURCES

Is /api/fetch worth testing for SSRF?

Yes. It forwards the url value server-side req 812 on a host that first appeared this week run 024. Start with scheme and internal-range checks WSTG-INPV-19 your playbook.

trafficreconmethodology

HUMAN IN THE LOOP

The AI suggests.
You decide.

Vigihunt drafts plans and proposes runs. It doesn’t take the keyboard: nothing runs against a target until you confirm it.

  1. 01

    Inspect the source. Every answer links to the requests, recon and methodology behind it.

  2. 02

    Choose the next action. Plans and runs are proposals. You confirm, edit or dismiss them.

  3. 03

    Keep the proof. Notes and evidence travel with the lead, all the way to the finding.

THE REST OF THE KIT

The whole hunt,
in one workspace.

Programs, captured traffic, methodology, coverage and keys sit beside the investigation, not in five other tabs.

PROGRAMS

Start from the program.

Browse your HackerOne and Bugcrowd programs and import their scope into a project in one step.

CAPTURE

Capture as you browse.

The browser extension streams requests into your project. Already in Burp? Import the export.

KNOWLEDGE

Bring your methodology.

Upload playbooks, checklists and notes. Plans and answers draw on them, with citations.

COVERAGE

See what’s still untested.

Coverage rolls up across every test plan, so gaps stand out before the engagement ends.

VAULT

One vault for every key.

Platform tokens and recon source keys live once per workspace, not once per project.

READY WHEN YOU ARE

Pick up the next lead.
Keep the whole story.

Give your next investigation a home for the details that matter.