Security Testing
Passive findings, secret and PII detection, JWT analysis, auth testing, and investigations.
Security-focused analysis: passive vulnerability findings, secret and PII detection, JWT tooling, authorization testing, and structured endpoint investigations.
Passive Security Findings
Automatic checks: HSTS/CSP, cookie flags, CORS, plaintext credentials, version disclosure.
Secret & PII Detection
Known-prefix and entropy secret scanning, PII and card detection with Luhn.
JWT & Authorization Testing
JWT analysis, alg=none and RS-to-HS tokens, HMAC dictionary, credential A/B replay.
Endpoint Investigations
SQLite-backed investigation records with review status, tags, notes, and evidence.