Skip to content

Hosts ​

Hosts are the targets in a project. The Hosts section lists everything you've added and is where you import new targets and open a host to see its details and results.

Open a project, then choose Hosts in the sidebar.

The Hosts list ​

Each row shows:

  • Host — the target's label (e.g. example.com:8443) and its full URL (https://example.com:8443).
  • Tools — which tools are configured for the target (nikto, lfic, bustah, …), or none, plus any live activity badge
  • Added — when the host was created.

Use the Filter hosts… box to narrow the list by label, the refresh button to reload, and click any row to open the host's detail view.

The header has List view and Tile view icon buttons. The choice is stored per project. List view is the table. Tile view is a screenshot grid sorted by host, then port.

Tile view ​

Each tile shows the target URL, a seed-page screenshot from the latest Headless Browser crawl, the same tools and activity badges as the table, a selection checkbox, and delete.

  • Click the screenshot (or the empty frame) to open host detail.
  • A host that has never been crawled shows an empty frame labeled No screenshot. The host Overview tab still hides the screenshot card entirely when none exists.
  • Tools, activity, bulk Scan / Delete, and New Scan/Import work the same as in the table.
  • Select all N above the grid selects every host in the current filter (the same set as the list header checkbox). With a filter active the label is Select all N shown. When everything visible is selected it becomes Clear selection. A partial selection shows the indeterminate dash.

Live activity badges ​

When a host has live scans, a small indicator appears on the Tools column (list) or the tile footer:

  • Spinner — at least one scan is actively issuing requests (tooltip names the tools)
  • Pause icon — scans are alive but paused
  • Clock icon — scans are queued behind the host-concurrency cap
  • A count appears when more than one scan is in that state

Click the badge to open Active Jobs, where you can pause or resume. Clicking it does not open host detail.

Import hosts and scan ​

Click New Scan/Import to open the New Scan wizard in bulk mode.

  1. Existing hosts — click a host already in the project to add its URL to the box (skipped when the project has none). Then Target URLs — one per line or comma-separated. Bare hostnames work too; http:// is assumed when no scheme is given. Use Load File… for text or CSV lists. Examples:

    https://example.com
    https://target.com:8443
    http://192.168.1.1
    2001:db8::1
    http://[2001:db8::1]:8080/

    The wizard shows a live count of detected URLs. See IPv6 targets for the two accepted IPv6 forms.

  2. Then choose one of:

    • Add Hosts — adds targets without scanning. Summary shows added, duplicates skipped, and failures. Click Done to close.
    • Next — continues to the Nikto, Crawl, and Bustah tool tabs, then Start Scan. Creation runs in the background while the wizard stays open. A host that does not resolve is refused at create time with a message that names it. See Scans → New Scan wizard.

Bulk scan from the list

Select hosts with checkboxes and click Scan in the bulk toolbar. The wizard opens with those hosts' URLs pre-filled.

IPv6 targets ​

The platform accepts IPv6 hosts in two equivalent forms:

FormExampleNotes
Bare literal2001:db8::1 or ::1No brackets. The wizard normalizes to a URL with bracketed host (http://[2001:db8::1]/). You can also prefix with a scheme/port: https://2001:db8::1:8443.
Bracketed URLhttp://[2001:db8::1]:8080/Standard URL syntax — address in [ ], optional port after the closing bracket.

Not supported: zoned or link-local literals with an interface suffix, such as fe80::1%eth0 (including the percent-encoded %25 form in URLs).

The LFIC setup probe accepts the same two forms. A bare IPv6 host is not refused as a mismatch against the bracketed URL the probe builds.

Force IPv6 on scans ​

When a target is reachable only over IPv6 (or you want to prove v6 exposure), enable Force IPv6 on the tool tab before launch (Nikto, Crawl, LFIC, or Bustah):

  • The scan is pinned to the target's AAAA record at creation time.
  • Creation fails if there is no AAAA record, or if this deployment has no IPv6 egress (the checkbox is disabled in that case).
  • There is no silent fallback to IPv4. Force IPv6 is a hard requirement, not a preference.

Whether IPv6 egress exists is detected when the API starts; many Docker and cloud environments have IPv4 only even when containers are configured for v6.

After an HTTPS Nikto scan, host Intel Gathered may also show Protocols — the HTTP versions the target was observed to speak (for example HTTP/1.1, HTTP/3). See HTTP/3 scanning.

Delete hosts ​

  • One host — click the trash icon on its row.
  • Several — select rows with the checkboxes and click Delete in the bulk toolbar.

Deleting a host permanently removes all of its scans and findings. If the host has entries in the project Report, the confirmation dialog lets you optionally also delete this host's report item(s). Confirm to proceed.

Host detail ​

Click a host to open its detail view. Tabs across the top:

TabPurpose
overviewHost facts, intel, findings summary, screenshot, notes
NiktoNikto scan list and New Scan (Nikto tool only)
CrawlCrawl scan list, detected technologies, New Scan (Crawl tool only)
LFICLFI Commander — see LFIC
BustahContent-discovery scans, bust jobs, results tree — see Bustah
SitemapUnified path tree from crawl, Nikto, and Bustah — see Sitemap tab
FindingsAll findings for this host
RecommendationsFollow-ups from Nikto and Crawl (including Export full file list for cloud storage listings); tab badge shows open count. Project-wide list is under sidebar Recommendations. See Recommendations.
Target ConfigHost identity only (Host, Port, SSL) — see Target Config tab
Scan DefaultsPer-host defaults for new scans — see Scan Defaults tab

Use the Hosts breadcrumb at the top to return to the list. Browser Back returns to the previous screen, which may not be the host list. When the target has a configured URL, the host label in the breadcrumb is a link that opens the site in a new tab (noopener noreferrer).

Overview tab ​

Cards sit in two columns. Notes is full width below them.

Left column

  • Host info table — Link (opens target in a new tab), Label, Host, Port, SSL, Tools configured, Added
  • Intel Gathered — scan-discovered profile facts (OS version, webroot, user counts, server banner, log paths, page title, Protocols from Nikto HTTPS scans, …)
  • Other — additional host-info keys outside the designed intel set, including Tls Cert Sha256, the fingerprint of the certificate last seen on this host (see Findings → TLS certificate findings)

Host intel is stored on the host and survives deleting the scan that discovered it (findings and other scan-scoped data still cascade away).

Right column

  • Findings Summary — severity counts; click a severity to jump to the Findings tab filtered to that level
  • Screenshot — seed-page capture from the latest crawl (only if one exists). Click the image to enlarge; the enlarged view names the page it was captured from. Hosts Tile view shows the same shot, or an empty No screenshot frame. See Web Crawler → Screenshot.

Notes sits below both columns, full width — freeform text that auto-saves as you type (Saving… / Saved / Unsaved). Placeholder: Add notes about this host…

Target Config tab ​

Edit how the platform reaches this host — the host's identity:

  • Host — hostname or IP
  • Port — blank uses the scheme default (80 or 443)
  • SSL (https) — use HTTPS for URL construction and scans

The card explains that Scan Defaults live on the next tab and the LFIC request template lives on the host LFIC tab (setup wizard or Edit Config). Saving here leaves both untouched.

Use Save Config when dirty, or Cancel to discard local edits. Like Scan Defaults, switching tabs or navigating away with unsaved edits prompts to save or discard. Status shows Unsaved / Saving… / Saved.

Scan Defaults tab ​

Per-host overrides for options shared across Nikto, Crawl, and LFIC. Same fields as Project Settings → Scan Defaults, with tri-state booleans (Use tool default / On / Off).

Precedence when launching a scan:

values on the scan form  >  host Scan Defaults  >  project Scan Defaults

Tri-state booleans use Use tool default (…) / On / Off — where the parenthetical summarizes each tool's built-in default (for example Secret Detection on for every tool).

Click Save Defaults when dirty, or Revert to discard local edits. Like Target Config, leaving the tab with unsaved edits prompts to save or discard.

Sitemap tab ​

A host-wide path tree built from every tool that discovers URLs — crawl, nikto, and bustah. Paths from deleted scans remain until you purge them.

  • Tree — folders expand/collapse; each row shows the path, discovering tool (color-coded), last HTTP status, and a link to open the URL on the target (new tab). On a redirect (3xx), the row also shows → and the Location the target sent (plain text, not a clickable link). Bustah is the usual source — it records the hop; a crawl that followed through to a 200 does not leave a redirect arrow on the original path.
  • Filter — text search, Hide resources (images/styles/fonts — on by default so app paths stay visible), and status chips.
  • Expand all / Collapse all
  • Purge sitemap — delete every stored path for this host (cannot be undone; re-scanning rediscovers only what that scan finds).

The tab polls every few seconds while sweeps or crawls run. Large hosts show showing N of M paths when the render cap is reached.

The host Crawl tab still lists Detected Technologies; the sitemap lives here on its own tab.

Next steps ​

Proprietary software. Licensed for use under the End User License Agreement.