Appearance
Scans
A scan is a single execution of a tool against a host. It collects findings, host info, and an activity log. Nikto, crawl, LFIC, and Bustah scans all appear in the project Scans section; each tool also has its own tab on the host detail page for launching and reviewing runs.
Open a project, then choose Scans in the sidebar — or start from the Tools menu.
Field-by-field options (shared Options / Throttling & Limits, Nikto modules, MS10-070, JWT) live on Scan options.
Tools menu (host-first)
Between Hosts and Scans, the sidebar has a collapsible Tools group with Nikto, Crawl, LFIC, and Bustah. Click Tools to expand or collapse it; the parent row does not navigate on its own.
Each tool page lands on a Hosts view: one row per host that tool has already run against in this project. Hosts the tool has never touched do not appear. Click a host to open that host's own view for the tool — results are never merged across hosts.
| Tool | Landing page | Launch |
|---|---|---|
| Nikto | Hosts this tool has scanned | New Scan — wizard scoped to Nikto |
| Crawl | Hosts this tool has scanned | New Scan — wizard scoped to Crawl |
| Bustah | Hosts this tool has scanned | New Scan — wizard scoped to Bustah |
| LFIC | Hosts this tool has scanned | New LFIC Scan — stays on the tool page (setup if needed, then launch) |
The header also has a Hosts / Scans toggle. Hosts is the default. Scans is the flat list of that tool's runs (same pause/resume/cancel controls as project Scans). Each page names its scope next to the title — here, every host in this project.
Host rows show Host, Scans, Last run, and Latest status. active means a run is still pending or running. degraded is sticky: a host whose newest run was clean can still show it if an earlier scan on that host was degraded.
The empty state is No host in this project has been scanned with Nikto yet (the tool name changes). Start a first run with New Scan or New LFIC Scan, or from Hosts / project Scans.
Launch opens from those buttons, not on arrival. Clicking the same tool in the sidebar while you are already on that page does nothing — it does not reset the Hosts / Scans toggle or reopen a form.
Nikto, Crawl, and Bustah share one New Scan wizard. LFIC uses New LFIC Scan — same window size and the same Throttling & Limits / Options tabs — because an LFIC target is an injection point, not a URL. See LFIC.
Use this path to see where a tool has already run.
New Scan wizard
Most Nikto, Crawl, and Bustah scans start in the New Scan wizard — a modal opened from several places:
| Where | Button | What happens |
|---|---|---|
| Tools → Nikto, Crawl, or Bustah | New Scan | Hosts/scans page for that tool; wizard scoped to that tool |
| Tools → LFIC | New LFIC Scan | LFIC wizard on the tool page — see New LFIC Scan |
| Hosts | New Scan/Import | Bulk mode: pick existing hosts and/or enter URLs |
| Hosts (bulk toolbar) | Scan | Bulk mode with selected hosts' URLs pre-filled |
| Scans | New Scan | Bulk mode; optionally pre-fill from selected scan rows |
| Host Nikto tab | New Scan | Single-host, Nikto tool tab only |
| Host Crawl tab | New Scan | Single-host, Crawl tool tab only |
| Host Bustah tab | New Scan | Single-host, Bustah tool tab only |
Click outside the wizard (on the dimmed backdrop), press Escape, or click ✕ to close. Confirmation dialogs are excluded — you must answer those explicitly. The wizard has no address of its own; reload or the browser Back button leaves the page under it.
Bulk flow (multiple hosts)
- Existing hosts — click a host to append its URL to the box (label Existing hosts (click to add)). Already-listed hosts show a check and added. A Filter box appears when there are more than six. If the list cannot load, the error names the project; you can still type URLs. The picker is hidden when the project has no hosts yet.
- Target URLs — one per line (comma-separated lists also parse). Clicking an existing host writes into this same box; you can still edit, paste, or Load File… (
.txt,.csv, or.list— the hint reads One URL per line). A live counter shows how many URLs were detected. - Add Hosts — adds targets without scanning (summary of added, duplicates, failures). Done closes the wizard.
- Next — moves to tool configuration.
- Tool tabs — Nikto, Crawl, and Bustah (red dot if enabled but invalid). Nikto and Bustah are on by default in bulk mode; Crawl is on by default with the Headless Browser engine (disable it or switch to Standard if Chromium is down). Enable or disable each tool with the checkbox at the top of its tab.
- Start Scan (N scan(s)) — queues creation. The wizard stays open and shows Creating scans… N of M (and (N failed) if some pairs fail). The footer button reads Creating… N/M. Closing this window does not stop scan creation. Structural refusals (no targets or tools, or more than 500 scans in
hosts × tools) still fail immediately with an error.
Each tool resolves the target host before the scan is created. If DNS fails, that scan is not queued — the wizard shows a short reason that names the host (for example Could not resolve host “example.invalid”). In a mixed batch, only the failed targets are reported; successful scans still start. A target created only for a scan that then fails to create is rolled back (no leftover empty host).
If creation stops before it finishes (API restart, or the 2-hour create budget), the wizard stays open and names how many scans were created and are already running, and how many were never attempted. If the wizard loses contact with the server (five failed status polls), it names the batch id and tells you to check the Scans list before retrying, so you do not launch duplicates.
Followed links and page includes are limited by the target's address tier — see Scan Scope & Address Tiers.
Single-host flow
Host-tab New Scan skips the URL step and opens directly on tool options for that host. The footer still reads Start Scan (N scan(s)) — one host times each enabled tool.
Nikto, Crawl, and Bustah together
In bulk or single-host mode you can enable any combination of Nikto, Crawl, and Bustah on the same launch. Each enabled tool creates a separate scan per target. The button count reflects hosts × tools (for example, 2 hosts with Nikto + Bustah → Start Scan (4 scans)).
Bulk Crawl has no seed field — each target is crawled from its own root URL. Choose Standard, Headless Browser, or both on the Crawl tab — see Web Crawler → Crawl engines. Bustah requires at least one wordlist when enabled. See Web Crawler and Bustah.
Shared wizard tabs: Options and Throttling & Limits
After the tool tabs, the wizard always includes two cross-tool tabs (alongside Nikto, Crawl, and Bustah when enabled):
| Tab | Controls | Applies to |
|---|---|---|
| Options | User-Agent, Virtual Host, Root Path, Additional Headers | Every enabled tool in this launch |
| Throttling & Limits | Concurrency, RPS, Delay, Host timeout, Max concurrent hosts, Proxy | Every enabled tool in this launch |
Each field shows per-tool notes underneath when a knob does not fully apply (for example Bustah ignores Root Path, or crawl Virtual Host only works with the Standard-only engine). Values follow the same three-tier default chain as Scan Defaults when left blank.
Boolean toggles (Follow Redirects, Send Browser Headers, Secret Detection, Force IPv6) stay on each tool's tab — defaults differ by tool. See Scan options.
Setting a Virtual Host on Options while the crawl includes Headless Browser (or both engines) blocks launch — use Standard only for a coherent vhost crawl, or clear the vhost. See Web Crawler → Virtual Host on crawl.
LFIC uses the same Options and Throttling & Limits panels on New LFIC Scan and on the host LFIC tab.
New LFIC Scan
Tools → LFIC → New LFIC Scan opens a modal the same size as New Scan. It does not navigate to the host tab. Steps:
- choose or add a host — pick an existing host, or type a URL and click Add & set up. Configured hosts are listed first and marked LFIC configured; others say needs setup and still appear (they go to setup first). Filter hosts narrows the list.
- set up the injection point — the same five-step setup as Edit Config on the host LFIC tab, when the host has no LFIC template yet. A host that is already configured skips this step. To change an existing template, use the host tab's Edit Config.
- options — tabs LFIC, Throttling & Limits, and Options (same shared panels as the other tools). Proxy and headers used to probe the host during setup are copied in as editable defaults; an existing choice and an enforced proxy are left alone. Select at least one module or fileset.
Start LFIC Scan creates one scan immediately and closes the modal. This is not the bulk Creating scans… path. The wizard Back button returns to the host picker. Select at least one fileset or module. blocks launch until the LFIC tab is valid.
See LFIC.
The project Scans list
The Scans sidebar page lists every scan in the project (nikto, crawl, lfic, and bustah). The title includes the scope every tool, every host in this project.
Each row shows Type, Host, Status, Started, Finished, and Progress (percentage and ETA while running; hover for task count and req/s). ETA and req/s use scanning time — paused idle does not inflate them. A Nikto scan launched with MS10-070 Active Confirm / Exploit carries a red MS10-070 exploit badge, so an active exploit run is identifiable in the list afterwards — see MS10-070. Filter by All types / tool name and by status (pending, running, completed, failed, canceled, timeout). Check Hide completed to drop every completed scan from the list, including degraded runs (those still finished normally). timeout stays visible — it is not completed. Use this when you only want active or failed work in view. Use checkboxes for bulk Pause, Resume, Cancel, and Delete. While a bulk action runs, a banner shows Pausing / Resuming / Canceling / Deleting N of M…. On full success it reports Paused N scans. (same pattern for the other verbs). If any fail, an error names each scan id and the reason. Success and failure never share a banner.
When any visible scan is pausable, the Actions column header becomes Pause All (N) — pauses every running scan in the current view. Resume on this page with each row's Resume or the selected-row Resume button. On Active Jobs, Resume All (N) resumes every paused queue of every paused scan, so a scan whose request backlog has already drained is not left paused with no obvious resume.
Click any row — any tool — to open the scan detail modal. Host view in that modal is the labelled way onto the host's own tab for the tool.
On a host's Nikto, Crawl, LFIC, or Bustah tab, a scan list shows only that tool's runs for the host (scope this host only). Host view for a crawl opens Overview (the host still has a Crawl tab). Columns: Status, Started, Finished, Progress, Actions. Click a row to open the same scan detail modal — except on the host Bustah tab, where the row selects that sweep in the results tree on the same page. See Bustah.
Scan detail modal
Every scan list except the host Bustah tab opens the same modal: project Scans, a tool page's Scans toggle, host Nikto / Crawl / LFIC tabs, and Active Jobs. There is no separate findings-only page.
Closing the modal (✕, backdrop, Escape, or browser Back) returns to the list you opened it from. Copy the address while the modal is open to reopen that scan on the same list.
Host view (header) opens the host's own workspace for that tool — configuration, full results, and its other scans. It is a labelled action, not a silent redirect on row click.
While the scan is running, a progress bar shows completion %, ETA, req/s, request and error counts, and crawl-specific page counts (N/M max · K known). A page with no body (redirect, 204) does not reset the known-page count. A Bustah sweep waiting on its seed source stays at 99% and shows orange waiting on its seed scan (with elapsed minutes once past the first). 100% means the sweep has finished, not that it is parked. See Bustah. Under that, a Speed limit: line shows RPS and concurrent requests the scan is actually allowed right now (and delay, when one is in force — for example 100ms between requests). When that is tighter than this scan's own settings, the line is orange, repeats those settings in parentheses (this scan is set to …), and names why — another scan on the same host holding a tighter limit (RPS capped by <tool> — <target>), held at the bulk fairness floor so foreground scans keep slots, narrowed after 429 responses from the target, or narrowed after requests timing out against a target that is still answering. If both 429s and timeouts are in play, the line says so. If the platform cannot measure the budget, the line starts Speed limit unknown: and names that reason instead of showing unconstrained numbers.
A dimension the host budget never measured (typical of crawl concurrency: the crawl paces itself) still shows this scan's own setting, with a caveat that it is enforced by the tool itself rather than the shared per-host budget. That caveat does not colour the line as throttled.
Tabs:
| Tab | Contents |
|---|---|
| Results | Bustah and LFIC only, and it is the default for those tools. Bustah renders the results tree in place, plus Open the full Bustah view for this host. LFIC states that extraction results live on the host LFIC tab and offers Open the full LFIC view for this host. |
| Findings | Same findings table as project Findings, scoped to this scan — filters, bulk actions, and auto-refresh while the scan is active. Default tab for Nikto and crawl. |
| Activity | Per-scan activity log (event + message), tailable with Load older for earlier pages |
| Tasks | Queued/running/completed HTTP tasks for this scan, newest first, with Load older |
If the scan is degraded, an orange banner under the header shows the full reason. See Degraded scans.
Degraded scans
Some scans finish with status completed but also show an orange degraded badge next to the status. That means the run ended normally but produced less coverage than you asked for — or skipped work you would normally expect.
Status answers “did the scan finish?” Degraded answers “can I trust the result as a full run?” A sweep that skipped 99% of its wordlist probes can still be completed; without degraded, it would look like a clean success.
| Where | What you see |
|---|---|
| Scans list and host scan lists | Orange degraded next to the status — hover for the full reason |
| Scan detail modal | degraded in the header plus an orange banner with the reason in full |
The reason is a single line. For Bustah, if several things went wrong, the badge shows the first note and mentions how many more are in the activity log (category bustah_degraded).
Degraded is not the same as failed, canceled, or timeout. Those statuses mean the scan did not complete its run. Degraded means it completed, but with a documented gap.
Common cases by tool:
| Tool | Examples of why a scan is marked degraded |
|---|---|
| Crawl | The crawl stopped before finishing (worker restart, mid-crawl failure) after fetching some pages, leaving partial page coverage. A crawl that fetched nothing is not degraded — it is retried, and if it still fails it shows as failed with the transport reason (wrong scheme, connection refused, DNS), not as partial coverage |
| Bustah | Soft-404 calibration failed for an extension (probes skipped), recursion/word/job caps hit, rate limiting or blocks when Never stop on errors kept the sweep going, transport failures, sustained 401 responses on an authenticated session (auth lost), every bust job stopping blocked/rate-limited, or a Wait for source sweep that gave up after 15 minutes (directories found later by the source are not swept) |
| Nikto / LFIC / any tool | failed / canceled for hard stops; degraded when sustained HTTP 429 rate limiting exhausted adaptive backoff (coverage likely incomplete — see the Sustained rate-limiting (HTTP 429) finding) |
If a later run completes cleanly, degraded can be cleared (for example, a crawl that previously interrupted and then finishes on retry).
When you see degraded, read the reason before treating findings or the sitemap as exhaustive — then check Logs → Scan Activity for supporting detail, especially on Bustah runs.
Control a running scan
Row actions on the project Scans list, host Nikto / Crawl tab scan lists, and bulk selection:
- Pause — stop processing the scan's queued work. Nikto, LFIC, and Bustah honor this. A Bustah pause mid-word re-sweeps that word (including remaining extensions) on resume, so those probes are not skipped. Paused idle time does not count toward Host timeout. Crawls cannot be paused — a crawl is one long-lived task, so there is no Pause button and the row never shows
(paused). Use Cancel to stop a running crawl immediately. - Resume — continue a paused (non-crawl) scan.
- Cancel — stop an active scan for good.
- Delete — remove the scan and its results (findings, tasks, artifacts). Deleting asks for confirmation. Host-profile intel and crawler screenshots on the host are kept where stored separately from the scan row.
Pause All (N) appears in the Actions column header when at least one pausable scan is in view. It pauses those scans' queues. Running crawls are skipped and a modal explains that they cannot be paused — they keep fetching until you Cancel them. A scan that finished between the list refresh and the click is reported as already stopped, not as still running.
Pause, resume, and cancel only apply while a scan is active (pending or running). Pausing a scan that is still queued keeps it queued — it does not flip to running with nothing to send.
Monitor progress with Active Jobs
For a live view of what the platform is working on, open Active Jobs in the lower (global) part of the sidebar. The title includes (all projects) — this list is not scoped to the sidebar project. Filter chips All, Running, and Paused count from the full set. A filter that hides every row says so (No running queues. / No paused queues.) and offers show all — it does not look like an idle queue.
It groups running work by scan and job type — for example HTTP Requests, Post Processing, and Nikto Prep — with the number of queued jobs, the threads (workers) assigned, and a per-module breakdown. Modules read by their operator names there, for example MS10-070 oracle.
Click anywhere on a queue row (not only the hostname) to open the same scan detail modal. Pause, resume, cancel, and delete on the row do not open detail. Host view in the modal adopts that row's project in the sidebar before opening the host, so the rest of the nav matches the page. If the project name cannot be loaded, the sidebar still switches (the id stands in for the name) rather than ignoring the click. A host with no project leaves the sidebar unchanged.
From Active Jobs you can pause/resume a scan's queue (except crawls), cancel an active scan, or delete a scan. Pause All (N) in the page header pauses every scan that still has an unpaused pausable queue — same bulk pause as on the Scans list, including the crawl skip + modal. Resume All (N) resumes every paused queue of every paused scan (not one queue at a time). Pausing acts on the whole job-type queue for that scan (there is no per-module pause). The view refreshes automatically every few seconds.
Exports appear above the scan queues when a cloud storage listing export is queued or running. Each row shows the recommendation title, target, and progress (Queued… or Walking page N · files · size), with Cancel. Finished downloads stay on the recommendation row, not here. See Recommendations → Export full file list.
Next steps
- Scan options — shared fields, Nikto modules, MS10-070, JWT, Speed limit
- Web Crawler — engines, screenshot, crawl recommendations
- Recommendations — follow-ups and listing exports
- Cloud Storage Listings — S3 / Azure Blob findings and full-list export
- LFIC — file inclusion scans (New LFIC Scan or host LFIC tab)
- Review findings
- Audit the activity log