Proof-based Active Testing
Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.
A finding you can reproduce is worth a hundred you can't. With your explicit consent, heimdallX crawls your own site, discovers injectable parameters, and safely probes them — reflecting a harmless marker for cross-site scripting, watching for database error signatures for SQL injection, and validating open-redirect behaviour. The result is proof-based DAST: findings you can trust because they were triggered, not inferred.
Proof, not noise
Proof-based scanning is how leading DAST engines kill false positives — instead of pattern-matching a response, the engine safely demonstrates the vulnerability. heimdallX marks these findings with an "active" exploit-maturity, and they flow straight into the Validation Core where confirmed exploitation outranks everything theoretical.
Safe by design
Active probing never runs by accident. It is gated behind an explicit consent flag, restricted to assets you've verified you own, uses only non-destructive HTTP GET probes, stays strictly same-origin, caps its request volume, and identifies itself with a dedicated user agent. No consent, no probing — the scan simply skips itself.
How probing works
A bounded crawl follows links and GET forms from your homepage to discover parameters worth testing. Each candidate gets targeted, safe payloads: a verbatim reflection marker for XSS, a quote that elicits a DB error signature for SQLi, and a controlled redirect target for open redirects. Anything that triggers is captured as proof.
How it works
Consent
Verify asset ownership and explicit opt-in to active probing.
Crawl
Bounded, same-origin crawl finds injectable parameters.
Probe
Safe payloads: marker reflection, DB-error, redirect.
Prove
Triggered findings flow into the Validation Core.
Put it to work
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX