
π΅οΈββοΈ ParamHunter Documentation
Welcome toΒ ParamHunter! This tool helps you discover URL and form parameters across websites, tag potential vulnerabilities, and supercharge your reconnaissanceβall from your browser toolkit.
π Features
- Multi-URL Support
- π Paste one or more target URLs (one per line) to start your hunt.
- Smart Crawling
- π Crawl HTML links for new URLs.
- π Analyze JavaScript files for hidden parameters.
- ποΈ Use Wayback Machine URLs for historical parameter discovery.
- π Extract parameters from forms (POST).
- πͺ Optionally include headers and cookies (advanced).
- Customizable Settings
- β‘ Threads: Control concurrent crawling.
- β±οΈ Timeout: Set request timeouts.
- ποΈ Crawl Depth: Choose how deep to follow links.
- π·οΈ Add custom headers and cookies for advanced scenarios.
- Results & Tagging
- π Results Table: See found URLs, parameters, sources, and vulnerability tags.
- π·οΈ Automatic tagging for XSS, SQLi, SSRF, LFI, Open Redirect, IDOR, and more.
- π Timestamped findings for easy tracking.
- Statistics
- π’ Track URLs found, processed, parameters discovered, and potential vulns tagged.
- β³ See elapsed time and progress bar.
- Filtering & Export
- π Filter results by vulnerability type or search term.
- π€ Export results as JSON for further analysis.
- Logging
- π Real-time log of actions, errors, and progress.
π οΈ How to Use
- Enter Target URLs
- Paste one or more URLs (one per line) in the Target URL(s) box.
- Configure Options
- Select which sources to crawl: HTML, JS, Wayback, Forms, Headers/Cookies.
- Adjust threads, timeout, and crawl depth as needed.
- Add custom headers/cookies if required.
- Start the Hunt
- Click the π Start Hunt button.
- Progress, stats, and logs update live.
- Stop anytime with the βΉοΈ Stop Hunt button.
- View & Filter Results
- Results appear in the Results tab.
- Filter by vulnerability type or search for specific URLs/parameters.
- Export Findings
- Click π€ Export Results to save your discoveries as JSON.
- Check Logs
- Switch to the Log tab for detailed activity and troubleshooting.