docs

Synaps modules

Install community WASM scanner checks, convert your Nuclei templates, or write your own sandboxed module with HTTP, DNS, TLS, Oastify OOB, and your live session. (Pro)

Synaps runs scanner checks you didn't write. A module is third-party Rust compiled to WebAssembly and run under a Wasmtime sandbox, so installing someone else's check never means running native code on your machine. Synaps is a Pro feature; installed modules join the Scanner and run beside Hugin's built-in checks. For in-app Lua hooks, see Extensions.

Install a module

Manage modules from the command line (the Synaps view mirrors this in the GUI):

hugin scanner install <id> --base-url <feed>
hugin scanner list
hugin scanner update
hugin scanner remove <id>

The community catalog ships bundled, so the Catalog tab and hugin scanner list browse it offline. hugin scanner update now installs the official community modules by default — it pulls their WASM from the official release feed, with no --base-url to configure. To fetch a single module by id, point install at a feed with --base-url; override the catalog source itself with --catalog-url.

What a module can do

Inside the sandbox a check still gets real reach. As attack value:

Probe with your live session

It reads the shared cookie jar, so its requests carry the session you are already logged in with elsewhere in Hugin — authenticated checks, no re-login.

Confirm blind bugs out-of-band

Generate an Oastify payload (DNS, HTTP, SMTP, LDAP, FTP, SMB), fire it, then poll for the callback — the way to prove blind SSRF, blind injection, or Log4Shell.

Reach past HTTP

Raw TCP, DNS lookups, TLS certificate inspection (expiry, self-signed, SAN), WebSocket send and receive, and local file reads.

Drive a headless browser

Navigate, run JavaScript, read the DOM, and screenshot — for checks that need a rendered page.

Chain modules

A producer module extracts a value — a version, a token, an endpoint — and dependent modules consume it through shared data. SBB pattern matching and regex extraction run over any response.

Write a check

A module is a Rust crate built for wasm32-unknown-unknown. The synaps_module! macro wires three functions:

synaps_module!(
    info: get_info,             // -> ModuleInfo: id, severity, CVE, tags
    check: check,               // the probe; returns CheckResult
    should_check: should_check, // optional: skip targets fast
);

check receives a Context (every capability above) and the target. Return CheckResult::vulnerable(Confidence::High) carrying an Evidence item, or CheckResult::not_vulnerable(). Severity::from_cvss(9.8) maps a CVSS score to a severity bucket.

The Synaps CLI

synaps is the author's toolchain:

synaps module new my-check --severity high   # scaffold the crate + module.json
synaps module build my-check --release       # compile to wasm32-unknown-unknown
synaps validate <module.wasm> --strict       # confirm the entry-point exports
synaps module test <module.wasm> -t https://target  # run one module live
synaps compile ./modules -o checks.sbb --aot # pack modules into a database
synaps scan https://target -d checks.sbb     # run the database against a target

Convert Nuclei templates

You don't have to write a module from scratch. synaps-feed turns the Nuclei templates you already run into Synaps modules — the same YAML, rebuilt as a sandboxed WASM check.

synaps-feed validate ./nuclei-templates                                # parse them, report what's supported
synaps-feed compile ./nuclei-templates -o ./wasm --target-dir ./cache  # codegen + build to wasm32
synaps-feed pack ./wasm -o checks.sbb                                  # pack the modules into one database
synaps scan https://target -d checks.sbb                               # run them against the target

compile reads the whole directory, generates Rust for each template, and builds the set in one batch — point --target-dir at a shared cache so repeated runs don't rebuild from cold. Templates that lean on features the converter doesn't support yet show up as failures in validate and are skipped during compile; the rest convert cleanly. Use convert instead of compile to stop at the generated Rust when you want to read or hand-tune a check first.

Sandbox and trust

Every module runs with hard limits: about 1 billion instructions of fuel, 16 MB of memory, and a 30-second wall-clock deadline, so a module that loops or hangs traps instead of taking Hugin down. Each module is addressed by the SHA-256 of its WASM, so you can pin a trust list — synaps scan --trust-file, or the HUGIN_MODULE_TRUSTED_CHECKSUMS variable — and the scanner refuses any module whose hash you haven't vetted.

A module can read your cookie jar and reach the network. Install checks you trust, and pin checksums on shared or CI machines.

Last updated 2026-06-24.