Synaps modules
Install community WASM scanner checks, convert your Nuclei templates, or write your own sandboxed module with HTTP, DNS, TLS, Oastify OOB, and your live session. (Pro)
Synaps runs scanner checks you didn't write. A module is third-party Rust compiled to WebAssembly and run under a Wasmtime sandbox, so installing someone else's check never means running native code on your machine. Synaps is a Pro feature; installed modules join the Scanner and run beside Hugin's built-in checks. For in-app Lua hooks, see Extensions.
Install a module
Manage modules from the command line (the Synaps view mirrors this in the GUI):
hugin scanner install <id> --base-url <feed>
hugin scanner list
hugin scanner update
hugin scanner remove <id>
The community catalog ships bundled, so the Catalog tab and hugin scanner list
browse it offline. hugin scanner update now installs the official community
modules by default — it pulls their WASM from the official release feed, with no
--base-url to configure. To fetch a single module by id, point install at a
feed with --base-url; override the catalog source itself with --catalog-url.
What a module can do
Inside the sandbox a check still gets real reach. As attack value:
It reads the shared cookie jar, so its requests carry the session you are already logged in with elsewhere in Hugin — authenticated checks, no re-login.
Generate an Oastify payload (DNS, HTTP, SMTP, LDAP, FTP, SMB), fire it, then poll for the callback — the way to prove blind SSRF, blind injection, or Log4Shell.
Raw TCP, DNS lookups, TLS certificate inspection (expiry, self-signed, SAN), WebSocket send and receive, and local file reads.
Navigate, run JavaScript, read the DOM, and screenshot — for checks that need a rendered page.
A producer module extracts a value — a version, a token, an endpoint — and dependent modules consume it through shared data. SBB pattern matching and regex extraction run over any response.
Write a check
A module is a Rust crate built for wasm32-unknown-unknown. The
synaps_module! macro wires three functions:
synaps_module!(
info: get_info, // -> ModuleInfo: id, severity, CVE, tags
check: check, // the probe; returns CheckResult
should_check: should_check, // optional: skip targets fast
);
check receives a Context (every capability above) and the target. Return
CheckResult::vulnerable(Confidence::High) carrying an Evidence item, or
CheckResult::not_vulnerable(). Severity::from_cvss(9.8) maps a CVSS score to
a severity bucket.
The Synaps CLI
synaps is the author's toolchain:
synaps module new my-check --severity high # scaffold the crate + module.json
synaps module build my-check --release # compile to wasm32-unknown-unknown
synaps validate <module.wasm> --strict # confirm the entry-point exports
synaps module test <module.wasm> -t https://target # run one module live
synaps compile ./modules -o checks.sbb --aot # pack modules into a database
synaps scan https://target -d checks.sbb # run the database against a target
Convert Nuclei templates
You don't have to write a module from scratch. synaps-feed turns the Nuclei
templates you already run into Synaps modules — the same YAML, rebuilt as a
sandboxed WASM check.
synaps-feed validate ./nuclei-templates # parse them, report what's supported
synaps-feed compile ./nuclei-templates -o ./wasm --target-dir ./cache # codegen + build to wasm32
synaps-feed pack ./wasm -o checks.sbb # pack the modules into one database
synaps scan https://target -d checks.sbb # run them against the target
compile reads the whole directory, generates Rust for each template, and
builds the set in one batch — point --target-dir at a shared cache so repeated
runs don't rebuild from cold. Templates that lean on features the converter
doesn't support yet show up as failures in validate and are skipped during
compile; the rest convert cleanly. Use convert instead of compile to stop
at the generated Rust when you want to read or hand-tune a check first.
Sandbox and trust
Every module runs with hard limits: about 1 billion instructions of fuel, 16 MB
of memory, and a 30-second wall-clock deadline, so a module that loops or hangs
traps instead of taking Hugin down. Each module is addressed by the SHA-256 of
its WASM, so you can pin a trust list — synaps scan --trust-file, or the
HUGIN_MODULE_TRUSTED_CHECKSUMS variable — and the scanner refuses any module
whose hash you haven't vetted.
A module can read your cookie jar and reach the network. Install checks you trust, and pin checksums on shared or CI machines.