Oastify CLI
Every hugin oastify subcommand for out-of-band callback tracking — connect, generate payloads, read interactions, run a self-hosted native OAST server.
The hugin oastify commands drive Hugin's out-of-band (OOB) callback
infrastructure from the terminal. All commands talk to the live API server
started by hugin start — they are not standalone.
export HUGIN_API_URL=http://127.0.0.1:8081 # default; override if your API is elsewhere
Remote OAST server
Connect to a hosted or self-hosted OAST server to receive DNS, HTTP, SMTP, LDAP, FTP, and SMB callbacks from payloads you inject.
connect
hugin oastify connect --domain oastify.eu --session my-session --token <api-token>
| Flag | Required | Default | Description |
|---|---|---|---|
--domain | yes | OAST server domain (e.g. oastify.eu, oast.example.com) | |
--session | yes | Session ID (adjective-noun-verb or 4–64 alnum/-) | |
--token | no | API token sent as x-api-token header |
Idempotent — reconnects if already connected.
disconnect
hugin oastify disconnect
status
hugin oastify status
Prints connection state, domain, session ID, and callback stats.
stream-url
hugin oastify stream-url
Prints the SSE stream URL for the connected session. Pipe into curl or
httpie to tail callbacks in real time.
remote-stream
hugin oastify remote-stream
Opens the remote SSE stream and tees it to stdout. Same URL as stream-url
but connects for you.
Payloads and interactions
generate
hugin oastify generate --command pl --target https://target.example --description "SSRF test"
| Flag | Required | Default | Description |
|---|---|---|---|
--command | no | pl | vurl command code |
--payload | no | Payload string for the upstream tracker | |
--target | no | Target URL | |
--description | no | Human-readable note |
Returns a tracked payload (usually a subdomain) you embed in your injection.
payloads
hugin oastify payloads --limit 50
hugin oastify payloads --command pl --limit 100
| Flag | Required | Default | Description |
|---|---|---|---|
--command | no | Filter by command code | |
--limit | no | 100 | Max results |
payloads-list-batch
hugin oastify payloads-list-batch --limit 200
Bulk-list payloads tracked by the upstream tracker.
| Flag | Required | Default | Description |
|---|---|---|---|
--limit | no | 200 | Max results |
list-rubrics
hugin oastify list-rubrics
Lists rubrics (registered payloads) for the connected session. Requires connection to a remote OAST server.
register-batch
hugin oastify register-batch --file payloads.json
Bulk-register payloads against the remote tracker. The JSON file must have
the shape {"payloads": [...]}.
| Flag | Required | Default | Description |
|---|---|---|---|
--file | yes | Path to JSON file |
interactions
hugin oastify interactions --format table
hugin oastify interactions --format json
| Flag | Required | Default | Description |
|---|---|---|---|
--format | no | json | table or json |
Table output: ID, type, subdomain, timestamp.
get-by-correlation
hugin oastify get-by-correlation abc123de
Fetch interactions filtered by correlation ID (the subdomain prefix embedded in your payload).
acknowledge
hugin oastify acknowledge <interaction-uuid>
Acknowledge an interaction so the live UI hides it.
revoke
hugin oastify revoke <rubric-id>
Revoke a registered payload by its rubric ID (from generate output).
clear
hugin oastify clear
Clear all callbacks for the connected session (server-side).
sync
hugin oastify sync
Sync the local tracker with the remote OAST server — polls and correlates.
audit
hugin oastify audit --limit 500
List recent audit events (admin-key required server-side).
| Flag | Required | Default | Description |
|---|---|---|---|
--limit | no | 200 | Max results |
Native OAST server
Run an in-process OAST listener (DNS + HTTP) without an external server. Useful for lab environments or when you control the DNS path.
native-start
hugin oastify native-start --domain oastify.local --external-ip 203.0.113.10
hugin oastify native-start --domain oastify.local --external-ip 203.0.113.10 --dns-port 5353 --http-port 8080
| Flag | Required | Default | Description |
|---|---|---|---|
--domain | yes | Domain for DNS responses (e.g. oastify.local) | |
--external-ip | yes | IP returned in DNS responses | |
--dns-port | no | 53 | DNS listener port |
--http-port | no | 80 | HTTP callback listener port |
native-stop
hugin oastify native-stop
native-stats
hugin oastify native-stats
Show native-server stats (payloads registered, interactions captured, uptime).
native-payloads
hugin oastify native-payloads --limit 50
| Flag | Required | Default | Description |
|---|---|---|---|
--limit | no | 100 | Max results |
native-interactions
hugin oastify native-interactions --format table
hugin oastify native-interactions --format json
| Flag | Required | Default | Description |
|---|---|---|---|
--format | no | json | table or json |
Table output: ID, protocol, correlation ID, timestamp.
The native OAST server needs root or CAP_NET_BIND_SERVICE to listen on
port 53. Use --dns-port 5353 for unprivileged testing.