docs

Oastify CLI

Every hugin oastify subcommand for out-of-band callback tracking — connect, generate payloads, read interactions, run a self-hosted native OAST server.

The hugin oastify commands drive Hugin's out-of-band (OOB) callback infrastructure from the terminal. All commands talk to the live API server started by hugin start — they are not standalone.

export HUGIN_API_URL=http://127.0.0.1:8081   # default; override if your API is elsewhere

Remote OAST server

Connect to a hosted or self-hosted OAST server to receive DNS, HTTP, SMTP, LDAP, FTP, and SMB callbacks from payloads you inject.

connect

hugin oastify connect --domain oastify.eu --session my-session --token <api-token>
FlagRequiredDefaultDescription
--domainyesOAST server domain (e.g. oastify.eu, oast.example.com)
--sessionyesSession ID (adjective-noun-verb or 4–64 alnum/-)
--tokennoAPI token sent as x-api-token header

Idempotent — reconnects if already connected.

disconnect

hugin oastify disconnect

status

hugin oastify status

Prints connection state, domain, session ID, and callback stats.

stream-url

hugin oastify stream-url

Prints the SSE stream URL for the connected session. Pipe into curl or httpie to tail callbacks in real time.

remote-stream

hugin oastify remote-stream

Opens the remote SSE stream and tees it to stdout. Same URL as stream-url but connects for you.

Payloads and interactions

generate

hugin oastify generate --command pl --target https://target.example --description "SSRF test"
FlagRequiredDefaultDescription
--commandnoplvurl command code
--payloadnoPayload string for the upstream tracker
--targetnoTarget URL
--descriptionnoHuman-readable note

Returns a tracked payload (usually a subdomain) you embed in your injection.

payloads

hugin oastify payloads --limit 50
hugin oastify payloads --command pl --limit 100
FlagRequiredDefaultDescription
--commandnoFilter by command code
--limitno100Max results

payloads-list-batch

hugin oastify payloads-list-batch --limit 200

Bulk-list payloads tracked by the upstream tracker.

FlagRequiredDefaultDescription
--limitno200Max results

list-rubrics

hugin oastify list-rubrics

Lists rubrics (registered payloads) for the connected session. Requires connection to a remote OAST server.

register-batch

hugin oastify register-batch --file payloads.json

Bulk-register payloads against the remote tracker. The JSON file must have the shape {"payloads": [...]}.

FlagRequiredDefaultDescription
--fileyesPath to JSON file

interactions

hugin oastify interactions --format table
hugin oastify interactions --format json
FlagRequiredDefaultDescription
--formatnojsontable or json

Table output: ID, type, subdomain, timestamp.

get-by-correlation

hugin oastify get-by-correlation abc123de

Fetch interactions filtered by correlation ID (the subdomain prefix embedded in your payload).

acknowledge

hugin oastify acknowledge <interaction-uuid>

Acknowledge an interaction so the live UI hides it.

revoke

hugin oastify revoke <rubric-id>

Revoke a registered payload by its rubric ID (from generate output).

clear

hugin oastify clear

Clear all callbacks for the connected session (server-side).

sync

hugin oastify sync

Sync the local tracker with the remote OAST server — polls and correlates.

audit

hugin oastify audit --limit 500

List recent audit events (admin-key required server-side).

FlagRequiredDefaultDescription
--limitno200Max results

Native OAST server

Run an in-process OAST listener (DNS + HTTP) without an external server. Useful for lab environments or when you control the DNS path.

native-start

hugin oastify native-start --domain oastify.local --external-ip 203.0.113.10
hugin oastify native-start --domain oastify.local --external-ip 203.0.113.10 --dns-port 5353 --http-port 8080
FlagRequiredDefaultDescription
--domainyesDomain for DNS responses (e.g. oastify.local)
--external-ipyesIP returned in DNS responses
--dns-portno53DNS listener port
--http-portno80HTTP callback listener port

native-stop

hugin oastify native-stop

native-stats

hugin oastify native-stats

Show native-server stats (payloads registered, interactions captured, uptime).

native-payloads

hugin oastify native-payloads --limit 50
FlagRequiredDefaultDescription
--limitno100Max results

native-interactions

hugin oastify native-interactions --format table
hugin oastify native-interactions --format json
FlagRequiredDefaultDescription
--formatnojsontable or json

Table output: ID, protocol, correlation ID, timestamp.

The native OAST server needs root or CAP_NET_BIND_SERVICE to listen on port 53. Use --dns-port 5353 for unprivileged testing.

Last updated 2026-07-10.