Glossary
The Hugin-specific terms used across these docs, defined from how Hugin actually works.
One captured request and its response, plus metadata and a source. The core unit — see what is a flow.
The live list of every captured flow (the Dashboard view).
Include/exclude pattern lists that define the target. Modes: capture all, in-scope only, out-of-scope only, or capture-all-and-tag. See scope.
A place an active check injects a payload — a query param, header, cookie, body param, JSON field/pointer, XML element/attribute, path segment, fragment, or the raw body.
The Scanner's two kinds: 48 passive checks read captured flows; 55 active checks send payloads. See active and passive checks.
Confirming a bug by a callback to a host you control when the response shows nothing. Caught by Oastify.
The signals that identify a client. Hugin matches a real browser across TLS (Chrome ClientHello, JA3/JA4), HTTP/2, and the JS environment. See fingerprinting.
Multiplexing many HTTP/2 requests into one packet to hit a race window. See race conditions.