docs

Glossary

The Hugin-specific terms used across these docs, defined from how Hugin actually works.

Flow

One captured request and its response, plus metadata and a source. The core unit — see what is a flow.

HTTP History

The live list of every captured flow (the Dashboard view).

Scope

Include/exclude pattern lists that define the target. Modes: capture all, in-scope only, out-of-scope only, or capture-all-and-tag. See scope.

Insertion point

A place an active check injects a payload — a query param, header, cookie, body param, JSON field/pointer, XML element/attribute, path segment, fragment, or the raw body.

Active vs passive check

The Scanner's two kinds: 48 passive checks read captured flows; 55 active checks send payloads. See active and passive checks.

Out-of-band (OOB)

Confirming a bug by a callback to a host you control when the response shows nothing. Caught by Oastify.

Fingerprint

The signals that identify a client. Hugin matches a real browser across TLS (Chrome ClientHello, JA3/JA4), HTTP/2, and the JS environment. See fingerprinting.

Single-packet attack

Multiplexing many HTTP/2 requests into one packet to hit a race window. See race conditions.

Last updated 2026-06-07.