docs

Fingerprint

Read the target's tech stack from its captured traffic — servers, frameworks, languages, CDNs and WAFs from response headers and cookies — then turn it into attack recommendations.

Fingerprint tells you what the target runs, so you know which exploits and which CVEs to reach for. The moment you know it speaks PHP, sits behind Cloudflare, or hands out JWTs, your testing has a direction — before you send a single payload. This is the target's stack, not Hugin's own browser fingerprint (that's evasion). It ships in Community; no license needed.

The Fingerprint view: detected technologies and security-header analysis
Identify the target's tech stack from its traffic, flag missing security headers, and turn that into attack recommendations.

Fingerprint is passive. It reads flows you already captured and sends nothing new at the target, so it's safe to run on any engagement. Browse or crawl the app first, then open Fingerprint.

What the profile reads

The Tech Profile is built from the response headers and cookies of your captured flows. Each technology that announces itself in a header or a Set-Cookie is detected and ranked by confidence — how consistently it shows up across your traffic, so a server seen on every response outranks a one-off.

It recognizes roughly 30 technologies, the ones that show their hand in headers:

  • Web servers — nginx, Apache.
  • Languages — PHP, ASP.NET.
  • Frameworks — Express, Laravel, Ruby on Rails, Flask, FastAPI, Next.js, Nuxt.
  • CDNs and edge — Cloudflare, Akamai, Fastly, CloudFront, Azure Front Door.
  • WAFs — AWS WAF, Imperva, Sucuri, F5 BIG-IP, Barracuda, ModSecurity.
  • Hosting and proxies — Vercel, Netlify, Heroku, Kong, Envoy, Traefik.
  • Auth — a JWT in an Authorization: Bearer header or a cookie.

Detection here is header- and cookie-driven, so this view doesn't parse page bodies, scripts, or meta tags, and it doesn't pull out version numbers. A CMS or JS framework that only shows up in the HTML won't land in the Profile. Pair Fingerprint with Nerve, which mines the same captured traffic for parameters worth attacking.

Fingerprint only knows what it has seen. Capture or crawl enough of the app first, or the Profile reads thin.

Security posture

Next to the tech list, the Profile flags how the target is configured:

  • Missing security headers — HSTS, Content-Security-Policy, X-Content-Type-Options, and X-Frame-Options absent across most of your traffic.
  • Information disclosure — a Server or X-Powered-By value that hands you the stack, and often the version, for free.
  • Security issues — a Content-Security-Policy weakened by unsafe-inline or unsafe-eval, the gap that lets injected script run.

Turn the stack into attacks

The Recommendations tab maps a tech stack to known attack playbooks. The header Profile feeds it automatically; you can also hand it tech you identified another way — from the Crawler, a body marker, or by hand — since a CMS or framework won't show up in the header-only Profile. Each play carries a priority, the rationale, payloads to try, and a reference. The headline plays:

  • JWT — alg:none, RS256→HS256 algorithm confusion, weak-secret brute force.
  • Spring — enumerate /actuator (env, heapdump, mappings), and test Log4Shell (CVE-2021-44228) with JNDI callbacks.
  • WordPress — user and plugin enumeration via /wp-json/wp/v2/users, /?author=1, and /xmlrpc.php.
  • PHP — type-juggling auth bypass with 0e-style magic-hash values.
  • ASP.NET — ViewState deserialization when MAC validation is off.
  • GraphQL — introspection to dump the schema.
  • Cloudflare — hunt the origin IP to skip the WAF.
  • nginx — alias path traversal and off-by-slash misconfig.

Recommendations key off the technology names, so they sharpen as you identify more of the stack. Send anything promising straight to Repeater or the Scanner.

Reference tabs

Three tabs are pure reference, for when you want to know what maps to what:

Categories

The 10 technology classes Fingerprint sorts detections into — web server, language, framework, CMS, CDN, WAF, database, API, JS framework, and authentication.

Signatures

14 example detection patterns, showing which header, cookie, or body marker points to which technology. A sample of the matching logic, not an exhaustive signature database.

Security headers

The 6 headers a hardened site sets, the deprecated X-XSS-Protection, and the 4 headers (Server, X-Powered-By, X-AspNet-Version, X-AspNetMvc-Version) that leak your stack — a checklist for reading the posture above.

Work it into the hunt

Capture or crawl the app first so Fingerprint sees a representative sample, read the Profile to learn the stack, then use Recommendations to aim the Scanner and your manual testing where the tech says the bugs will be.

Last updated 2026-06-17.