docs

Nerve

Passively classify the parameters in captured traffic, so you know which inputs are worth attacking. (Pro)

A big app has hundreds of parameters; most are boring. Nerve reads the traffic you have already captured and classifies the inputs, so you can aim your testing instead of fuzzing everything. It is a Pro feature, and it is purely passive — it sends no requests of its own.

Nerve's passively classified parameters, grouped by attack category
Nerve reads captured traffic and classifies each parameter into attack categories, so you aim your testing instead of fuzzing everything.

What it surfaces

  • Parameter categories — Nerve matches each parameter name (in query, body, path, header, or cookie) against signal patterns for 22 categories: IDOR, SQLi, SSRF, command injection, LFI, SSTI, XSS, XXE, open redirect, mass assignment, GraphQL, auth, cloud, AI/LLM, workflow, prototype pollution, gateway, edge, SaaS, sourcemap, debug, and feature flags.
  • Value risk — it reads the values too, sorting them into 13 risk classes that raise or lower the confidence on a finding. Details below.
  • Contextual pairs — it flags ~20 high-risk parameter-name combinations, where the attack is the pair rather than either name alone. Details below.
  • Framework detection and false-positive suppression keep the list short — Drupal/WordPress aggregation params, static-asset cache-busters, pagination, and Hugin's own loopback UI traffic are filtered out before they reach you.

The confidence column

Every row carries a confidence — Confirmed, High, Medium, or Low — and that is the column you triage on. Nerve sorts the list so the rows worth your time rise to the top, and it sets that level from more than the parameter name.

  • The value moves it up or down. A name match is a guess; the value is evidence. user_id=42 (a 1–6 digit ID) bumps an IDOR signal from High to Confirmed — small, guessable, exactly what you enumerate. A param that looks like a file path but carries a UUID or a Base64 token gets knocked down a level; it is probably an opaque handle, not a path you can traverse. Nerve keeps the original level too, so you can see when it adjusted one.
  • Repeats rank higher. The same parameter on the same host collapses to one row with a count, and the count drives the order. A param you captured 40 times across the app outranks a one-off — it is load-bearing, so it is worth attacking first.
  • camelCase and snake_case are the same parameter. userId is read as user_id, isAdmin as is_admin. A camelCase API matches the same signals as a snake_case one — the naming style never hides a parameter from you.
  • Nested and path IDs don't hide either. Nerve flattens JSON bodies, so data.user_id still matches on its user_id leaf, and it infers IDs from the path itself — /users/12345/orders/67890 surfaces user and order even though neither is a named query parameter.

What a value tells you

The parameter name says what an input might be; the value often says what it is. Nerve sorts values into 13 risk classes and uses them to set confidence.

Short numeric IDs (1–6 digits)

The strongest IDOR tell — a small, guessable address space. id=42, account=1007. Enumerate up and down.

Longer sequential IDs

Still walkable, just a bigger range. Watch for gaps that map to other users' objects.

UUIDs, and low-entropy UUIDs

A random UUID is hard to guess. A low-entropy one is not — when the bytes are not random, the IDs may be sequential or time-based underneath, and IDOR is back on the table.

Base64 and structured Base64

A blob that Base64-decodes to JSON or XML — not random bytes — is a tamper target: change a field and re-encode. Random high-entropy blobs are likely tokens and rank lower.

Serialized objects

Java (ac ed header) or PHP (O: / a:) serialized data in a value is a deserialization sink — often a straight path to RCE.

Admin booleans

is_admin, is_staff, verified, or enabled carrying true/false is a mass-assignment flip — set it on a write and see if the server takes it. Plain boolean flags are flagged too, just lower.

Inline JSON objects and arrays

A value that is itself {...} or [...] is an object-injection opportunity — smuggle extra keys the endpoint did not expect.

Parameter pairs that matter

One parameter is a lead; two together are a plan. Nerve flags ~20 high-risk combinations that appear on the same request — when both names show up, the attack is often the pair, not either one alone.

Parameters seen togetherWhat it points to
url / endpoint + webhook / callbackSSRF data exfiltration
id / client_id + grant_typeOAuth flow manipulation
token / access_token + redirect / returnToken theft on redirect
bucket + key / objectS3 object access
model + promptLLM prompt injection
namespace + pod / deployment / serviceKubernetes API access
role + user_id / account_idPrivilege escalation
function / handler + payload / bodyServerless RCE
query + variablesGraphQL injection
password + email / usernameCredential-stuffing surface
x-forwarded* + internal / bypassWAF / ACL bypass
x-original-url + admin / internalPath-based ACL bypass
__proto__ + shell / env / execPrototype-pollution RCE
constructor + prototypePrototype-pollution chain
cache_key + host / originCache poisoning
x-forwarded-host + cacheWeb cache poisoning
stripe / payment + amount / pricePayment / price tampering
return_url / success_url + stripe / paymentPost-payment redirect hijack
service_id + upstream / backendService-mesh lateral movement
trace_id + service / clusterDistributed-tracing abuse

Seed the access-control engine

Nerve never sends a request — but its strongest access-control reads do not just sit in a list. The High and Confirmed findings in three categories cross into the active broken access control (BAC) engine and become attack candidates.

  • IDOR params seed a predictable-ID signal — the address to rotate across identities.
  • Mass assignment and debug params seed a role/privilege-field signal — the field to flip for vertical escalation.

Lower-confidence noise stays out, so the active engine only chases the leads Nerve is sure about. This is the one place Nerve's passive read turns into a confirmed bug: the BAC engine replays each endpoint across your identities and diffs the responses. A parameter name is a hint, not proof, so every seeded candidate stays tentative until that replay proves it. See access control testing for the auth-diff engine and Endpointer for feeding it.

Teach it your target's parameter names

The shipped parameter database is fixed, but real apps invent their own — tenantSlug, orgRef, acting_as. Add a custom parameter for the engagement, map it to idor, mass, or debug, and Nerve starts seeding the BAC engine with it immediately — no rebuild, and it survives restarts. Matching is the exact name, case-insensitive (not a regex you have to get right), and you can toggle an entry off without deleting it.

Tag high-value flows as you browse

You do not have to run Nerve as a batch over a saved list. As you browse the target through the Proxy, Nerve reads each real request and tags the high-value ones inline, so the parameters worth attacking surface in your traffic while you capture it. It skips the dead weight — tunnel setup (CONNECT), the bare /, and static assets like .js, .css, images, and .map files carry no injectable parameters, so they are never analyzed. The shortlist fills itself while you click around; read it, then send the top rows to Repeater or Intruder.

Find parameters from a bare URL

No captured traffic yet? Give Nerve a bare URL and it suggests parameter names worth testing for that endpoint type, ranked by priority — a starting wordlist tailored to the target instead of a generic dump.

Nerve is a tip sheet, not a verdict — its "reflected" signal is name-based, not a live reflection test. Confirm anything it flags in Repeater, and aim Intruder at its shortlist.

Last updated 2026-06-17.