Nerve
Passively classify the parameters in captured traffic, so you know which inputs are worth attacking. (Pro)
A big app has hundreds of parameters; most are boring. Nerve reads the traffic you have already captured and classifies the inputs, so you can aim your testing instead of fuzzing everything. It is a Pro feature, and it is purely passive — it sends no requests of its own.

What it surfaces
- Parameter categories — Nerve matches each parameter name (in query, body, path, header, or cookie) against signal patterns for 22 categories: IDOR, SQLi, SSRF, command injection, LFI, SSTI, XSS, XXE, open redirect, mass assignment, GraphQL, auth, cloud, AI/LLM, workflow, prototype pollution, gateway, edge, SaaS, sourcemap, debug, and feature flags.
- Value risk — it reads the values too, sorting them into 13 risk classes that raise or lower the confidence on a finding. Details below.
- Contextual pairs — it flags ~20 high-risk parameter-name combinations, where the attack is the pair rather than either name alone. Details below.
- Framework detection and false-positive suppression keep the list short — Drupal/WordPress aggregation params, static-asset cache-busters, pagination, and Hugin's own loopback UI traffic are filtered out before they reach you.
The confidence column
Every row carries a confidence — Confirmed, High, Medium, or Low — and that is the column you triage on. Nerve sorts the list so the rows worth your time rise to the top, and it sets that level from more than the parameter name.
- The value moves it up or down. A name match is a guess; the value is
evidence.
user_id=42(a 1–6 digit ID) bumps an IDOR signal from High to Confirmed — small, guessable, exactly what you enumerate. A param that looks like a file path but carries a UUID or a Base64 token gets knocked down a level; it is probably an opaque handle, not a path you can traverse. Nerve keeps the original level too, so you can see when it adjusted one. - Repeats rank higher. The same parameter on the same host collapses to one row with a count, and the count drives the order. A param you captured 40 times across the app outranks a one-off — it is load-bearing, so it is worth attacking first.
- camelCase and snake_case are the same parameter.
userIdis read asuser_id,isAdminasis_admin. A camelCase API matches the same signals as a snake_case one — the naming style never hides a parameter from you. - Nested and path IDs don't hide either. Nerve flattens JSON bodies, so
data.user_idstill matches on itsuser_idleaf, and it infers IDs from the path itself —/users/12345/orders/67890surfacesuserandordereven though neither is a named query parameter.
What a value tells you
The parameter name says what an input might be; the value often says what it is. Nerve sorts values into 13 risk classes and uses them to set confidence.
The strongest IDOR tell — a small, guessable address space. id=42,
account=1007. Enumerate up and down.
Still walkable, just a bigger range. Watch for gaps that map to other users' objects.
A random UUID is hard to guess. A low-entropy one is not — when the bytes are not random, the IDs may be sequential or time-based underneath, and IDOR is back on the table.
A blob that Base64-decodes to JSON or XML — not random bytes — is a tamper target: change a field and re-encode. Random high-entropy blobs are likely tokens and rank lower.
Java (ac ed header) or PHP (O: / a:) serialized data in a value is a
deserialization sink — often a straight path to RCE.
is_admin, is_staff, verified, or enabled carrying true/false is a
mass-assignment flip — set it on a write and see if the server takes it. Plain
boolean flags are flagged too, just lower.
A value that is itself {...} or [...] is an object-injection opportunity —
smuggle extra keys the endpoint did not expect.
Parameter pairs that matter
One parameter is a lead; two together are a plan. Nerve flags ~20 high-risk combinations that appear on the same request — when both names show up, the attack is often the pair, not either one alone.
| Parameters seen together | What it points to |
|---|---|
url / endpoint + webhook / callback | SSRF data exfiltration |
id / client_id + grant_type | OAuth flow manipulation |
token / access_token + redirect / return | Token theft on redirect |
bucket + key / object | S3 object access |
model + prompt | LLM prompt injection |
namespace + pod / deployment / service | Kubernetes API access |
role + user_id / account_id | Privilege escalation |
function / handler + payload / body | Serverless RCE |
query + variables | GraphQL injection |
password + email / username | Credential-stuffing surface |
x-forwarded* + internal / bypass | WAF / ACL bypass |
x-original-url + admin / internal | Path-based ACL bypass |
__proto__ + shell / env / exec | Prototype-pollution RCE |
constructor + prototype | Prototype-pollution chain |
cache_key + host / origin | Cache poisoning |
x-forwarded-host + cache | Web cache poisoning |
stripe / payment + amount / price | Payment / price tampering |
return_url / success_url + stripe / payment | Post-payment redirect hijack |
service_id + upstream / backend | Service-mesh lateral movement |
trace_id + service / cluster | Distributed-tracing abuse |
Seed the access-control engine
Nerve never sends a request — but its strongest access-control reads do not just sit in a list. The High and Confirmed findings in three categories cross into the active broken access control (BAC) engine and become attack candidates.
- IDOR params seed a predictable-ID signal — the address to rotate across identities.
- Mass assignment and debug params seed a role/privilege-field signal — the field to flip for vertical escalation.
Lower-confidence noise stays out, so the active engine only chases the leads Nerve is sure about. This is the one place Nerve's passive read turns into a confirmed bug: the BAC engine replays each endpoint across your identities and diffs the responses. A parameter name is a hint, not proof, so every seeded candidate stays tentative until that replay proves it. See access control testing for the auth-diff engine and Endpointer for feeding it.
Teach it your target's parameter names
The shipped parameter database is fixed, but real apps invent their own —
tenantSlug, orgRef, acting_as. Add a custom parameter for the engagement, map
it to idor, mass, or debug, and Nerve starts seeding the BAC engine with it
immediately — no rebuild, and it survives restarts. Matching is the exact name,
case-insensitive (not a regex you have to get right), and you can toggle an entry
off without deleting it.
Tag high-value flows as you browse
You do not have to run Nerve as a batch over a saved list. As you browse the target
through the Proxy, Nerve reads each real request and
tags the high-value ones inline, so the parameters worth attacking surface in your
traffic while you capture it. It skips the dead weight — tunnel setup (CONNECT),
the bare /, and static assets like .js, .css, images, and .map files carry
no injectable parameters, so they are never analyzed. The shortlist fills itself
while you click around; read it, then send the top rows to Repeater or Intruder.
Find parameters from a bare URL
No captured traffic yet? Give Nerve a bare URL and it suggests parameter names worth testing for that endpoint type, ranked by priority — a starting wordlist tailored to the target instead of a generic dump.