docs

Param Discover

Actively find the hidden parameters an endpoint accepts but never advertises — debug flags, admin toggles, mass-assignment fields. (Pro)

Nerve reads the parameters already in your captured traffic. Param Discover goes after the ones that never show up: undocumented inputs an endpoint still accepts — debug flags, admin toggles, and mass-assignment fields. It fires candidate parameter names at a live endpoint and reports the ones the app actually processes. It is active, unlike Nerve which sends nothing, and it finds parameters, not paths (that is Discover). It is a Pro feature.

Point it at an endpoint

Right-click a flow in History and choose Discover params — the URL and method carry over; click Start Discovery. Or type a target URL yourself. Pick the method (GET, POST, PUT, PATCH, DELETE) and the location to test: query string, form body, JSON body, headers, or cookies. Single Check mode tests one named parameter against one endpoint and shows its baseline beside the with-parameter response.

Where the candidate names come from

Built-in wordlist

A default list of common parameter names, with a header-specific list when you test the header location.

Custom wordlist

Your own names, pasted one per line.

JS mine URL

Point it at a JavaScript file and it pulls parameter names straight from the code — URLSearchParams, params[...], ?name= — into the run.

How it confirms a real parameter

It calibrates first — capturing the endpoint's baseline both cached and cache-busted, so it knows how the page moves on its own. Then it sends candidates in batches, each carrying a unique marker and a fresh cache-buster. A batch that shifts the response — status, body, a length swing past the threshold, or the marker reflected — is promoted, and each promoted name is re-sent alone, with and without it, to confirm. Findings fill a sortable table: name, location, confidence, the detection signal, the status change, and the byte difference.

The marker plus the with/without recheck separate a parameter the app truly handles from a page that just changes on its own. The names that survive are worth attacking.

Turn on cache detection to flag whether a confirmed parameter sits in the cache key — the opening for cache poisoning. Take a confirmed name into Repeater to attack its value, or load the shortlist into Intruder to fuzz it.

Last updated 2026-06-16.