Param Discover
Actively find the hidden parameters an endpoint accepts but never advertises — debug flags, admin toggles, mass-assignment fields. (Pro)
Nerve reads the parameters already in your captured traffic. Param Discover goes after the ones that never show up: undocumented inputs an endpoint still accepts — debug flags, admin toggles, and mass-assignment fields. It fires candidate parameter names at a live endpoint and reports the ones the app actually processes. It is active, unlike Nerve which sends nothing, and it finds parameters, not paths (that is Discover). It is a Pro feature.
Point it at an endpoint
Right-click a flow in History and choose Discover params — the URL and method carry over; click Start Discovery. Or type a target URL yourself. Pick the method (GET, POST, PUT, PATCH, DELETE) and the location to test: query string, form body, JSON body, headers, or cookies. Single Check mode tests one named parameter against one endpoint and shows its baseline beside the with-parameter response.
Where the candidate names come from
A default list of common parameter names, with a header-specific list when you test the header location.
Your own names, pasted one per line.
Point it at a JavaScript file and it pulls parameter names straight from the
code — URLSearchParams, params[...], ?name= — into the run.
How it confirms a real parameter
It calibrates first — capturing the endpoint's baseline both cached and cache-busted, so it knows how the page moves on its own. Then it sends candidates in batches, each carrying a unique marker and a fresh cache-buster. A batch that shifts the response — status, body, a length swing past the threshold, or the marker reflected — is promoted, and each promoted name is re-sent alone, with and without it, to confirm. Findings fill a sortable table: name, location, confidence, the detection signal, the status change, and the byte difference.
The marker plus the with/without recheck separate a parameter the app truly handles from a page that just changes on its own. The names that survive are worth attacking.
Turn on cache detection to flag whether a confirmed parameter sits in the cache key — the opening for cache poisoning. Take a confirmed name into Repeater to attack its value, or load the shortlist into Intruder to fuzz it.