Syphax
Deep Scan Assessment
Syphax's exhaustive five-phase penetration testing engagement.
Syphax runs an exhaustive, multi-phase engagement:
Phase 1 — Reconnaissance & Mapping
- Subdomain enumeration across multiple sources
- Full port scanning and service fingerprinting
- Technology stack identification
- Complete content and endpoint discovery
- API schema extraction (REST, GraphQL, WebSocket)
- JavaScript analysis for hidden endpoints and secrets
- User role mapping and access control topology
Phase 2 — Business Logic Analysis
- Full storyboarding of user flows and state transitions
- Trust boundary mapping between components
- Identification of implicit invariants and assumptions
- Multi-step workflow documentation (e.g. checkout → payment → fulfilment)
- Third-party integration analysis
Phase 3 — Attack Surface Testing
Every input vector tested with every applicable technique:
- Injection: SQL, NoSQL, LDAP, XPath, command injection, template injection
- Authentication: brute-force protection, session fixation, JWT manipulation, OAuth flow abuse, password reset vulnerabilities, MFA bypass, account enumeration
- Access control: horizontal and vertical privilege escalation, IDOR, forced browsing, HTTP method tampering
- File operations: upload bypass, path traversal, SSRF via file inclusion, XXE
- Business logic: race conditions, price manipulation, workflow bypass, parallel execution attacks, TOCTOU
- Advanced: HTTP request smuggling, cache poisoning, subdomain takeover, prototype pollution, CORS misconfiguration, GraphQL-specific attacks, WebSocket security
Phase 4 — Vulnerability Chaining
Syphax doesn't just find isolated bugs — it chains them for maximum impact:
- Information disclosure → access control bypass
- SSRF → internal service access
- Low-severity findings enabling high-impact attack paths
- End-to-end exploit paths: initial foothold → privilege escalation → sensitive action
Phase 5 — Persistent Testing
When initial attempts fail, agents try alternative techniques, different encodings, timing-based exploitation, and blind exploitation approaches before concluding a vector is clean.