Sypha AI Docs
Syphax

Deep Scan Assessment

Syphax's exhaustive five-phase penetration testing engagement.

Syphax runs an exhaustive, multi-phase engagement:

Phase 1 — Reconnaissance & Mapping

  • Subdomain enumeration across multiple sources
  • Full port scanning and service fingerprinting
  • Technology stack identification
  • Complete content and endpoint discovery
  • API schema extraction (REST, GraphQL, WebSocket)
  • JavaScript analysis for hidden endpoints and secrets
  • User role mapping and access control topology

Phase 2 — Business Logic Analysis

  • Full storyboarding of user flows and state transitions
  • Trust boundary mapping between components
  • Identification of implicit invariants and assumptions
  • Multi-step workflow documentation (e.g. checkout → payment → fulfilment)
  • Third-party integration analysis

Phase 3 — Attack Surface Testing

Every input vector tested with every applicable technique:

  • Injection: SQL, NoSQL, LDAP, XPath, command injection, template injection
  • Authentication: brute-force protection, session fixation, JWT manipulation, OAuth flow abuse, password reset vulnerabilities, MFA bypass, account enumeration
  • Access control: horizontal and vertical privilege escalation, IDOR, forced browsing, HTTP method tampering
  • File operations: upload bypass, path traversal, SSRF via file inclusion, XXE
  • Business logic: race conditions, price manipulation, workflow bypass, parallel execution attacks, TOCTOU
  • Advanced: HTTP request smuggling, cache poisoning, subdomain takeover, prototype pollution, CORS misconfiguration, GraphQL-specific attacks, WebSocket security

Phase 4 — Vulnerability Chaining

Syphax doesn't just find isolated bugs — it chains them for maximum impact:

  • Information disclosure → access control bypass
  • SSRF → internal service access
  • Low-severity findings enabling high-impact attack paths
  • End-to-end exploit paths: initial foothold → privilege escalation → sensitive action

Phase 5 — Persistent Testing

When initial attempts fail, agents try alternative techniques, different encodings, timing-based exploitation, and blind exploitation approaches before concluding a vector is clean.

On this page