Inspect authorized offline satellite and SATCOM artifacts without transmitting. Use for TLE sets, CCSDS Space Packet streams, telemetry or telecommand captures, sequence-counter anomalies, spacecraft identifiers, packet-length validation, or passive…
Investigate authorized unsafe deserialization and serialized-data trust boundaries. Use when typed discovery identifies encoded object cookies or tokens, pickle or object streams, YAML type tags, serialized uploads or imports, type-confusion errors, or…
Investigate authorized file-upload, stored-file, and upload-parser boundaries. Use when typed discovery identifies upload forms, multipart requests, filename or content-type handling, stored-file readback, image or document ingestion, archive processing, XML…
Investigate authorized GraphQL schemas, operations, resolvers, and object-authorization boundaries. Use when typed discovery identifies GraphQL endpoints, introspection, query or mutation names, global object identifiers, resolver errors, or API…
Investigate object-level and tenant authorization boundaries on authorized web or API targets. Use when typed routes or operator context expose object identifiers, account or tenant selectors, user-owned resources, GraphQL object lookups, or suspected…
Investigate authorized local file inclusion, path traversal, and arbitrary file-read boundaries. Use when typed discovery identifies path, file, page, template, include, download, or document inputs, target-observed file-read replay contracts, local-file…
Investigate authorized server-side command and code-execution boundaries. Use when typed discovery or target-origin behavior identifies command injection, process-launching, diagnostic, converter, expression-evaluation, parser, include, or other server-side…
Investigate authorized SQL injection boundaries on web and API inputs. Use when typed discovery or target-origin evidence identifies query-backed parameters, database-error signals, boolean or timing SQL differentials, SQL-filter behavior, or a suspected…