0. 先读 1 分钟:这是做什么的?
Hx0鹰眼 是面向 Chrome 与 Firefox 的浏览器扩展:扩展图标弹窗负责开关抓包/拦截、配置目标,以及进入「抓包界面」;侧边栏承载历史、拦截队列与重放工作台。本手册以两版共通能力为主,浏览器差异集中在 §14。
社区版主链路:抓包 → 筛选 → 看详情 → 拦截改包 → 普通重放 → 基础编解码。专业版在此基础上进一步开放 浏览器级 Agent、浏览器自动化 MCP、页面内重放、微型 Fuzz、页面脚本注入、暗链检测、AI 分析、AI 任务、Skills 知识库 与 批量工作台。
新手友好
抓包定位快
支持重放
支持敏感检测
支持AI分析
浏览器级Agent
浏览器自动化 MCP
v1.0.6本次更新重点
- 鹰眼浏览器自动化 MCP(PRO):定位类似面向安全专版的 Playwright MCP,除导航、点击、输入和快照外,还直接贯通鹰眼抓包、重放、变异、敏感信息与证据工具,兼容 stdio、Streamable HTTP 与 legacy SSE。
- 浏览器级 Agent 能力(PRO):Agent 模式仅在有效试用或专业版授权下可用;它在用户真实浏览器会话中自主规划并多轮执行导航、复杂控件 / iframe 交互、抓包研判、重放验证与下载,不只是普通对话或单次 AI 分析。
- 相比 1.0.5 的社区版能力开放:智能代理分流器、全量深度搜索,以及内置 / 自定义敏感信息匹配与关键词库在 1.0.6 起向社区版开放。
- 抓包、重放与 WebSocket 性能优化,降低大响应、大文件和大流量场景的卡顿与内存占用,并提升二进制消息处理完整性。
- Chrome / Firefox 真实输入与证据留存:加强可信键鼠输入和 Firefox 原生输入回退,保护需要
userActivation 的全屏等操作;browser_screenshot 可按需保存为本地 PNG/JPEG 证据文件。
- AI 任务与长时间运行稳定性提升,优化日志持久化、超时 / 取消清理和 MCP 断线重连可靠性。
- 强化 Chrome / Firefox 双版本一致性,加入自动完整性与回归检查。
- 抓包界面快捷键:默认
Ctrl+H(Mac 为 Control+H / ⌃H,不是 Command 或 Option),不必先点开弹窗。Chrome 打开或收起抓包侧栏,改键请到 chrome://extensions/shortcuts;Firefox 打开或收起页面内抓包浮窗(浮窗里可「收起到侧边栏」),可在高级设置录制新组合,再按一次即关闭。
0909版本更新:模型与记忆:新增 DeepSeek V4.1 Flash(支持图片)候选,OpenAI 默认改为 GPT-6 Astra 并保留 GPT-5.6,适配 max / low 思考参数;历史摘要召回默认关闭;新增默认人设「鹰眼万能浏览器助手」。Agent 操作:导入对话改为标题栏「+」左侧小按钮,并按导出 Markdown 还原工具卡片;Skills 默认关闭,浮层从 Skills 按钮向右上方展开,再点一次关闭并恢复未选中,智能路由不限制技能加载数量;任务建议覆盖日常浏览器操作(如打开哔哩哔哩搜索奥特曼并播放)与安全排障。稳定性:修复切换标签页后仍操作旧页、关闭任务页异常退出、文件发现误触发下载和检查点超限阻断新任务;完善目标/计划进度保留、中断恢复与防重复提交;修复 Skill 保存回执,以及空响应/输出预算耗尽后最多一次恢复。
1. 小白 5 分钟上手(必看)
安装 ZIP 发行包:Chrome 先解压 ZIP 到固定目录,打开 chrome://extensions,开启「开发者模式」后选「加载已解压的扩展程序」,选择含 manifest.json 的目录;Firefox 先解压 ZIP,打开 about:debugging#/runtime/this-firefox →「临时载入附加组件」,选择 manifest.json(重启 Firefox 后需重新临时载入)。官方仅发布 ZIP,不发布 CRX / XPI:可避免非商店 CRX 被 Chrome 自动停用,并让两个浏览器统一从可校验的解压目录安装。升级前请备份重要导出数据,用新版文件替换原目录后在扩展管理页重新加载。
- 第1步:先只开抓包。弹窗里把
抓包 打开,拦截 先不要开(避免影响正常访问)。
- 第2步:先缩小范围。在弹窗「抓包与拦截目标域名/IP」填测试站点(如
*.example.com)。首次安装默认勾选 XHR/Fetch、WebSocket、HTML、JS、JSON、XML,这组合兼顾接口、前端逻辑和页面入口;高流量页面可临时只留 XHR/Fetch + WebSocket 降噪。
- 第3步:访问目标页面。正常点页面按钮或提交表单,触发接口请求。
- 第4步:打开主工作台。在弹窗点
抓包界面 打开侧边栏,也可直接按默认快捷键 Ctrl+H(Mac 为 Control+H,不是 Command;详见 §4)。切到 历史;默认显示当前页面的数据包,再用 Host/方法/状态码/搜索等筛选。
- 第5步:展开详情。先看
Pretty,有需要再看 Raw(未格式化原始文本)、Hex、Render、敏感信息。
- 第6步:重放验证。点
重放 进入工作台,改参数后发送;社区版到这里已经能完成“抓包 → 看详情 → 普通重放”的主链路闭环。
- 第7步(专业版 · 可选):在详情里试 检测暗链 / AI 分析 / AI脚本 / 加密逻辑智能分析(见 §5.2);浏览目标页时启用内置 页面情报 / 智能解码 / 智能渗透 脚本(见 §4.4);需要全自动验证时再开 AI 任务(见 §10)。
建议:第一次使用先跑通“抓包 + 看详情 + 普通重放”;后续再按需启用拦截改包,并在专业版中使用页面内重放、微型 Fuzz、页面脚本、暗链和 AI 功能。
2. 弹窗入口
点击浏览器工具栏上的扩展图标,打开 Hx0 鹰眼弹窗。弹窗顶部通常有三个标签:
- 基础设置:抓包 / 拦截开关、目标域名、抓包类型、代理分流等——详见 §3。
- 高级设置:语言、页面脚本、AI、Skills、敏感规则、暗链等——详见 §4。
- 抓包界面:打开侧边栏主工作台(历史 / 拦截 / 重放 / AI 任务等)。
弹窗右上角为状态徽章(社区版 / 试用 / 专业版),单击进入软件激活,双击(已授权时)查看授权详情,见 §13。Chrome 还可在 chrome://extensions → 本扩展「详细信息」→「扩展程序选项」打开独立设置页,与弹窗高级设置部分重叠。
不必每次都点弹窗:默认快捷键 Ctrl+H(Mac 为 Control+H)即可打开或收起抓包界面。Chrome 切换侧栏;Firefox 切换页面内浮窗。改键与浏览器差异见 §4、§14。
3. 基础设置
控制是否抓包、抓哪些站、抓哪些类型,以及拦截、代理分流与 Chrome 被动监听等。社区版与专业版差异见各条说明。
- 抓包开关:开启后才会记录数据包;关闭则仅保留已有历史,不再新增。
- 抓包与拦截目标域名/IP(同一输入框):
- 支持多行或逗号分隔;支持
*.example.com 通配。
- 留空表示全部域名(流量多,新手不建议)。
- 命中规则的请求进入抓包历史;开启拦截时,同一规则决定哪些请求进入拦截队列。
- 抓包类型 / 后缀:
- 首次安装的推荐默认:勾选
XHR/Fetch、WebSocket、HTML、JS、JSON、XML;不勾选 CSS、Other text、BINARY 和 Flash。这能抓到主流 API、页面入口、脚本中的接口/签名逻辑、JSON/XML 配置和 WebSocket 帧,同时避开大量样式与二进制静态资源。
- JS 建议默认勾选:安全测试和前端联调常需要它定位隐藏 API、sign/token 算法、source map 和动态资源;只在资源密集站点出现明显噪声时临时关闭。
- 「自定义后缀」可填
php, asp, aspx 等(逗号分隔);输入 * 表示不按后缀限制(流量会非常多)。
- 抓包和拦截共用过滤条件:抓包可保留上述默认组合;开启拦截时,为避免主 HTML/JS/XML 也被暂停导致整页发白,建议缩小目标 Host,并优先只拦截 XHR/Fetch + WebSocket。
- 智能代理分流器(社区版可用):位于「抓包类型/后缀」下方,默认收起。上游代理预设使用与模型选择器一致的自绘下拉菜单,选择后会自动收起。
- 按站点规则将命中的浏览器请求转发到指定上游代理(如 Burp / Yakit 监听端口),未命中仍走原有网络路径。
- Firefox:兼容模式仅处理命中规则的请求;接管模式由扩展接管代理决策,未命中直连。
- 修改上游代理后需点保存;留空或
* 表示全部站点。首次启用有证书提醒——需信任 Burp/Yakit 根证书,否则 HTTPS 可能报错。
- 拦截开关(社区版可用):暂停匹配目标的请求,在侧栏拦截队列中改包 / 放行 / 丢弃。Chrome 可能出现「正在调试」顶部提示,属正常;Firefox 一般没有。
- 内网/自签名 HTTPS 响应体(被动监听)(仅 Chrome):部分内网 / 自签名 HTTPS 响应体可能显示不全,开启此项并刷新页面后再抓。Firefox 无此开关,常规抓包一般即可拿到完整响应体(见 §14)。
- 悬浮球:控制页面内快捷入口是否显示;主流程仍建议使用侧边栏。
常用组合:默认抓包 → XHR/Fetch + WebSocket + HTML + JS + JSON + XML;高流量降噪 → XHR/Fetch + WebSocket;精准拦截 → 缩小目标 Host + XHR/Fetch;与 Burp 同屏 → 开智能代理分流并按站点转发。
3.1 鹰眼浏览器自动化 MCP(PRO)
权限说明:此功能带有 PRO 标识。未激活用户可查看教程和下载 Server;激活或试用期间可开启扩展桥接并调用 MCP 工具。
这个名称比“浏览器控制 MCP”更准确:它不仅能点击和输入,还能导航、读取页面快照、截图,以及调用鹰眼抓包与证据检查工具。MCP Server 不是 AI 模型,也不会自己聊天;它是把鹰眼能力暴露给 Codex、Cursor、Claude Code 等 MCP Host / Agent 的本地工具桥。
工作原理
Agent / MCP Host
→ hawkeye-mcp-server.mjs
→ 127.0.0.1:19016
→ 鹰眼扩展
→ 开启开关时绑定的真实浏览器标签页
第一步:准备环境并下载
- 安装 Node.js 18 或更高版本,在终端运行
node -v 确认能输出版本号。
- 在鹰眼弹窗的“基础设置”中点击下载 MCP Server。下载的
hawkeye-mcp-server.mjs 是单文件、零第三方依赖的 Server,无需 npm install、无需再拷贝其它模块。鹰眼会自动记录浏览器返回的真实下载路径。
- 下载后点击复制通用配置;配置中的
args 会直接填入真实路径,不需要手工替换占位符。
第二步:在 Agent 中配置
stdio 方式(推荐):把“复制通用配置”生成的内容加到 Agent 的 MCP 配置中。下方占位路径仅是文档格式示例;弹窗实际复制的内容会使用已记录的真实绝对路径。使用 stdio 时,不需要手工运行 Server,Agent 会自动启动它。
{
"mcpServers": {
"hx0-hawkeye": {
"command": "node",
"args": [
"/ABSOLUTE/PATH/hawkeye-mcp-server.mjs",
"--port", "19016"
]
}
}
}
- Claude Code / Cursor / LM Studio:使用上面的
mcpServers 格式,放入各自的 MCP 配置页或配置文件。
- Codex:配置
[mcp_servers.hx0-hawkeye],command = "node",args = ["绝对路径", "--port", "19016"]。
- OpenCode:新建
type: "local" 的 MCP,command 数组依次填 node、文件绝对路径、--port、19016。
- OpenClaw / Hermes Agent / TeleAgent / DeepSeek Harness / DeepSentry / 自研 Agent:选择 local/stdio MCP,填写同样的
command 和 args。不对产品名做白名单,任何符合 MCP 规范的 Host 都可接入。
- DeepSeek / Ollama:它们是模型/API 或本地推理运行时,不是鹰眼要连接的 MCP Host。请先在 OpenCode、Hermes、LM Studio、DeepSentry 等 Host 中选择 DeepSeek/Ollama 模型,再将鹰眼 MCP 添加给该 Host。
Codex TOML 示例(也可直接用弹窗复制出的真实路径):
[mcp_servers.hx0-hawkeye]
command = "node"
args = ["/ABSOLUTE/PATH/hawkeye-mcp-server.mjs", "--port", "19016"]
只支持 URL 的 Host:先在终端运行 node "/绝对路径/hawkeye-mcp-server.mjs" --port 19016,再把 Host 配置到 http://127.0.0.1:19016/mcp(Streamable HTTP);旧版 Host 可用 http://127.0.0.1:19016/sse。
第三步:连接并验证
- 保存 MCP 配置并重启 Agent。
- 在浏览器打开一个普通
http:// 或 https:// 目标页,再打开鹰眼弹窗开启此开关。开关会绑定当前标签页。
- 状态显示“MCP Server 已连接”后,向 Agent 发送:
使用 hx0-hawkeye 打开 https://example.com,读取页面标题并截图。
51 个工具怎么用
- 浏览器与联网研究(31 个):采用“可访问性快照 + 稳定定位优先,视觉按需”的工作方式。除导航、表单、iframe/Shadow DOM、截图、原生下载、响应式视口和授权的一方验证码辅助外,
browser_security 会返回结构化 TLS/证书证据,browser_search、browser_fetch、browser_research 分别负责快速检索、已知 URL 取证和有预算的多来源研究。第三方反机器人挑战仍交由用户人工处理。
- 抓包与安全证据(20 个):可启停抓包、读取历史/单条记录、生成变异、重放与受控 fuzz、对比响应、管理 Scope/findings、调用本地编解码与自动探测、运行页面脚本、扫描敏感信息/暗链及处理拦截队列。
授权测试步骤:先调用 hawkeye_scope 的 set 动作,填写已获授权主机、设置 acknowledgeAuthorization: true。请求重放只允许 Scope 内主机;只有显式开启 fuzzingEnabled 后才可 fuzz,每次最多 12 个请求。详细参数见扩展目录中的 MCP-INTEGRATION.md。
可信键鼠输入、全屏与 userActivation
- Chrome 优先通过 CDP
Input.dispatchKeyEvent / Input.dispatchMouseEvent 分发可信输入;Firefox 在受支持的桌面环境中,对全屏等受保护操作会走本机原生键鼠中继回退。
- 页面输入焦点会在按键前校正,避免
F 被按钮、输入框或旧焦点吞掉。对 B 站等站点,可直接请求 Agent “播放并按 F 进入全屏”。
navigator.userActivation.isActive 是瞬时状态,全屏 API 成功后可能已被消耗,因此工具返回后再查看它为 false 不能单独判定失败。应结合工具返回的 eventEvidence.isTrusted / isActive、userActivationObserved 以及 document.fullscreenElement 的实际结果判断。
截图给模型看,也可保存本地证据
不传新参数时与旧版完全相同:只向模型返回图片,不会写盘。需要 WriteUp、取证或报告图片时,调用:
{
"save_to_file": true,
"file_path": "/absolute/path/evidence.png",
"overwrite": false
}
- 绝对路径按指定位置保存;相对路径、空路径或只给
save_to_file 时,保存到 HAWKEYE_SCREENSHOT_DIR 指定目录,未配置则使用当前工作目录下 screenshots/,并自动生成安全文件名。
- 目录不存在时自动创建;默认不覆盖同名文件。成功返回
saved_to、file_path、file_bytes 和绝对路径。
- 权限或磁盘错误不会吞掉已生成的图片:模型仍能看图,text 会提示“截图已生成但保存失败”。
状态与故障排查
- PRO:需处于有效试用期或已完成授权激活。
- 等待本地 MCP Server:开关已开,但 Agent 尚未启动 Server;检查 Agent 是否已重启、文件路径和两端端口是否一致。
- MCP 桥接不可用:到浏览器扩展管理页重新加载鹰眼,然后重新打开弹窗。
- 新版 Chrome 本地网络权限:首次开启时,若浏览器弹出“查找并连接本地网络设备”类似询问,请选择允许;建议先启动 Agent / Server,再点击开关。
- 复制配置提示尚未记录路径:先在当前版本中点击一次“下载 MCP Server”,待显示已记录路径后再复制。
- 下载无文件:查看浏览器下载记录是否拦截
.mjs;重新加载扩展后再点一次,按钮下方会给出明确成功或失败信息。
node 找不到:安装 Node.js 18+,并完全重启 Agent,让它重新读取系统 PATH。
- 端口占用:同时修改弹窗端口与 Agent 配置中的
--port。
- 截图失败:视口截图时被绑定页需保持为当前窗口的活动标签页;Chromium 整页/元素截图若提示调试器被占用,请先关闭该页 DevTools 或其他调试连接。
chrome://、about: 和扩展商店等内部页不可操作。
安全提示:Server 仅监听 127.0.0.1,但 Agent 会真实点击、输入和导航。仅在自有或明确授权系统中使用,完成后关闭开关。
更高效的浏览器操作:快照 → 定位 → 操作 → 核验
参考 Playwright MCP 的结构化快照与明确引用方式,优先让模型读取页面结构,仅在图片、Canvas 或布局判断需要时截图。每次操作都用工具回执和页面结果确认是否达到目标。
- 先读需要的区域:第一次调用
browser_snapshot;默认只读视口内的紧凑快照。已知要找的文字时用 browser_find,局部区域用 focus;需要视口外内容时再设 viewport_only=false。大结果只带 page_token 续读同一份缓存,不要为了翻页再执行一次写操作。
- 用当前引用定位:使用最近快照返回的
ref,不要编造引用。页面导航、列表刷新、切换标签后重新获取;旧引用失效时先定位新目标,不盲目重复点击。
- 减少无效往返:多个已知字段可用
browser_fill_form 一次填写;等待文字、URL 或元素状态时用 browser_wait_for。需要追踪变化时用 browser_snapshot 的 diff=true,需要坐标时才开 boxes。
- 按操作顺序执行:同一标签页的导航、点击、输入和提交按先后执行;互不依赖的只读检查才适合有限并发。工具的只读/副作用标注帮助 Host 判断,但不能替代你的实际授权。
取消、繁忙与断线:Host 发出取消后,服务端会结束等待并通知扩展停止后续工作。已提交的浏览器操作无法回滚;超时或断线后,先重新读取页面状态再决定是否重试。若提示请求过多,等待现有调用完成再继续。升级扩展后请重新下载 MCP Server 并重启 Host,保持两端一致。
稳定分页与能力裁剪:工具回执里的 context.next_page_token 只指向这一次不可变结果,两分钟内有效,且绑定当前 MCP 会话。续页时只发送 page_token,不要混用旧的数字 cursor,也不要改 focus 或其他参数,否则会被拒绝而不是悄悄拼上另一份快照。可用 --profile core 或 --caps 按能力缩减工具目录;stdio 在慢客户端或超大输出时会限流,必要时断开该传输,HTTP 会话仍可继续。
3.2 MCP、Agent 分别做什么?与主流 Browser MCP 怎么选?
先把三个概念分开
| 名称 | 它是什么 | 是否需要额外安装/配置 | 适合场景 |
| 鹰眼 MCP | 本地工具 Server;把真实浏览器操作、抓包、拦截、重放与证据能力提供给外部 AI Host,不包含模型 | Node.js 18+ + 单文件 Server + 在 Codex/Cursor/Claude Code 等 Host 中添加 MCP 配置 | 已在外部 Agent 工作,希望它调用鹰眼 |
| 内置 Agent 模式 | 鹰眼侧栏中的多轮对话与自主规划界面;直接调用鹰眼工具运行时 | 不用配置第三方 MCP Host;需有效试用/PRO,并在高级设置配置 Base URL、API Key(如需)和 Model | 想在扩展内直接说人话完成浏览、分析、验证和报告 |
| AI 任务 | 有 Scope、方向、Skills、安全门禁和结构化报告的可重复测试流水线 | 与内置 Agent 共用 AI 配置;需任务级目标、Scope 与 Skills 选择 | 授权安全测试、CTF、批量证据与稳定报告 |
内置 Agent 安装与使用
- 进入高级设置 → AI 分析设置,选提供商并填写 Base URL、API Key 和 Model;建议先用一次普通 AI 分析验证连通性。
- 打开要操作的 HTTP(S) 页面;如要研判流量,先开抓包并设置精确目标 Host。
- 打开抓包界面 → Agent 模式,新建对话,选择安全级别和需要的 Skills,再输入目标,例如:
打开当前站点的登录页,只观察请求并告诉我鉴权流程,不提交数据。
- 涉及发送数据、下载、重放、变异或对外部系统产生影响的步骤时,阅读工具回执与确认提示;不要让内置 Agent 与外部 MCP Agent 同时操作同一标签页。
Agent 与 MCP 智能搜索
browser_search 的 query 保留主问题,queries 添加不同证据方向;includeDomains 匹配任一所列域名。自动引擎根据查询语言选择来源,合并重复链接;同一扩展内研究标签页最多并发 3 个,取消会停止后续阶段并清理临时页。
需要核验时设置 maxFetches 或使用 browser_research 阅读正文。研究优先覆盖不同站点;验证码页不计为有效证据。排名分数只表示检索相关度,结果受阻、缓存过期或输出截断时会标注;应补充查询或读取具体来源后再得出结论。
当选项表示“提供信息”或“自定义输入”时,选择后会关闭弹窗并等待你在输入框填写实际内容;等待期间不会自动再次询问。相同工具连续返回相同内容或错误时会先纠偏,再明确暂停,保留未完成状态。
目标模式:暂停、恢复与完成
- 目标会持续保留,直到 Agent 明确确认整个目标达成;单轮回复结束、下载进入队列或部分步骤完成不会自动清除目标。
- 点击目标栏的暂停保存执行进度;点击恢复继续原目标,无需先发送排队消息。已确认的操作会跳过,结果不确定的提交需要先核验。
- 缺少信息或达到本轮执行上限时,目标保留为受阻状态;可直接补充信息或回复“继续”。修改目标会先停止旧任务;删除目标会停止执行并保留对话与排队输入。
与主流浏览器 MCP 的定位对比
对比依据各项目截至 2026-08-30 的公开官方文档;项目会继续演进,最新细节以文末官方链接为准。
| 项目 | 浏览器/会话 | 主要强项 | 抓包、拦截与安全工作台 | 更适合 |
| Hx0 HawkEye MCP | Chrome + Firefox;直接绑定用户当前已登录真实标签页 | 可访问性快照 + 按需视觉、可信输入、网页操作与安全证据同一链路 | 内置请求头/体、响应、WebSocket、拦截改包/放行/丢弃、重放、变异/fuzz、敏感/暗链、Scope/findings 与截图落盘 | 浏览器内授权安全测试、取证、CTF、抓包驱动分析,特别是 Firefox 真实会话 |
| Microsoft Playwright MCP | 可启动 Chrome/Firefox/WebKit/Edge;可持久或隔离 profile;官方扩展连接现有浏览器时主要为 Chrome/Edge | 基于可访问性树的稳定定位、跨浏览器自动化、表单、网络 mock、跟踪、测试与 CI | 有通用网络与自动化能力,但官方定位不是鹰眼这类常驻抓包/拦截/重放/fuzz 安全工作台 | 跨浏览器功能测试、隔离会话、测试代码生成和 CI |
| Chrome DevTools MCP | Chrome / Chrome for Testing;可连接正在运行的 Chrome | DevTools/Puppeteer 级页面调试、Console、Network、性能 trace 与性能建议 | 强于 Chrome 网络调试与性能证据,但不提供鹰眼式的跨 Chrome/Firefox 拦截队列、安全重放/fuzz 与敏感证据工作流 | Chrome 前端调试、性能分析、Console/Network 问题定位 |
| Browser MCP | Chrome 扩展 + 本地 MCP Server;连接当前已登录标签页 | 本地、低摩擦的导航、点击、表单填写、快照与截图 | 官方文档主要是通用浏览器自动化,未列出鹰眼这类完整抓包、拦截改包、重放/fuzz、安全证据和 Firefox 版链路 | 日常已登录 Chrome 页面的通用 Agent 操作 |
选型建议:跨浏览器隔离自动化与 CI 选 Playwright MCP;Chrome 性能与 DevTools 深度调试选 Chrome DevTools MCP;简单复用已登录 Chrome 做日常操作可选 Browser MCP;需要抓包 + 拦截 + 改包 + 重放 + 安全证据 + Chrome/Firefox 同一体验时选 HawkEye。它们也可按阶段组合,不必二选一。
官方资料:Playwright MCP · Chrome DevTools MCP · Browser MCP。
4. 高级设置
控制界面语言、页面脚本、AI、Skills、搜索深度、敏感信息、暗链与 Payload 编码等。带专业版标注的项需激活后可用。
- 语言:界面中英文切换;影响侧栏、弹窗及 AI 提示语。
- 抓包界面快捷键:默认
Ctrl+H;Mac 上是 Control+H(⌃H),不是 Command,也不是 Option。网页获得焦点时即可使用,不必先点开弹窗或主面板。
- Chrome:打开或收起抓包侧栏。Chrome 不允许扩展自行改快捷键;高级设置里会显示当前组合,按钮为「去设置」,会打开
chrome://extensions/shortcuts。在列表中找到「打开或收起 Hx0 鹰眼抓包界面」后改绑,改完以该页显示的组合为准。
- Firefox:打开或收起页面内抓包浮窗(不是直接打开原生侧边栏)。浮窗里可点「收起到侧边栏」切换;再按一次同一快捷键关闭。可在本页点「录制」后按下新组合,或「恢复默认」。
- 页面脚本(专业版):总开关、启用数量、脚本工作台入口与浏览器授权状态。具体使用见 §4.2。
- AI 分析设置(专业版):
- 提供商:OpenAI、DeepSeek、Anthropic、Kimi、智谱 GLM、小米 MiMo、硅基流动、本地 (LM Studio)与自定义。每个提供商的 Base URL、API Key、Model 和模型能力独立保存。
- Base URL 自动识别:程序从域名和路径判断提供商与端点类型,不再设置“Coding Plan / Token 资源包 / 按量计费”选择按钮。智谱标准 API / Token 资源包使用
https://open.bigmodel.cn/api/paas/v4,Coding Plan 使用 https://open.bigmodel.cn/api/coding/paas/v4;小米按量计费使用 https://api.xiaomimimo.com/v1,Token Plan 请填套餐页给出的区域端点(如中国区 https://token-plan-cn.xiaomimimo.com/v1)。已知提供商与 URL 串号时会自动归位,并修复旧版留下的智谱/小米错位配置。
- 当前模型候选:OpenAI 默认候选更新为
gpt-6-astra(GPT-6 Astra),保留 GPT-5.6 可选;DeepSeek 新增 deepseek-v4.1-flash-expires-on-0910,支持文字与图片输入。已保存的模型选择不会被自动替换。GPT-6 Astra 的深度思考开关分别使用 max / low;带版本和日期后缀的 DeepSeek V4 型号也会正确传递思考开关。
- 多模态图片输入:选中内置能力表里的已知视觉模型时会自动勾选,例如
glm-5.3-flash、deepseek-v4.1-flash-expires-on-0910、deepseek-v4-flash-vision-exp、gpt-6-astra、claude-opus-5、kimi-k3/kimi-k2.6 和 mimo-v2.5;未知或自定义模型默认不勾选,可人工确认。手动修改会保留,直到切换模型后重新按能力表判断。mimo-v2.5-pro 不默认勾选图片输入。
- 上下文窗口:下拉项的单位是 token,不是 KB/MB;
128K 即约 131072 tokens,1M 即 1000000 tokens。选“自定义”后填模型官方公布的 token 数,留空则按模型自动识别。
- 配置 Base URL、API Key(如需要)与 Model;提供商切换、输入、模型选择和相关开关都会自动保存,无需再点“保存AI设置”。
- AI 自动脱敏后再发送默认开启,作用于 AI 分析与 AI 任务全流程;关闭后按原文发送。若 Cookie/鉴权头被替换导致 AI 误判未登录或测试跑偏,可关闭此项(仅限已授权环境)。
- AI 技能(Skills)(专业版,位于 AI 分析设置下方):
- 内置知识库(HawkEye-native):预装
Hx0 渗透测试知识库(19 个子模块)与 Hx0 CTF 知识库(28 个子模块,含 Web/Misc 与 AI 赛道)。全部在扩展内用 capture/replay/mutate/codec/crypto.logic.analyze 等工具验证,不要求 sqlmap/curl 等外部 CLI。中英文子模块一一对应;正文存本机,注入时随你配置的模型 Endpoint 发送。
- 子模块管理:展开知识库可勾选/取消子模块;点编辑可改 markdown(覆盖存
chrome.storage.local,不影响安装包默认)。完整模块清单见 §16。
- 测试方向联动:AI 任务选
自定义方向 时会自动勾选对应专项(如 SQLi → injection-attacks,文件上传 → file-upload-ssrf-lfi / CTF file-upload);AI自主判断 默认注入 hawkeye-runtime + 方法论 + 产品指纹等。任务面板每个主 Skill 右侧有 智能启用 开关(悬停可看说明):开启后运行中可按证据动态追加该库子模块(日志「任务中途 Skills 动态注入」);关闭则仅注入你手动勾选的子模块。
- 扩展专题:渗透侧
js-reverse(sign/token/前端加密)、ai-site-workflow(AI 站点八步流水线)、ai-llm-security;CTF 侧 misc-encoding(猪圈/Bacon/套娃等)、js-reverse、prompt-injection 与 ctf-ai-* 四模块(间接 RAG / Agent·Tool / 输出链等)。
- AI 生成技能(专业版):在 AI 技能区点击
AI 生成技能(需已配置 AI 接口)。用自然语言描述测试方法论或漏洞类型,可生成单个技能或技能集合(2–6 个相关模块);生成内容对齐 Hx0 内置工具链(replay/mutate/capture 等),生成后可编辑、导出、重新生成。保存目标:独立 Skill、渗透/CTF 内置库子模块、含 references 的新 Skill,或追加到已有导入 Skill。详见 §16。
- Agent 主动沉淀:只有用户在 Agent 对话中明确说“请记住这次流程 / 记住这个错误 / 保存为 Skill”等命令时,才会把本次已验证步骤与教训生成独立 Skill;成功或失败都会给出真实回执。新 Skill 标记为
Agent 沉淀,可在此查看、编辑、停用或删除。
- 导入外部技能:单文件或文件夹批量导入;格式与编写要求见 §16。导入后可启用/停用/删除(最多 32 个自定义技能)。
- 全局允许列表:高级设置中勾选的主 Skill / 子模块,是 AI 任务与 Agent 可使用的上限;未勾选的 Skill 不会被智能匹配绕过。AI 任务默认启用 Skills 只控制 AI 任务页,不会为 Agent 模式开启 Skills。任务内用法见 §10。
- Payload 智能编码:对发出的 payload 中指定字符做 URL 编码,减少特殊字符截断(可选)。
- 列表搜索 · 全量深度搜索(社区版可用):勾选后侧栏搜索扫描完整请求/响应正文;数据量大时更耗性能。
- 敏感信息匹配:
- 总开关 + 多条内置规则(证件、手机、银行卡、JWT/Shiro 指纹、IP、域名、CTF Flag 等)——社区版可用。
- 内置规则采用正则初筛 + 二次校验:身份证校验位、银行卡 Luhn、JWT 三段结构、邮箱/域名/IPv4 上下文过滤、Shiro 路径/Cookie 级特征、CTF flag 前缀白名单等,降低 JS 域名片段、版本号、资源文件名等误报。
- IPv4 / IPv6 / 域名规则默认关闭,可在高级设置按需开启(开启后同样走二次校验)。
- 「管理自定义正则」「管理关键词库」及批量导入/导出、一键清空均为社区版可用,详见 §4.1。
- 规则颜色用于列表圆点与详情高亮。
- 暗链与静态威胁检测(专业版):内置只读规则(CSS 隐匿、移出视区、嵌套资源、动态原文、硬编码 IP 等);常见 CDN/统计域与高信誉顶级域白名单降低误报;单独「变色龙配色」或无障碍
sr-only 类不再单独告警。侧栏使用见 §9。
模型刷新与配置切换:刷新模型列表只更新可选项,保留你已填写的模型(包括旧型号、私有部署名),不会因推荐项改变而自动升级。切换提供商、Base URL 或密钥时,旧的列表请求会取消,迟到的结果不会覆盖新配置。切换到另一提供商使用该提供商自己的密钥,首次配置需重新填写。列表加载失败时仍可手工填写模型名。Base URL 请填写完整 HTTP(S) 地址,API Key 放在独立输入框中;不要把用户名、密码或 #片段写入 URL。
流式输出与能力契约:后台已按提供商能力发流式请求,并记录首字延迟、总耗时、token 与重试次数。429/5xx 会遵守 Retry-After 且不超过总时间预算;不完整的流不会付费重试。原生工具、结构化输出、图片和思考字段按当前模型能力启停:接口明确不支持时不会静默降级成“已完成”。取消会中止未发出的重试。
4.1 自定义正则与关键词:批量导入、导出与一键清空
入口:高级设置 → 敏感信息匹配 → 管理自定义正则 或 管理关键词库。内置规则、自定义正则、关键词库和批量导入导出均为社区版能力。
- 添加规则:填写规则名称、正则或关键词、颜色标记后,点蓝色「添加规则」即可。
- 一键清空:在「添加规则」右侧的红色按钮,用于清空当前弹窗内这一份列表(自定义正则与关键词库分别清空);操作前有确认提示。
- 下载导入模板:下载带表头的示例表格,照着列名填写即可。模板里紧跟表头的那一行是样例,导入时会自动跳过,一般不用改。
- 批量导入:选择你编辑好的表格文件。自定义正则三列表头须为:
name、pattern、color(颜色多为 # 开头的六位色值)。关键词库三列为:name、keywords、color。
- 批量导出:把当前列表中的规则导出为表格,便于备份或换设备迁移。
- 导入结果:完成后会提示成功、跳过、无效的大致条数;若与内置规则颜色撞车,扩展会自动微调色值,尽量减少重复。
Firefox 用户 · 批量导入:在 Firefox 里,系统「选择文件」并点「打开」后,工具栏上的主弹窗常会自己关掉,因此批量导入会额外打开一个小窗口让你选文件。按窗口说明操作,看到成功提示后,再点一次工具栏里的扩展图标即可回到主弹窗查看列表。该小窗口的说明文字会跟随你在高级设置里选的界面语言。
4.2 页面脚本注入(专业版)
入口:弹窗 高级设置 → 页面脚本 查看总开关和状态;点击 打开脚本工作台 后进入侧栏顶部 脚本 页签。工作台提供 新建、AI 创建、导入、导出;在历史列表选中流量后,也可右键 从流量 AI 创建页面脚本。简单理解:以前要在 F12 Console 反复粘贴 JS,现在可保存为脚本库,一键对当前页或匹配域名执行。
- 第 1 步:新建脚本:打开
脚本 页签,点 新建 或 AI 创建,给脚本起一个能看懂的名字,例如“给当前页面加调试标记”。
- 第 2 步:写脚本代码:在 脚本代码 区输入 JS。代码框支持行号、关键词搜索、一键格式化和基础语法检查;不确定哪里写错时,先点
语法检查。
- 第 3 步:选择运行方式:新手建议保持
页面加载后(推荐)、安全隔离环境(推荐)、手动执行。这组配置最稳,不容易影响网页正常加载。
- 第 4 步:手动执行:先点
保存,再点 注入当前页。仅支持 HTTP/HTTPS 网页,扩展页、浏览器内部页和非网页 URL 会被阻止并提示。
- 第 5 步:确认没问题后再自动注入:如果脚本已经在目标站点验证可用,可把
注入范围 改为 匹配域名自动注入,规则里填 *.example.com、example.com 或完整 URL。所有网页自动注入影响最大,新手不建议一开始使用。
- 导入油猴脚本:直接导入
.user.js 或粘贴带 // ==UserScript== 的代码即可。扩展会自动识别 @name、@match、@include、@require、@grant、@run-at 和 @noframes;@require 依赖会尽量通过后台请求加载,减少目标网页 CORS/混合内容拦截。若脚本依赖 jQuery 且外部 CDN 不可访问,会自动启用内置的轻量 jQuery 兼容层,满足常见选择器、事件和 DOM 修改用法。
- 验证码脚本常用设置:验证码或登录框如果在 iframe 里,请开启
iframe 也注入。油猴脚本默认会进入匹配的子框架;只有脚本写了 @noframes 时才不进 iframe。
- AI 创建与优化:
AI 创建 适合「还没有具体包、只想先搭个通用助手」的空手起步;从流量 AI 创建(详情底栏 AI脚本、行操作列或勾选多条)适合「已经在抓包里看到关键接口/页面行为,要把真实 URL、参数名、响应字段、鉴权头写进脚本」——后者成功率远高于凭空描述。保存后可用 AI 优化 改进结构、错误处理或接入 GM_hx0CallTool(系统会自动递增 @version patch 位并在描述中追加优化记录)。务必先 注入当前页 验证,再开启自动注入。
- GM 脚本菜单:调用
GM_registerMenuCommand 的脚本,在侧栏展开条目后会自动读取菜单(一般无需先切到匹配页或手动刷新页面)。若浏览器里已有匹配 @match 的已打开标签,会优先从该页探测/注入;当前侧栏页不匹配时,菜单仍可能出现,并提示「菜单来自匹配页面标签 #xx」。若仍为空,再点 注入并刷新菜单。
- 几个选项怎么理解:
页面加载后(推荐)表示等页面基本加载完再跑脚本;DOM 就绪后更早一些;页面刚开始加载最早,适合拦截/改写早期逻辑。安全隔离环境(推荐)更稳;只有脚本必须修改页面自己的 window 全局对象时,才选 页面主环境(可改 window)。
- 授权与浏览器差异:Chrome 安装清单已含
userScripts;若仍提示不可用,请在 chrome://extensions → 本扩展「详细信息」中手动开启「允许用户脚本」(浏览器安全策略要求,扩展无法代开)。Firefox 将 userScripts 列为可选权限,按工作台引导完成授权;更新扩展后请在 about:debugging 重新加载一次再试注入。
- 导入导出:脚本工作台支持 JSON 导入/导出,适合备份或迁移脚本库。请只导入可信脚本,并仅在你有授权的站点上使用自动注入。
- 调用鹰眼通用能力:自写脚本可通过
GM_hx0CallTool 复用抓包、重放、敏感/暗链扫描、编解码等后台能力,详见 §4.3。
4.3 自写页面脚本与调用插件通用能力(专业版)
本节说明:如何在页面脚本里调用鹰眼已实现的「工具运行时」,而不是在脚本里重复造轮子(手写 fetch 重放、正则扫敏感信息、自己拼 Fuzz 框架等)。AI 任务台与页面脚本共用同一套工具 ID,区别仅在于:AI 由任务台 JSON 调度,你的脚本用 JavaScript 直接调用。
前置条件
- 专业版 + 高级设置里页面脚本总开关已开启(见 §4.2)。
- 脚本元数据声明
// @grant GM_hx0CallTool(扩展也会根据代码自动补全 grant)。
- 需要读历史抓包、
recordId 或联合分析时,请先在弹窗开启抓包并在目标页产生过流量。
- 调用
ai.complete 前,请在高级设置 → AI 分析设置 配置 API Key / 模型;可先 settings.read 判断 aiConfigured。
- 仅在已授权的测试、CTF 靶场或自有环境中使用;勿对未授权站点做攻击性自动化。
最小可用模板
// ==UserScript==
// @name 我的鹰眼助手
// @match *://*/*
// @grant GM_hx0CallTool
// @grant GM_addStyle
// @run-at document-idle
// ==/UserScript==
(function () {
'use strict';
async function call(tool, input) {
if (typeof GM_hx0CallTool !== 'function') {
throw new Error('请在 Hx0 鹰眼页面脚本环境中运行');
}
return GM_hx0CallTool(tool, input || {});
}
call('settings.read', {}).then(function (cfg) {
console.log('语言', cfg && cfg.uiLanguage, 'AI已配置', cfg && cfg.aiConfigured);
});
})();
等价写法:Hx0.callTool('replay.request', input) 与 GM_hx0CallTool 相同。调用走扩展后台,带当前标签页上下文;默认超时约 120 秒,失败时 Promise 会 reject 并带 error 字段。
扩展预置 3 条内置用户脚本(页面情报 / 智能解码 / 智能渗透),可直接启用或复制改写成自己的脚本。功能说明、默认注入方式与操作步骤见 §4.4。
工具 API 一览(页面脚本 / AI 任务共用)
常用写法示例
1
扫描当前页敏感信息与暗链
var html = document.documentElement.outerHTML.slice(0, 120000);
var payload = { url: location.href, html: html, responseBody: html };
Promise.all([
GM_hx0CallTool('sensitive.scan', payload),
GM_hx0CallTool('darklink.scan', Object.assign({ use_dom: true }, payload))
]).then(function (rows) {
console.log('敏感', rows[0] && rows[0].items);
console.log('暗链', rows[1] && rows[1].threats);
});
2
读同 host 最近抓包
GM_hx0CallTool('capture.history', { targetHost: location.hostname, limit: 20 })
.then(function (res) { console.log((res && res.rows) || []); });
3
重放(需先有 raw 报文或从侧栏复制)
GM_hx0CallTool('replay.request', {
rawRequest: 'GET /api?id=1 HTTP/1.1\\nHost: example.com\\n\\n',
url: 'https://example.com/api?id=1'
}).then(function (res) { console.log(res && res.status, res && res.responseRaw); });
4
编解码 / 高级加解密
GM_hx0CallTool('codec.transform', { action: 'jwtparse', text: 'eyJhbGciOi...' })
.then(function (res) { console.log(res && res.output); });
GM_hx0CallTool('codec.transform', {
action: 'aesdec', text: 'BASE64_CIPHERTEXT', key: '0123456789abcdef', iv: '0000000000000000', mode: 'cbc'
}).then(function (res) { console.log(res && res.output); });
5
加密逻辑研判(需 raw 报文;专业版)
GM_hx0CallTool('crypto.logic.analyze', {
rawRequest: 'POST /login HTTP/1.1\\nHost: example.com\\n\\nuser=1&sign=abc...',
parameter: 'sign', url: 'https://example.com/login', reason: 'sign 疑似前端 MD5'
}).then(function (res) { console.log(res && res.summary, res && res.steps); });
6
AI 动态文案(先 settings.read 检查 aiConfigured)
GM_hx0CallTool('ai.complete', {
prompt: '用三句话总结当前页面可能的测试入口',
context: 'URL: ' + location.href
}).then(function (res) { console.log(res && res.content); });
编写建议
- 优先 callTool:抓包、重放、敏感/暗链、编解码、Fuzz、上传/头/WS 探测一律走工具 API;页面脚本只做 DOM 采集、UI 展示与业务流程编排。
- 先 settings.read:再决定界面中英文与是否提示用户去配置 AI。
- 错误处理:
.catch(function () { return { ok: false }; }) 避免单工具失败拖垮整页;扫描类工具可能返回 skipped: true(高级设置里关闭了对应开关)。
- 世界与时机:只改 DOM/样式用
USER_SCRIPT + document-idle;要 hook 页面 window 用 MAIN + document-start(见 §4.2)。
- AI 辅助写脚本:脚本工作台「AI 生成 / 优化」已内置规范,会引导使用
GM_hx0CallTool;生成后务必在目标站手动注入验证再开自动注入。
- 与 AI 任务台关系:任务台通过 JSON
tool_calls 自动调度上表工具;你写的脚本可在用户浏览页面时同步提供情报面板、自动标注、业务辅助菜单等。Skills 知识库(§16)里的工具 ID 与上表一致,可对照编写。
调试技巧:脚本里 console.log 输出可在 DevTools Console 查看;工具返回的 error 字段会说明缺抓包、缺 recordId、AI 未配置等原因。侧栏 脚本 页签可对单条脚本点「注入当前页」快速试跑。
4.4 内置用户脚本详解(专业版)
Hx0 鹰眼自带 3 条内置页面脚本,首次安装时会写入脚本库(带「内置」标识)。入口:弹窗 → 高级设置 → 页面脚本 查看总开关;侧栏 → 脚本 页签管理单条脚本的启用、编辑、注入与同步。删除内置脚本后,下次扩展启动会自动恢复;需要最新逻辑时点 从内置同步。若你要针对某一条已抓到的接口写定制自动化,优先用详情底栏 AI脚本(§5.2),而不是在这里空手创建。
| 脚本 | 默认状态 | 注入方式 | 主要能力 |
| Hx0 页面情报助手 | 启用 | 手动执行 | 攻击面采集 + 敏感/暗链扫描 + 页面高亮 |
| Hx0 智能解码助手 | 启用 | 所有网页自动注入 | 选中文本即解码 + 哈希/加密特征识别 |
| Hx0 智能渗透助手 | 启用 | 手动执行(需 AI) | 抓包 + 源码审计 + AI 渗透分诊简报 |
① Hx0 页面情报助手
做什么:在你浏览授权目标页时,自动采集 DOM 攻击面并在右下角浮层汇总——适合人工渗透/源码审计前的快速摸底,不会自动发包攻击。
如何启动:
- 确认高级设置里页面脚本总开关已开;在脚本列表中保持该脚本启用(默认即为启用)。
- 打开目标 HTTP/HTTPS 页面 → 侧栏 脚本 → 选中「Hx0 页面情报助手」→ 点 注入当前页(或展开脚本后使用 GM 菜单)。
- 注入成功后右下角出现页面情报浮层;侧栏脚本条目展开后可见 GM 菜单 Hx0 重扫页面情报,可随时刷新扫描结果。
浮层内容(各模块默认折叠,点击标题展开):
- 概览:当前 URL、表单数、隐藏域数、链接/端点数量及敏感/暗链命中计数。
- 表单:每个
<form> 的 action、method 与字段列表(含 hidden/readonly)。
- 隐藏字段:按「高价值名称 / 疑似凭证值 / 噪声参数」打分排序,优先展示 token、csrf、redirect 等字段。
- 链接与资源:a/form/iframe/script 来源 URL,按 api/admin/upload/redirect 等路径特征排序;长 URL 可展开复制。
- 脚本/API 端点:从内联 JS 正则提取 fetch/axios/XHR/Request 等疑似 API 路径。
- 敏感信息:调用
sensitive.scan,展示规则命中明细(具体匹配片段)。
- 暗链威胁:调用
darklink.scan(use_dom: true),展示威胁类型与目标。
页面标注:扫描同时给页面上的表单加蓝色实线框、隐藏输入加橙色虚线框(悬停可看字段名/值预览),便于对照 DOM。
其它操作:浮层支持拖动、折叠/展开整面板、复制 JSON(完整 intel 结构,含 window.__HX0_SCRIPT_INTEL__ 同源数据)、关闭。界面语言跟随鹰眼 settings.read 的 UI 语言。
提示:侧栏单条抓包详情里的暗链报告仍用于深度复核与导出;本脚本侧重「当前页浏览时的一屏摘要」。
② Hx0 智能解码助手
做什么:在任意网页选中可疑字符串后,即时尝试常见编码/古典密码解码,并对 MD5/SHA、OpenSSL Salted__、摩斯、Brainfuck 等给出特征提示(不可逆哈希/密文会标明需密钥或走专业工具)。
如何启动:默认所有网页自动注入,无需手动点注入。打开任意页面后:
- 用鼠标选中 2–4000 字符的文本(过短/过长不会弹窗)。
- 松手后约 200ms 内右下角弹出智能解码面板,自动列出可读解码结果与「可能算法」提示区。
- 每条结果可单独复制,或使用 复制全部;面板可拖动,位置会记住。
- GM 菜单 Hx0 切换智能解码面板:对已选中文本重新打开/关闭面板;若不想全局监听,可在脚本工作台关闭该脚本或改为手动执行。
自动尝试的解码(节选,命中多条时按可读性/套娃深度排序展示):
- 常见编码:Hex、Base64、Base32、URL、HTML 实体、Web/JSON/JavaScript 转义(
\uXXXX、\u{...}、\xNN、%uXXXX)、Quoted-Printable、UUencode、二进制/十进制/八进制 ASCII。
- CTF 常见:摩斯、敲击码、Brainfuck、AAEncode、JSFuck、Base58/62/85/92、ROT13/凯撒爆破、Atbash、培根、仿射、维吉尼亚/Playfair/自动密钥、栅栏、列置换、多层套娃组合解码。
- 特征识别(非解密):MD5/SHA/SM3 长度、bcrypt/Argon2、PEM 密钥头、OpenSSL Salted__、高熵 Base64 密文等——会提示「不可逆」或请用侧栏高级加解密。
与重放台分工:本脚本覆盖选中即解的轻量场景;AES/DES/RSA/SM2/SM4、JWT 拆解、auto_probe 智能套娃、crypto.logic.analyze 等请用侧栏重放台编解码菜单(§6,专业版)。
③ Hx0 智能渗透助手
做什么:在已授权测试场景中,把「当前页上下文 + 同 host 鹰眼抓包 + 轻量探针 + 源码快审」交给 AI,生成证据优先的 Markdown 渗透分诊简报(不是自动 exploit,也不会代替 AI 任务台跑完整测试链)。
前置条件:
- 专业版 + 页面脚本总开关已开。
- 高级设置 → AI 分析 已配置 API Key 或本地 AI(可先
settings.read 看 aiConfigured)。
- 弹窗已开启抓包,并在目标站产生过同 host 历史流量(否则简报会提示暂无抓包记录)。
如何启动:
- 打开目标页并完成必要交互(登录、点菜单等)以产生抓包。
- 侧栏 脚本 → 选中「Hx0 智能渗透助手」→ 注入当前页。
- 首次注入会显示加载态,随后展示 AI 渲染后的简报;GM 菜单 Hx0 刷新智能渗透分析 可重新拉取抓包并分析。
AI 输入证据(脚本自动拼装,无需手填):
- 页面:URL、标题、表单数、高价值 hidden 字段、内联 JS 疑似 API 端点。
- 鹰眼抓包:
capture.history 同 host 最近记录(优先与当前 URL 相关、非静态资源、含 api/upload/auth 等路径),展示 method/status/请求响应摘要。
- 源码快审:
source.audit 返回技术栈线索、审计 notes、flag/敏感 hint。
- 轻量探针(只读、默认不 fuzz):
header.probe、ws.probe;页面存在上传面时附加 upload.probe(execute: false)。
简报结构(固定四段,语言跟随鹰眼 UI 设置):
- 已确认事实:表格列「证据 | 来源 | 安全含义」——只写可见事实。
- 高价值攻击面 Top 5:按测试 ROI 排序的入口表,含可控点、证据、置信度。
- 推荐验证队列:3–5 条低噪声测试,每条含工具/目标/动作/观察/停止条件(优先 replay、mutate、upload/header/ws 等鹰眼工具)。
- 暂不建议测试:证据不足或噪声大的线索,避免浪费时间。
其它操作:浮层可拖动、折叠、复制全文 Markdown/HTML 渲染结果、关闭。若输出被截断,可刷新重试或换输出上限更高的模型。
与 AI 任务台区别:本脚本生成一次性浏览简报;AI 任务台(§10)会按测试项自动调度 tool_calls 链并产出带证据的完整报告。二者可配合:先看简报定方向,再在任务台深度验证。
维护与二次开发:三条脚本源码均可在工作台查看/复制;更新扩展后若行为异常,先对对应内置项点 从内置同步。自改代码前建议 导出 JSON 备份;内置项删除不会永久消失,下次启动会恢复默认版本。
5. 界面术语解释(看不懂就看这里)
- 历史:已完成的请求记录;默认显示当前页面的数据包,可点「全部数据包」切换为全部域名。
- 拦截:被暂停、待你处理的请求队列;默认显示全部域名,避免漏掉跨子域 XHR 等请求。展开详情后,请求侧和已到达的响应侧都可直接编辑,再点
放行。Firefox 下还会尽量列出与当前页相关的其他 Host 资源,避免只放行主文档导致页面残缺(详见 §14)。注意:历史与拦截的默认范围不同——历史偏「当前页」,拦截偏「不漏包」;切换标签页后历史会随当前页变化,拦截队列仍保留未处理项。
- 重放台:侧栏顶栏第三个标签,进入重放工作台。日常更常见做法是在「历史」里选中记录后点行内
重放,自动带入该条请求。
- 全部数据包 / 当前页面:工具栏 scope 按钮,切换列表是“全部域名”还是“当前标签页域名”。
- Pretty:格式化后的易读视图(JSON/HTML/JS 等会美化)。
- Raw:未格式化的原始文本,中英文都叫 Raw;在详情、重放、微型 Fuzz 中 Pretty 旁边都有 Raw tab。
- Hex:十六进制视图,适合看二进制/乱码问题。
- Render:把响应当 HTML 渲染查看(安全沙箱环境)。
- 敏感信息:按规则汇总证件号、Token、IP、组件指纹等命中;在高级设置中启用后,工具栏会出现敏感信息筛选下拉。
- 侧栏工具栏(历史/拦截):类型标签、Host/方法/状态码筛选、范围按钮(全部数据包/当前页面)、排序、搜索框;另有 刷新、刷新当前网页、展开为完整页面、清空历史。拦截视图下提供 一键放行、一键丢弃(与弹窗拦截开关配合使用)。
- 展开为完整页面:在侧边栏模式下,点击后会打开独立浏览器标签页承载同一套抓包界面(历史/拦截/重放等),并尽量收起右侧 Side Panel,便于大屏对照目标页操作;在独立页里再次点击同一按钮可收回到侧边栏。AI 任务运行中切换模式可能中断任务,需先等待完成或取消。独立页浏览器标签标题为 Hx0鹰眼 - 当前视图(如「Hx0鹰眼 - 历史」),切换顶栏标签时会同步更新。
5.1 侧栏小技巧:点「请求 / 响应」标题
- 在历史列表展开某条后的左右分栏、重放工作台、以及微型 Fuzz结果详情里,「请求」「响应」两栏上方的标题区域可点击(悬停时有明显样式提示)。
- 点「请求」标题:根据当前请求原文解析并复制完整 URL 到剪贴板(含协议、Host、路径、查询串等;会尊重当前内容与智能 URL 编码设置)。成功或失败都会弹出简短提示;解析不出有效 URL 时会提示无法生成。
- 点「响应」标题(通常带状态码):将当前请求区与响应区的原始文本打包下载为 UTF-8 的
.txt 文件(文件中用「REQUEST」「RESPONSE」分段),便于存档或在其他工具里查看。
说明:此处是点击标题复制完整 URL、下载当前双栏编辑器中的请求+响应原文(分段 .txt)。与 §5.2「信息架构面板」里各栏旁的复制、底栏/行内的下载(Burp 风格导出)不是同一套逻辑。
5.2 信息架构面板(列表展开后的双栏详情)
入口:侧栏 历史 或 拦截 中,点击某行 详情 展开的区域(左请求、右响应,可切换 Pretty / Raw / Hex 等)。重放工作台、微型 Fuzz 结果详情里也有与 §5.1 相同的标题点击行为,以及各栏的 复制 按钮,下文以「历史」展开区为主说明。
- 各栏旁的「复制」(请求侧、响应侧各一个):复制当前这一侧在所选视图下展示的文本(Pretty / Raw / Hex 等)。用于把报文片段贴到笔记或其它工具;不会像 §5.1 那样只解析并复制完整 URL。
- 拦截里可直接改包:在 拦截 视图中,左侧请求与右侧已收到的响应都可以直接编辑;点
放行 后,会以当前编辑内容作为最终放行结果,适合快速验证前端分支、回包结构或容错逻辑。
- 底栏「下载」(展开区底部主按钮):与行操作列里的
下载 相同逻辑——从存储中导出该条的 Burp 风格 文本文件(文件名形如 HawkEye-<id>.txt)。与 §5.1 点击「响应」标题生成的文件(基于当前编辑器里的双栏原文、REQUEST/RESPONSE 分段)格式与数据来源可能不同;若你在详情里改过报文,优先用 §5.1 导出「所见即所得」双栏原文。
- 底栏其它入口:
收起、重放、下载、删除、格式化 JSON,以及下方四个专业版快捷按钮(详见本小节「四个专业功能按钮」)。历史列表行操作列也有 详情、下载、删除、重放、AI分析、AI脚本 等,无需先展开详情即可使用。
- 重放工作台 / 微型 Fuzz:请求、响应标题行右侧同样有
复制。响应在 Render 视图下可能无法按报文复制(会提示);在 AI结果分析 视图下,响应侧 复制 一般为复制 AI 输出文本。
行操作 vs 详情底栏(别找错按钮)
| 位置 | 有哪些 | 适合什么时候用 |
| 列表行操作列 |
详情、下载、删除、重放、AI分析、AI脚本 |
还没展开详情时快速重放、导出、删记录,或直接从行里发起 AI 分析 / 从流量生成脚本。 |
| 展开详情 · 底栏 |
收起、重放、下载、删除、格式化 JSON + 四个 Pro 按钮 |
已经打开双栏编辑器、改完包后要检测暗链、AI 分析、加密逻辑智能分析,或边看报文边生成脚本。 |
| 展开详情 · 标题行 |
各侧 加密&编码 按钮 + 作用范围下拉 + 复制 |
在 Pretty/Raw 里选中片段后做 MD5/Base64/智能套娃等就地编解码,不必先跳重放台(菜单项与 §6 一致)。 |
标题行「加密&编码」(内联编解码)
位置:展开详情后,请求与响应标题行右侧各有一组 加密&编码 按钮 + 作用范围下拉(选中文本 / 仅参数值 / 整行 URL)。这是重放台同款编解码菜单的快捷入口,适合在列表详情里看完包后直接试解码/哈希,无需先点 重放。
- 怎么用:先在对应侧切到
Raw(或 Pretty 里可选中文本),按需要选中片段 → 选作用范围 → 点 加密&编码 → 选 MD5、Base64、智能套娃解码、AES 等菜单项。结果会写回当前编辑器(或弹出配置框后再写回)。
- 作用范围:
仅参数值 与 整行 URL 仅适用于请求;响应侧请用 选中文本。与 §6 重放台规则相同。
- 和底栏四个 Pro 按钮的区别:内联编解码是确定性工具(算哈希、解 Base64);加密逻辑智能分析 是 AI 研判「这条链路可能怎么签/怎么加密」,两者可配合——先 AI 分析定位思路,再用内联菜单或重放台
codec.transform 验证。
- 和智能解码助手(§4.4)的区别:助手在任意网页选中文本即弹面板,偏浏览时的轻量解码;详情内联菜单针对当前这条 HTTP 报文,且含 AES/RSA/智能套娃等专业项。
四个专业功能按钮(详情底栏 · 专业版)
位置:侧栏 历史 或 拦截 中展开某条 详情 后,双栏编辑器底部工具栏右侧(在 格式化 JSON 之后)。四个按钮均为专业版能力;社区版点击会提示激活。结果统一显示在详情下方的报告区(可下载、可缓存;切换条目再回来会自动恢复)。
| 按钮 | 做什么 | 怎么用 | 前置条件 / 提示 |
| 检测暗链 |
对当前记录的响应体做静态威胁 / 暗链规则扫描(隐藏链接、可疑脚本、内联样式风险等),在报告区展示威胁类型、目标与「原始代码」跳转。 |
展开详情 → 点 检测暗链。无需配置 AI。有缓存时再次点击直接恢复上次暗链报告。 |
需在弹窗 高级设置 开启暗链检测总开关。当前标签页可用时引擎可结合 DOM 线索(与 darklink.scan 一致)。详见 §9。 |
| AI 分析 |
将当前记录的请求/响应摘要发给你配置的模型,生成风险等级、技术指纹、安全问题与敏感线索等 Markdown 报告。 |
点 AI 分析 → 可选填写补充说明(留空走默认)→ 开始分析。报告出现在详情下方;支持下载。与暗链报告分开展示,但同一数据包可分别缓存。 |
需 高级设置 → AI 分析设置 配置 API Key / 模型。默认会经「AI 自动脱敏」再发送(可在高级设置关闭)。详见 §9。 |
| AI脚本 |
把「刚抓到的这条包」变成可复用的页面脚本——AI 会读取真实 URL、Method、请求头/Body、响应体与 recordId,按你的意图生成油猴脚本(常含正确的 @match、字段名、JSON 路径,以及 GM_hx0CallTool 调用)。 |
在已经定位到关键流量后:展开详情 → AI脚本 → 只写「要做什么」(不必复述 URL/参数,包已在上下文里)→ 生成 → 工作台里保存并 注入当前页 验证。行操作列、勾选多条批量创建同理。 |
需专业版 页面脚本 + AI API Key。与脚本页空手 AI 创建 的区别见下方说明框。 |
| 加密逻辑智能分析 |
结合当前报文 URL/参数/Body/响应线索及同页 JS/HTML,研判 sign、token、password 等字段可能的编码、摘要、签名或混合加密链路,输出推理链与验证建议(不自动还原密钥)。 |
推荐:在请求或响应区(Raw 视图)选中可疑片段(如某个参数值)→ 点 加密逻辑智能分析 → 可选补充说明 → 开始。未选中时会对整条请求做自动范围推断。也可在重放工作台通过「加密&编码」菜单触发(同一引擎,见 §6)。 |
需 AI API Key。改包或换环境后建议重新分析。AI 任务台经 crypto.logic.analyze 走同一套流程(§10)。 |
为什么用「AI脚本」从流量生成,而不是脚本页里直接 AI 创建?
- 痛点:测试时你往往先在历史里筛出关键包(登录接口、带
sign 的 POST、返回 token 的 JSON、上传接口等),真正需要的是「针对这条接口/这次页面行为」的辅助脚本——在 DOM 上标注对应字段、从响应里提取 token 填表、一键重放变体、或调用 GM_hx0CallTool('replay.request') 做半自动验证。若只在脚本工作台空手 AI 创建,模型不知道真实参数名、响应结构、Content-Type 和鉴权头,容易猜错字段、写错 @match、造出不存在的 API,还要你手工把包内容粘贴进 prompt。
- 从流量生成的价值:鹰眼会把所选包的完整请求/响应摘要(含 URL、状态码、Burp 风格原文片段)一并交给 AI,并引导它从流量推断
@match 域名、页面该监听什么、该读哪些 JSON 字段。你只需写意图,例如:「把响应里的 accessToken 写到页面控制台并在表单旁提示」「高亮所有会提交到该 POST 路径的 input」「每次点击按钮时用 GM_hx0CallTool 重放这条请求并对比响应」。
- 典型场景:① 登录/鉴权后抓到 token 接口 → 生成「页面自动展示/复制 token」脚本;② 发现签名参数 → 生成「标注 sign 来源字段 + 调用编解码工具」脚本;③ 复杂 SPA 某 XHR → 生成「在 Network 对应 DOM 区域加标记」脚本;④ 勾选登录 + 业务两条包 → 生成串联上下文的脚本。
- 和内置脚本(§4.4)的区别:内置三条是通用能力;AI脚本 是「这一包、这一站、这一接口」的定制自动化,生成后仍要手动注入验证,满意再保存/开自动注入。
说明:暗链扫描与 AI 分析/加密逻辑分析共用同一块报告展示区域,后点的报告会替换当前可见内容,但各类结果仍分别缓存;切走再展开同一包可恢复。行操作列的 AI分析 与底栏 AI 分析 行为一致。
6. 重放工作台(最常用)
- 编辑并重放:左侧改请求,点
重放,右侧看响应变化;支持撤销/重做;请求/响应区均支持行内查找(上下箭头切换匹配)。
- 页面内重放:专业版能力。针对带 WAF 动态防御的站点,普通重放只能拿到加密/挑战页。点
页面内重放 会在浏览器中真实导航(GET)或以表单 POST(请求头 Content-Type: application/x-www-form-urlencoded)提交后执行 JS、再提取 DOM。multipart、JSON 等 POST 无法走表单路径,请用普通重放。若目标站点已打开,会复用同源 Tab 加速。
- 拦截开启也能直接发:普通
重放 与 页面内重放 走工具内白名单,即使拦截已打开,也不会再次进入拦截队列,避免自己拦住自己。
- AI 生成用例:专业版能力,且需已在弹窗高级设置中配置 AI。点击后会弹出类型与数量等选项,模型根据当前请求原文生成结构化用例列表。多数云端接口需要 API Key,本地 LM Studio 等按界面提示为准。
- 清空测试用例:用于清空除草稿外的所有测试页签,包含 AI 生成的用例以及用户手动发送出来的测试页签。
- 另存为新标签:在重放工作台窗口内新增一条并行会话(顶部重放历史标签栏),便于同窗口对比多套改包方案,并非新开浏览器标签页。
- 切换请求方法:专业版能力。位于
另存为新标签 右侧,支持 GET ↔ POST 快速转换。GET → POST 时会优先把查询串迁入 body,并自动补常见的 Content-Type / Content-Length;POST → GET 时会尽量把 application/x-www-form-urlencoded body 迁回 URL 查询串,并清理不合时宜的 Origin / Referer / Sec-Fetch-* 等浏览器上下文头。若原始请求是 JSON、multipart、签名包或自定义语义,仍建议人工复核一次。
- 加密 & 编码:社区版开放基础项,如
MD5、SM3、SHA-1、SHA-256、ROT13、Base32 / Base64 / URL / Hex 编解码;专业版再追加 SHA-512、HMAC-SHA256、Base64URL、Unicode、HTML、JSON、JWT 解析、时间戳转换、智能套娃解码(对可疑密文自动尝试多种嵌套编解码并以报告展示)、AES 加解密(CBC/ECB/CFB/OFB/CTR 等,可配 Key/IV)、DES/3DES、RSA 加解密、SM2/SM4 等国密项,以及 加密逻辑智能分析 等高级项。对称/非对称菜单项会弹出 Key、IV、模式等配置;AI 任务与页面脚本经 codec.transform 调用时也可透传 key/iv/mode/keyFormat 等字段验证假设。重放工作台工具栏在「加密&编码」旁提供当前作用域下拉框:请求 / 响应。作用范围仍可选 选中文本、仅参数值、整行 URL:其中 仅参数值 与 整行 URL 仅适用于请求;若当前作用域为响应,只支持「选中文本」(建议先在响应区切到 Raw,选中要处理的片段后再点菜单)。列表内联详情里请求/响应两侧另有各自的编解码入口,行为与上文一致。
加密逻辑智能分析怎么用:先在请求区、响应区(重放工作台内)或详情区定位疑似字段,例如 password、sign、token、timestamp、nonce,再按场景选范围:只想分析值本身用 仅参数值;想连同键名、拼接格式一起看用 选中文本;想让模型结合整条查询串、路径或路由特征判断签名位时用 整行 URL(响应作用域下请用「选中文本」)。随后打开 加密&编码 → 加密逻辑智能分析 即可。结果会优先结合当前请求的 URL、参数、请求头、Body、响应线索,以及同页 JS / HTML 中疑似加密函数、字段名、提交逻辑,帮助研判前端是否做了编码、摘要、签名或混合加密,并给出排查方向。若你改动了 Cookie、时间戳、随机数、签名参数或切换了目标环境,建议再点一次重新分析。该功能用于辅助研判与定位链路,不会自动替你还原密钥或直接改写请求。
- 标记注入点:专业版能力。选中内容后用
§...§ 包裹,给微型 Fuzz 指定注入位置。
- 目标域名切换:专业版能力。可覆盖 Target,快速验证同接口在不同环境的行为。
- 视图切换:请求/响应都支持 Pretty、Raw、Hex、Render(响应)、敏感信息;AI 结果分析为专业版能力,切换到该视图后才会向模型发起分析。分析过程中的提示语与高级设置 · 语言一致,例如英文界面下为英文提示。
7. WebSocket 抓包、重放与 Fuzz
- 抓包入口:弹窗 抓包类型/后缀 勾选
WebSocket 后,侧栏历史列表可用 WebSocket 类型筛选查看。握手会显示为 GET 101;真实帧会显示为 WS,OUT 表示浏览器发往服务器,IN 表示服务器返回浏览器。
- 域名筛选:Host 下拉与当前页面筛选支持
ws:// / wss:// URL;本地调试时 localhost、127.0.0.1 会尽量归并匹配。若只看到握手,看一下是否把类型、Host 或“当前页面/全部数据包”筛掉了。
- 详情显示:出站帧优先放在左侧请求区;入站帧优先放在右侧响应区。为避免和 HTTP 报文混淆,Raw 文本会以
WEBSOCKET OUT 或 WEBSOCKET IN 开头,并附带 connection=...。
- 帧重放:在 WebSocket 帧上点
重放 会复用现有重放工作台,而不是弹一个简单输入框。左侧编辑 payload 后点击 重放,工具会通过当前页面里仍处于 OPEN 的 WebSocket 连接发送,右侧显示下一条收到的服务器消息。
- 重放限制:WebSocket 帧重放不是重新发一次
GET /ws 握手,也不能伪造成服务器主动下发;即使从 IN 帧进入重放,实际也是把该 payload 当作客户端出站消息发送。页面刷新、连接关闭、目标页面不存在或没有活动 socket 时,会提示连接不可用。
- 微型 Fuzz:在 WebSocket 重放请求区用
§...§ 标记一个注入点后,可打开 微型 Fuzz。WS Fuzz 会串行发送每个 payload,并把下一条入站消息作为响应结果,适合 echo、订阅、聊天、游戏协议等轻量验证;页面内 Fuzz 属于 HTTP/DOM 场景,不适用于 WS。
- 拦截改包:开启拦截并命中 Host 规则后,页面 JS 创建的 WebSocket 出站/入站帧可进入帧级队列,支持编辑、放行、丢弃。
- 边界说明:当前定位是浏览器扩展内的 WebSocket 工作台,不是系统级 MITM 代理。它覆盖页面 JS 创建的 WebSocket;不透明处理原生 App、其他浏览器、扩展后台脚本或浏览器内部组件发起的连接。二进制帧会尽量以文本、Base64/Hex 视图保存和展示。
8. 微型 Fuzz(进阶)
- 版本说明:微型 Fuzz、页面内 Fuzz 与注入点工作流均为专业版能力。
- 必须有注入点:请求里要有且仅有一对
§。
- 开始 Fuzz / 页面内 Fuzz:
开始 Fuzz 为普通 HTTP 重放;页面内 Fuzz 对每个 payload 在浏览器中加载并执行 JS,提取解密后的 DOM,适用于 WAF 动态防御站点。页面内 Fuzz 与页面内重放一致:支持 GET,或 application/x-www-form-urlencoded 的 POST 表单。
- 拦截开启不自锁:
开始 Fuzz 与 页面内 Fuzz 同样走工具白名单,即使开启拦截也会直接发包,不会再次排进拦截列表。
- 先看基线:系统会先发基线请求,用于和变异请求对比。
- 重点观察三项:状态码、响应长度、响应时间。
- 辅助判断:结合
Render、敏感信息、AI结果分析 来定性。
- 视图:请求/响应同样支持 Pretty、Raw、Hex 等;复制 Raw 时得到未格式化原始文本。
9. 暗链检测 & AI 分析
单条流量上的入口:§5.2 详情底栏 检测暗链、AI 分析、加密逻辑智能分析(以及从流量创建脚本的 AI脚本)。下文说明引擎行为、报告与批量工作台。
- 版本说明:本节中的暗链检测、AI 分析、AI 结果分析、报告下载与批量 AI / 暗链工作台均为专业版能力。
- 暗链检测:对 HTML 做规则检测,识别隐藏链接/可疑脚本/内联样式风险等;在当前标签页可用时还会走 DOM 分析(与
darklink.scan 的 use_dom 一致),比纯静态字符串更准确。引擎会合并 style 标签中的类选择器、过滤常见 CDN/统计脚本、跳过版本号形态 IPv4 与单独变色龙/无障碍类误报;高级设置里可维护高信誉顶级域,同域或列表内域名会降低外链类告警。用法:历史/拦截详情底栏点 检测暗链(§5.2)。
- 页面情报助手:内置页面脚本(§4.4)在手动注入后调用
sensitive.scan / darklink.scan,在浮层展示敏感命中明细与暗链摘要;侧栏单条详情里的暗链报告仍用于深度复核与导出。
- 原始代码跳转:暗链报告里点击「原始代码」会切到 Raw 视图并定位到对应片段,便于在未格式化文本中精确查看。
- AI 分析 / AI 结果分析:会结合当前请求和对应响应包内容发给你配置的模型做解释、快速总结与风险提示。用法:详情底栏或行操作列点 AI 分析(§5.2);可选填写补充说明后执行。输出首行含风险等级,并含技术指纹小节。
- 报告封面条:会展示风险等级、生成时间、模型名、Report ID、目标域名、请求编号。
- 下载报告:AI报告和暗链报告都支持下载,方便归档和提交。
- 报告缓存:同一数据包可保留 AI 与暗链两份报告,切走再回来会自动恢复。
- 批量 AI / 批量暗链工作台:在侧栏 历史 中勾选多条记录后,点工具栏 批量AI分析 或 批量暗链检测,会在浏览器新标签页打开独立页面,逐条展示原始请求/响应(含行号与语法高亮)、模型或引擎结果,并支持汇总与导出报告。适合一次性复核多包;与单条详情里的 AI/暗链入口互补。展示用的请求首行一般为
GET /路径?查询 HTTP/2 形式(路径+查询),与发往源站的常见写法一致。复制各区块内容请点标题旁的复制按钮。
10. AI任务(专业版)
- 入口:打开侧栏,切到顶部
AI任务 页签。该功能需要专业版,并且需要先在弹窗 高级设置 → AI 分析设置 中配置模型、Base URL 和 API Key(本地模型按界面提示填写)。
- 第 1 步:选择目标:在 目标网站 中从下拉选择、手动输入,或点
使用当前站点。建议先打开并操作一次目标页面,让历史里已有登录态、表单提交或接口请求,这样 AI任务更容易覆盖到真实入口。
- 第 2 步:选择测试方向:默认使用
AI自主判断,适合不知道该测什么时让系统按页面和历史流量自动选择方向。若你只想测某一类问题,切到 自定义方向 并勾选 SQLi、XSS、命令执行、SSRF、越权、XXE、反序列化或文件上传;自定义后会按你选定的方向收敛,例如只勾 SQLi 就不会主动跑 XSS。
- 第 3 步:选择测试模式:
智能渗透 适合授权安全评估,结果会偏向漏洞、影响和修复建议;CTF夺旗 适合靶场/比赛题,目标是尽快找到 flag。两种模式目标不同,不建议混用评价标准。
- 第 4 步:填写任务背景:点开 任务背景 / 测试策略,写清授权范围、重点模块、不要碰的功能和希望的测试方式。任务启动后、发送任何测试 payload 之前,扩展会先用 AI 理解这段文字并落成结构化测试范围(关键词仅作兜底):
- 留空 +
AI自主判断:按证据尽量全面发现,不硬性收窄方向。
- 硬限制:写「
仅测试 暗链」「只测 XSS」等 → 只跑对应检测(如暗链用 darklink.scan),不会再发其他漏洞族的注入 payload。
- 排除项:在 禁止/跳过 填「
禁止 SQLi」等 → 仍可自主发现其他方向,但过滤掉被禁止家族的 payload。
- 偏好提示:写「重点测登录」但未写「仅/只/禁止」→ 作排序提示,不锁死其他方向。
- 日志卡片
0. 任务范围 会显示 AI 解析结果(含来源标记 [ai] / [keyword_exclude] 等)。CTF 模式建议写题面、hint、flag 格式、附件线索和你已经试过的入口。
- 第 5 步:确认安全选项:
智能放行拦截包 建议保持开启,它会帮助低风险请求继续走完;默认同意高危测试授权(无人值守) 只建议在靶场、CTF 或你明确授权的测试环境中开启。不开启时,涉及写操作、命令执行、SSRF、上传、身份参数修改等高风险动作会暂停等待确认或被策略拦截。
- 第 6 步:配置 Skills(可选):AI 任务页提供
Skills 总开关与配置面板(需先在 §4 高级设置 启用至少一个知识库)。
- 两层配置:高级设置决定全局有哪些知识库/子模块「可用」;AI 任务面板决定本次任务实际注入哪些子模块。主开关关闭时,不会向模型注入知识库正文。
- 默认勾选:
智能渗透 模式默认只勾选 Hx0 渗透测试知识库;CTF 夺旗 模式默认只勾选 Hx0 CTF 知识库。导入的自定义技能不会默认勾选,需在任务面板手动启用。
- 手动勾选优先:你在任务面板勾选或取消的技能/子模块(含跨模式内置库、自定义技能),启动任务后会原样注入,系统不会强制移除。
- 未手动配置时的子模块推荐:
智能渗透 + AI自主判断 时默认只勾选 鹰眼运行时(必读) 与 鹰眼渗透方法论;自定义方向 勾选具体漏洞类型时,会同步对应专项子模块。手动勾选后不会被自动改写。
- 切换模式或测试方向:仅在你未手动配置任务级 Skills 时,才会按新模式重置默认内置库;已手动配置则保持不变(仍会与高级设置中的全局启用列表对齐)。
- 智能启用(每个主 Skill 右侧):默认关闭。关闭时:任务开始时只注入你在该 Skill 下手动勾选的子模块,运行中不会为该库追加新模块。开启时:除初始注入外,任务执行中若证据指向新漏洞类型,可为该 Skill 动态追加匹配子模块(见日志「任务中途 Skills 动态注入」)。鼠标悬停「智能启用」或开关可查看 tooltip 说明。
- 内置工具链与智能脚本:模型通过 JSON
tool_calls 调度与 §4.3 相同的工具 API,在浏览器同源会话下真实发包验证,而不是只写 curl 建议。常用组合:
- 抓包与变异:
capture.history → capture.inspect / source.audit → packet.mutate → replay.request(密文/挑战页改 replay.dom)
- 编解码与加密:遇 sign/token/前端加密疑点时,可先
crypto.logic.analyze 研判链路,再用 codec.transform 验证哈希/编解码(可传 key/iv/mode),最后 packet.mutate + replay.request 闭环;若响应是密文/挑战页/WAF 动态 HTML,改用 replay.dom(与重放台「页面内重放」同源)
- 专项探测:
upload.probe/upload.fuzz、header.probe/header.fuzz、ws.probe/ws.fuzz、microfuzz.run、darklink.scan 等按证据触发
- LLM 题型(CTF):识别到 Chat API 时可用
llm.history 拉取对话上下文,再用 llm.chat 多轮套话
- 智能脚本调用(可选开关):启用后还可经
script.list / script.run 调度你在 §4.2 配置的页面脚本,与内置工具互补
手动重放台里的「加密逻辑智能分析」与 AI 任务中的 crypto.logic.analyze 走同一套多轮研判流程;差别在于前者由你点菜单触发,后者由 Agent 在任务中自动调用并回填到测试胶囊。
- 第 7 步:启动任务:点击
启动AI任务。执行时顶部会显示 7 个阶段:
- 流量采集:建立目标基线。
- 资产识别:识别页面、表单、链接、JS 和接口候选。
- 攻击建模:根据当前目标选择测试入口。
- 智能调度:决定下一步测试并生成请求。
- 漏洞探测:真实发包并记录响应。
- 结果研判:判断是否形成漏洞或疑似风险。
- 报告生成:输出最终报告并可下载。
- 执行中怎么看(日志 UI):
- 左右分栏:任务运行后,主输出区左侧为
执行日志,右侧为 分析报告;中间竖向分隔条可拖拽,按需放大日志或报告。日志标题旁有 清空,可一键清除当前会话日志(不影响已生成的报告与胶囊数据)。
- 时间轴卡片流:日志不再是单调纯文本,而是时间戳 + 竖向时间轨 + 卡片。左侧显示
HH:MM:SS,右侧为带色徽章的卡片,长文本自动换行,便于扫读整轮任务脉络。
- 卡片类型(看徽章颜色/文案):
- 阶段:7 阶段进度、队列/画像/建模/调度/判定等流水线节点。
- AI:模型规划、推断、自动测试内容生成、源码线索等。
- 测试:真实 HTTP 发包、payload、执行轮次、方法/路径摘要。
- 警告:跳过、待人工、保守策略、意图未落地等。
- 完成 / 错误:任务结束、Flag 命中、评级生成,或失败/取消/超时。
- 结构化字段:阶段研判、安全策略、AI 规划等卡片会解析
摘要、输入、输出、计划、安全策略、响应差异、判断、状态 等键值行(中英文键名均支持);过长字段可点「展开」查看全文。
- AI 工具调用卡片:每次
tool_calls 执行会单独成卡,显示工具名、耗时(ms)、成功/失败徽章;点击卡片头可展开查看格式化后的 input / result JSON(大段 HTML/rawRequest 等会自动截断并标注字符数)。常见条目包括 capture.history、packet.mutate、replay.request、replay.dom、codec.transform、crypto.logic.analyze、llm.chat 等。
- 测试胶囊(嵌在日志时间轴):每次真实请求除工具卡外,还会插入胶囊按钮(显示 HTTP 状态色点、方法/路径标签、状态码)。点击打开 AI 测试胶囊弹窗,可切换请求/响应的 Pretty、Raw、Hex、敏感信息等视图;支持复制、送到重放台。选中胶囊会在日志中高亮。
- Skills 动态注入:仅对任务面板中已勾选且开启「智能启用」的主 Skill 生效。运行中根据新证据追加子模块时,日志会出现
任务中途 Skills 动态注入 卡片,并列出触发原因与新增模块组——便于确认模型是否拿到了 JS 逆向、上传、LLM 等专项知识。
- 顶部指标:进度条下方可看历史包数量、候选数量、耗时与执行摘要;与日志卡片互补,适合快速判断「卡在哪一阶段」。
- 运行中补充线索:仅在任务正在执行时,工具栏会出现
补充线索。将你新观察到的信息写入后点 提交补充线索,会以带时间戳的日志条目出现,并追加到后续 AI 轮次的有效上下文末尾(不替代启动前的任务背景)。请勿粘贴真实口令;队列与单条长度有上限。
- 报告怎么看:
- 报告封面:展示报告 ID、目标域名、生成时间、请求编号和你在设置里填写的模型名称。
- 结论卡片:优先看风险等级、结论状态、漏洞点、触发参数和利用载荷。利用载荷会尽量显示实际修改的参数值,例如
stunum=2' 或 target=127.0.0.1; id。若本轮确认多项漏洞,触发参数/漏洞点可能显示「多项(见漏洞清单)」。
- 漏洞清单:智能渗透模式下,报告会按严重程度列出「漏洞清单」表格,汇总各类已确认问题;多漏洞场景不再挤在一行结论里。CTF 模式则侧重 WriteUp、利用链与复现步骤。
- 请求/响应证据:报告与下载 JSON 含
request_response_evidence,与日志中的测试胶囊、工具调用结果对应,便于人工复核与归档。
- 完整 AI 报告:展开后可看测试过程、已确认漏洞、未确认风险、请求覆盖与执行状态。
pending / waiting_confirm 表示请求尚未实际执行或等待确认,不等于漏洞证据。
- 下载报告:点击
下载报告 可归档当前结果;报告顶部的 基于报告继续测试 可带着本轮线索进入下一轮。
- 常见选择建议:
- 只想测 SQL 注入:选择
自定义方向,只勾 SQLi,确认 Skills 已选中注入相关模块。
- 只想测暗链(
AI自主判断 亦可):在任务背景写「仅测试 暗链」,日志应出现范围约束且以 darklink.scan 等静态检测为主,不应再跑 XSS/SQLi payload。
- 自主判断但别碰 SQLi:保持
AI自主判断,在 禁止/跳过 填「禁止 SQLi」——其他方向仍可测,SQLi payload 会被过滤。
- 只想测文件上传:自定义方向只勾
文件上传,确认 Skills 已选中上传/SSRF 相关模块。
- 不知道入口在哪:保持
AI自主判断,任务背景留空,避免一次注入过多知识;需要动态补模块时再为对应 Skill 打开 智能启用。
- 带登录态测试:先在浏览器正常登录目标站点,再点
使用当前站点 启动。若 AI 日志里 Cookie 变成占位符、会话分析不准,请到扩展设置关闭 AI 自动脱敏后再发送 后重试。
- 前端 sign/token/密码加密:保持
AI自主判断 或自定义方向勾选相关 Skills(如 JS 逆向、加密缺陷子模块),Agent 会优先尝试 crypto.logic.analyze + codec.transform;也可先在重放台手动跑一遍「加密逻辑智能分析」再把结论写进任务背景。
- 上传、命令执行、SSRF、越权类测试:建议确认授权范围后再开启无人值守,生产环境慎用。
- 注意事项:仅在已授权环境使用。外部模型会接收必要上下文;默认开启自动脱敏以保护 Cookie/Token,但带登录态测试时可能让 AI 丢失会话线索,可按需关闭。避免主动提交与测试无关的真实敏感数据。AI 任务会尽量低噪验证,但最终结论仍建议人工复核,特别是越权、业务逻辑、上传利用和生产环境影响评估。
10.1 Agent模式(PRO)
Agent模式仅在有效试用或专业版授权下可用。它是侧栏顶部的独立页签,与“AI任务”并列,不是 AI任务页面中的一个配置项。Agent模式适合用自然语言连续操作当前浏览器与鹰眼能力;AI任务则适合按既定范围执行结构化安全测试流水线并生成报告。
- 开始使用:先在 高级设置 → AI 分析设置 配好模型、Base URL 与 API Key,再打开侧栏顶部
Agent模式。已知模型会自动识别上下文窗口;下拉框和自定义值的单位都是 token,留空保持自动。输入目标后按 Enter 发送,Shift+Enter 换行;运行中发送键会变为停止键。
- 输入区模式开关与深度思考:输入框下方依次显示
浏览器 · HawkEye Agent、深度思考、Skills、目标 与 计划模式。深度思考按会话保存,新会话默认关闭,Agent 运行期间暂时锁定。已知提供商使用原生字段:OpenAI GPT-5 系列关闭/开启对应 reasoning_effort=none/max;DeepSeek V4 对应 thinking.type=disabled/enabled(开启时为 max);GLM-5.3(含 GLM-5.3-Flash)不能完全关闭思考,因此关闭态使用最低的 reasoning_effort=low,开启态使用 max;其他可控 GLM 使用 disabled/enabled;Claude Opus/Sonnet 5 使用 disabled/adaptive;硅基流动使用 enable_thinking。Kimi、MiMo、本地模型和自定义接口无法只凭模型名可靠判断:关闭时不额外注入思考参数并遵循接口默认,开启时尝试通用兼容字段;若后端不支持,界面会显示其真实错误。不同状态使用独立缓存,避免复用另一档的回答。
- 任务建议:空对话会显示 4 条建议,覆盖日常浏览器操作与鹰眼能力。例如打开哔哩哔哩搜奥特曼并播放、总结当前页、问卷试填、公开商品比价,以及流量/接口梳理、敏感与暗链、证书、响应式、公开研究、Burp/Yakit 分流、完整响应深搜、编解码、原生下载和复杂控件可访问性。点
换一批 会继续轮换中英文建议。
- 会话与标题:每次新建都是独立会话并保存在本机。第一条消息发出后会先显示简短临时标题,再由当前模型主动生成类似 Codex 的概括标题。双击页头标题可手动改名;左侧会话悬停后可删除,页头删除键也能删除当前会话,删除前会二次确认。
- 消息时间、编辑与定位:每条用户消息、AI 完成回复和工具结果都显示自己的时间;跨日或间隔较长时还会显示日期分隔。用户消息可点铅笔重新编辑,发送后会从该条分支重新执行。向上查看旧消息后,右下角会出现“回到底部”。
- 工具调用详情:每个工具步骤都是可展开卡片。单击工具行可查看真实
Input 与 Result,并可分别复制;绿色表示成功,红色表示失败。工具结果仍应结合历史/重放中的原始请求响应人工复核。
- Markdown 显示:AI 回复会以简洁的 GFM 样式呈现标题、粗体/斜体、列表、引用、链接、行内代码、代码块和表格。渲染前会兼容
内容为**《标题》**、##标题 等模型常见的中文紧邻/缺空格写法,但不会改写行内代码或代码块。表格过宽时会在消息内横向滚动。
- 附件与视觉分析:输入框左下角的
+ 可添加图片、TXT、MD 与 CSV(最多 6 个,单个 8 MB)。文本附件作为分析上下文;图片受高级设置的“当前模型支持多模态图片输入”开关控制。已知视觉模型会自动开启;新发布、代理或自定义模型如已确认接口支持 image_url,可手动开启。原始附件不写入持久化历史。Agent 平时优先用可访问性快照;遇到验证码、Canvas、浮层、白屏或响应式布局时,可自主截取视口、整页或单元素,截图结果会直接回灌到下一轮视觉模型判断。
- 复制、导出与快捷操作:消息右上角可复制单条内容,页头复制键可复制整段会话;页头下载键会把完整对话(含每个工具的 Input、Result 与时间)导出为 Markdown 文件。⌘/Ctrl+Shift+N 新建会话;焦点不在输入控件时按 / 可快速定位输入框。
- 可执行能力:Agent模式会组合浏览器 MCP 与鹰眼内部工具完成导航、点击、输入、自定义下拉选择、抓包检索、数据包检查、重放、敏感信息/暗链扫描、编解码与结果比对。对于深层 iframe、开放 Shadow DOM、富文本编辑器和自定义下拉框,它会优先按可访问结构定位;遇到问卷/考试可先结构化提取题目,再批量填写选项、判断和文本答案(最终提交仍需明确指令)。
- 本地 OpenSSL/CryptoJS AES 解密:对以
U2FsdGVkX1 开头的 OpenSSL Salted__ Base64 密文,Agent 会把密文与口令交给内置 hawkeye_codec 的 openssl_decrypt,在扩展后台本地解密;不会向当前网页注入密码学脚本,也不会加载外部 CDN。未知动作、缺少/错误口令、非 Salted__ 格式或不兼容的 KDF/算法会明确显示失败,空输出不再标记为成功。
- 通用文件下载:当你要求下载当前页的视频、音频、Word、Excel、PDF、ZIP、RAR 或其他文件时,Agent 会先从页面媒体/下载链接或当前标签页的鹰眼抓包中定位真实 HTTP(S) 资源。只有一个可用候选时,发现步骤会在按安全策略取得授权后自动继续调用
browser_download_file 加入浏览器原生下载队列,并根据 Content-Type/Content-Disposition 补全扩展名。只有返回 nativeDownloadStarted=true 与 downloadId 才算已开始;仅找到地址、打开链接或看到播放器不算完成。页面若只暴露 blob:,Agent 会继续从当前标签页的捕获记录查找底层文件请求。
- Agent Skills 与主动沉淀:普通 Skill 仍采用双重授权——新会话默认关闭,用户点击输入框下方
Skills 后,也只能从高级设置已启用的 Skill / 子模块中匹配。Agent 会先按当前任务检索轻量元数据,再按需读取必要 Skill 或明确指定的子模块;智能路由不限制加载数量,但仍不会把所有已开启 Skill 正文一次性注入模型上下文。查看 Skill 清单/内容时也是由 AI 根据真实的按需检索结果回答,不是固定话术。例外是用户明确要求“记住”后生成且仍保持勾选的 Agent 沉淀 Skill:它会先在后续相似任务中成为候选,确实需要时才读取正文;在高级设置取消勾选或删除后立即停止使用。
- 当前页与自主联网研究:Agent 会在任务开始时锁定你实际正在查看的 HTTP(S) 标签页,即使 Agent 已展开成完整页面,“当前页”也不会误指向扩展自身。知识不足、信息较新或多个来源冲突时,Agent 可自主选择
browser_search、browser_fetch 或 browser_research 搜索并读取多源证据。临时后台标签会自动关闭,不改变当前页;结果显示缓存、引擎状态、证据评分、失败与信息缺口,AI 只能引用成功读取的来源。该能力为鹰眼自研实现,不安装、不调用也不依赖第三方 Wigolo 服务或代码。
- 计划自修复、空响应恢复与长上下文:若模型返回缺字段、非法 JSON、未知工具、
success/completed/done 等兼容状态或纯文本总结,Agent 会先标准化,再把具体校验错误和错误输出回传给模型自动重生成。若 HTTP 200 的 content 为空,且请求开启思考、响应只有思考内容或 finish_reason=length 等输出预算耗尽标记,在剩余重试与时间预算内最多恢复一次:按模型能力降低或关闭思考,结构化请求移除接口格式约束但仍要求本地校验,长度耗尽时适度增加输出预算,并要求返回简短完整内容。普通无原因的空响应不会自动重试。恢复后仍为空时,错误会带上 finish_reason、reasoning 字符数及 token 用量,便于区分模型只输出思考、输出预算耗尽或接口兼容问题。若工具步骤已有可靠结果,则基于当前运行的真实 observation 生成确定性降级总结,不让末轮空响应抹掉已经验证的结果。上下文按 token 而非字符估算,并为系统规则、按需读取的 Skill、工具结果和模型输出预留空间。Skill 正文按需读取,智能路由不限制加载数量,单次读取仍受上下文窗口约束,仅在当前 Agent 运行中保留;下一个新任务若仍需要,必须重新按相关性读取。接近总预算时会把较旧消息滚动压缩为持久任务记忆,单独保存原始目标、用户更正、约束、已验证事实、完成项、待办和失败证据,同时保留近期原文。压缩调用失败时会用本地确定性摘要兜底,不会中断任务;编辑历史消息会清除旧摘要并从编辑处分支,避免陈旧记忆污染。MCP 的大快照仍可用 context_budget_chars 与 page_token 分页续读。
- 选择技能与智能路由:新会话默认关闭 Skills,按钮保持未选中。点击输入区 Skills(或标题栏 ✦)打开浮层,浮层从该按钮左缘向右上方展开,不会盖住左侧按钮;可点选任意数量已启用技能,点选即保存,不设数量上限。再点一次 Skills 会关闭浮层并关闭 Skills,按钮恢复未选中。点浮层外部或 Esc 只关浮层,已选技能仍保持开启。智能路由关闭时只使用指定技能;开启后可按当前需求检索并加载必要技能,也不限制加载数量。高级设置中的全局禁用仍然有效。
- 导入对话:左侧标题栏「+」左侧的小按钮可导入鹰眼导出的 Markdown(.md)文件,新增独立对话。用户/助手消息按原 Markdown 排版恢复;工具记录还原为可展开的工具卡片(含输入/结果),不会摊成 Raw JSON 正文。不会自动执行历史操作,也不恢复待执行队列、权限或目标。图片附件只保留导出时的名称。文件最多 2 MB、500,000 字符、600 条消息。
- 保存为 Skill:直接说“帮我保存为 skill”即可将已有已验证流程交给独立的生成、校验与本地保存流程;没有
hawkeye_skill_upsert 工具不代表不能保存,也不需要转成用户脚本。用户也可直接要求“更新该 Skill”:Agent 先读取目标,再通过 hawkeye_skill_update 按 ID 追加内容或精确替换唯一片段;保留原 ID、未修改正文、子模块及勾选状态,保存后回读核验。支持已有自定义与 Agent 沉淀 Skill,内置 Skill 不可直接覆盖。已有证据足够时无需重新浏览页面或重复输出完整文档。以平台发出的真实 Skill 保存回执为准;生成或保存失败时会说明原因,不会提前宣称已保存。
- 跨会话摘要记忆与人设:历史摘要召回默认关闭。未勾选“在新对话中召回相关历史摘要”时,各会话独立,不召回其他会话的目标、偏好、完成项或待办,也不生成新的跨会话摘要;当前会话消息与压缩任务记忆仍保留。勾选后才生成并按当前问题召回相关摘要,不注入完整旧对话,也不把摘要当作指令。已有开关选择会保留;关闭不会删除已保存摘要或聊天记录,记忆管理区仍可查看、编辑、单条删除或清空摘要。人设新增“鹰眼万能浏览器助手”并作为默认,熟练使用鹰眼完成标签页、导航、iframe、表单、弹窗、上传、下载和多步骤网页任务,先观察、再操作、核验实际结果。连同鹰眼安全搭档、Web 渗透、CTF、前端/API 排障、研究分析和长期朋友,共七种预设;支持自定义。已有手动选择的人设保留,可在下拉框切换或恢复预设。人设不覆盖用户指令、权限边界和工具证据。
- 目标、计划与推荐选择:输入框下方的
目标 可为当前会话设置一个持续追求的目标;当 Agent 核验任务完成,目标会自动清除,不会停留为“进行中”模板。等待你选择或确认计划时,目标不会被提前清掉。运行中修改或删除目标会同步到后台任务;删除会停止当前执行。计划模式 只允许调研和生成具体 Markdown 方案(范围、前置条件、步骤、验证点与风险),并禁止改当前页(导航/刷新/前进后退)、下载或截图落盘。需要你拍板时会像 Codex Ask 一样给出选项,由你自己选,不会擅自实施。方案完整后确认弹窗会显示可滚动的完整计划,并保留“按计划执行 / 调整计划 / 暂不执行”。只有选择“按计划执行”才退出计划模式并开始真实操作;顶部任务清单会留下来,完成一项勾一项,不会因为开始实施而消失。
- 执行与安全反馈:发送后会立即显示“AI 正在思考”和当前阶段;停止键会显示明确文字。页头安全菜单有
请求批准、风险时询问和 完全访问 三档;默认只拦截提交、删除、发送、重放/Fuzz、修改授权范围等高风险动作。完全访问不逐次询问,界面会持续提示后果。
- 连续协作:可以在同一会话继续补充“只看当前域名”“不要提交,只填写到最后一步”“根据刚才结果继续”等约束。若达到单轮上限,可回复“继续”;模型会带上该会话的消息与工具结果续跑。
- 授权与隐私:仅对你拥有或明确获准测试的目标执行操作。提交表单、删除、修改数据、上传、越权验证等可能改变外部状态的动作应在指令中写清边界,并在关键步骤前人工确认。模型会接收完成任务所需的上下文,真实凭据与隐私数据请按需脱敏。
停止与完成状态:在工具确认窗口等待期间停止任务,即使随后确认也不会继续执行该工具。模型格式恢复失败时会保留未完成目标并交接已核实的结果;尚有工具待执行时不会提前清除目标。旧任务的下载记录不能充当本次任务的成功证据;“已加入下载队列”也不等于文件已经下载完成,请以浏览器下载状态为准。任务结束会清理由 Agent 临时开启的抓包,不关闭你原先已开启的抓包。长文本和多附件会共同计入上下文预算,必要时压缩或截短;关键要求请放在最新消息中明确说明。
标签页、下载与收尾:Agent 切换或绑定标签页后,后续操作使用该页面;关闭任务页面后仍可总结已有资料,再次操作页面前需要选择或新建标签页。文件发现只列候选,下载需要独立执行;加入下载队列后仍会核对剩余工作。标题和历史记忆在后台整理,不阻塞下一项任务;明确要求保存的 Skill 会先完成再收尾。
后台续跑与断点:Agent 执行已从侧栏生命周期拆出。关闭侧栏、刷新扩展或后台被系统回收后,已确认完成的步骤不会重做;正在进行、结果未知的提交/下载/点击会停在“核实中断操作”,由你确认“已完成 / 未执行 / 停止”,系统不会自动再提交一次。重新打开侧栏会接上后台进度,而不会用旧对话覆盖新检查点。断网后会按检查点退避重试只读恢复,写操作仍需你核实。
11. 批量操作与典型场景
- 版本说明:批量导出、批量删除、批量重放、批量 AI 分析、批量暗链检测与批量报告导出均为专业版能力。
- 批量操作:勾选多条记录后,可批量导出、删除、批量AI分析、批量暗链检测(打开 §9 所述新标签工作台)、批量重放。
- 联调排错:抓包 → 找目标接口 → 重放改参 → 对比响应。
- 敏感排查:抓包 → 详情切到敏感信息 → 定位命中字段。
- 安全初筛:暗链检测 → AI辅助分析 → 导出报告。
12. 常见问题(新手高频)
- 状态徽章单击和双击有什么区别? 单击打开「软件激活」或已授权时的尊享说明(试用中同理)。在已取得有效正式授权(按天或永久)时,双击打开授权详情(机器码、激活时间、剩余时间、可展开的激活码等),详见 §13。
- 首次打开要同意协议? 首次使用需在弹窗中滚动阅读用户协议摘要到底部,勾选同意后方可继续使用(完整版可另开页面查看)。
- 快捷键打不开抓包界面? 默认是
Ctrl+H,Mac 上必须按 Control 而不是 Command 或 Option。不必先打开弹窗。Chrome 若已在 chrome://extensions/shortcuts 改过组合,以设置页为准。Firefox 默认打开的是页面内浮窗,不是原生侧边栏;再按一次关闭。网页若占用了同一组合,可在高级设置(Firefox)或扩展快捷键页(Chrome)改绑。详见 §4。
- 看不到数据包? 先确认抓包开关开启、抓包目标是否匹配、抓包类型/后缀是否把请求过滤掉。
- 请求区只有“GET /path HTTP/1.1”、没有请求头? 这一行是请求行,不是请求体。最新 1.0.6 会合并 Firefox WebRequest/页面钩子可见的请求头并补齐 Host 权威信息。若旧历史记录仍只有请求行,请在
about:debugging / 扩展管理页重载最新版,确认抓包已开,再强制刷新目标页产生新请求;已存的旧记录不会凭空补全。浏览器仍可能隐藏 HTTP/2 伪头或受保护头,这不代表抓包失效。
- 请求体是否有问题?
GET/HEAD 通常本来就没有 body,只显示请求行+请求头属正常。请用新产生的 POST/PUT/PATCH 请求验证 body;Firefox 会读取 formData 或 raw bytes。若仍为空,再检查请求是否是不可重放的流、浏览器隐私限制,或正文因大小上限被截断。
- 默认抓包勾选哪些?为什么勾 JS? 默认建议 XHR/Fetch + WebSocket + HTML + JS + JSON + XML;JS 对隐藏 API、sign/token、source map 和前端动态请求很有价值。高流量时可临时收缩为 XHR/Fetch + WebSocket;拦截时建议更精确,见 §3。
- WebSocket 只看到
GET 101 握手,看不到 123 这种消息? 先确认抓包类型里勾选 WebSocket,历史列表不要只看 XHR/Fetch;再检查 Host、当前页面/全部数据包、搜索框是否过滤掉了帧。真实帧在列表中显示为 WS,出站在请求侧,入站在响应侧。
- WebSocket 重放失败或没有响应? 帧重放依赖当前页面仍有
OPEN 状态的 WebSocket。页面刷新、连接断开、切到别的 Tab,或服务器本身不回包时,右侧可能显示连接不可用或超时;这不是重新握手的 HTTP 重放。
- 想让 Burp/Yakit 里只看到目标站点? 在基础设置中打开智能代理分流器,配置上游代理与站点规则即可。Firefox 可按场景选择兼容模式或接管模式。
- 列表/存储有上限吗? 单条请求或响应正文在扩展内有大小上限(大文件 multipart 等可能显示不完整);历史条数亦有上限,极长时间运行可酌情清空历史。
- 响应体为空? Chrome 且为内网/自签名 HTTPS 时,可在设置中开启「内网/自签名 HTTPS 响应体(被动监听)」后刷新重抓。Firefox 版无此开关;请从抓包开关、目标域名、类型筛选等方向排查——通常不依赖「被动监听」这一项。
- 抓到的响应是密文/挑战页? 若站点有 WAF 动态解密,用
页面内重放 或 页面内 Fuzz,在浏览器中执行 JS 后提取解密内容。
- 页面内重放/页面内 Fuzz 与 POST? 需在浏览器内完成与页面同源的导航或表单提交。已支持 POST(请求头为
application/x-www-form-urlencoded,正文为表单字段);multipart、JSON 等请用普通重放。
- 拦截开着,为什么重放 / Fuzz 没进拦截队列? 这是刻意设计:
重放、页面内重放、微型Fuzz、页面内Fuzz 走工具白名单,避免测试流量再次被自己拦住。
- 切换请求方法后还要不要自己检查? 要。该按钮会自动处理常见的 GET / 表单 POST 场景,但若原始请求含 JSON、multipart、签名字段、时间戳或自定义校验逻辑,仍建议手工复核请求头、body 与签名是否匹配。
- AI 任务能自动做加密逻辑分析吗? 可以(专业版)。Agent 会经内置工具
crypto.logic.analyze 调用与重放台「加密逻辑智能分析」相同的多轮研判;你也可在重放台先手动分析,再把结论写进任务背景。验证哈希/编解码时 Agent 还会用 codec.transform(可传 key/iv/mode),再用 packet.mutate + replay.request 闭环;若响应是密文/挑战页,会改用 replay.dom 页面内重放。
replay.dom 和 replay.request 怎么选? 普通 API/静态 HTML 用 replay.request(后台 HTTP 重放,快)。当响应是 WAF 动态解密、JS 挑战页或密文 HTML 时,用 replay.dom(与重放台「页面内重放」同源,浏览器内导航后提取 DOM)。批量带 §注入点§ 的变体探测用 microfuzz.run 并设 use_dom:true。
- 敏感信息误报多怎么办? 内置规则已做二次校验;若仍噪音大,可在高级设置关闭 IPv4/IPv6/域名等宽泛规则,仅保留证件/JWT/Shiro/指纹类;社区版也可添加自定义正则与关键词规则精调。
- 暗链检测误报多怎么办? 在高级设置补充本站 CDN/合作方到高信誉顶级域;侧栏暗链报告优先看「隐藏样式 + 外链」组合信号,单独变色龙或无障碍类可忽略。
- 编解码没生效? 检查“作用范围”是否选对;若选“选中文本”,必须先选中内容。详情标题行的 加密&编码 与重放台菜单相同,响应侧不支持「仅参数值 / 整行 URL」。
- 详情里四个 Pro 按钮有什么区别? 检测暗链:规则扫描响应/HTML,不需 AI。AI 分析:模型总结整包风险与指纹。AI脚本:把当前包生成可注入的页面脚本(见 §5.2 说明框)。加密逻辑智能分析:研判 sign/token 等字段的加密/签名链路。四者报告分类型缓存,但同屏只显示最后一次点击的那一类。
- AI脚本 和脚本页「AI 创建」怎么选? 已抓到关键包、要写针对这条接口的自动化 → 用行内或底栏 AI脚本(包已在上下文)。只有模糊想法、还没有具体流量 → 脚本工作台
AI 创建。详见 §4.2 与 §5.2。
- 智能解码助手支持哪些 Web 编码? 支持常见 URL 百分号编码、HTML 实体、Base64/Base64URL、Hex、JSON 反转义和 JavaScript/JSON
\uXXXX Unicode 转义,也可智能探测多层套娃。如 \u8d44\u6e90\u4e0d\u5b58\u5728 应解码为中文;选中时请包含完整的 \u 序列,不要只选十六进制数字。专业版的详情/重放菜单还可手动选“Unicode 解码”或“JSON 反转义”。
- 智能解码助手一直弹窗怎么办? 侧栏 脚本 → 关闭「Hx0 智能解码助手」,或改为手动执行;GM 菜单 Hx0 切换智能解码面板 可临时开关当前页。轻量浏览解码用助手;报文内 AES/套娃仍用详情内联或重放台(§5.2、§6)。
- AI按钮可点但没结果? 检查 Base URL/API Key/Model 与购买的计费类型是否匹配,再检查网络。智谱错误
1113 表示当前账户/端点没有可用余额或资源包:Coding Plan 和标准 API 必须使用各自端点。小米 tp- Token Plan Key 与 sk- 按量 Key 也不能混用。页面会在 Base URL 下显示识别到的提供商/计费端点;若提供商、URL 或模型串号,重新选择提供商或重载新版扩展即会自动归位。
- 为什么当前是社区版却看不到或不能使用某些高级功能? 社区版保留“抓包 → 看详情 → 拦截改包 → 普通重放 → 基础编解码”的主链路;页面内重放、微型 Fuzz、页面脚本注入、AI、暗链、批量工作台、高级编解码等属于专业版。点击对应专业入口时,会显示功能说明并引导进入激活窗口。
- 切页面后报告丢失? 同一数据包会分别缓存并恢复 AI 分析、暗链、加密逻辑 三类报告;切换列表行或收起再展开即可恢复上次结果(同屏仍只显示你最后一次打开的那一类)。
- Firefox:侧边栏不在右侧? 左右位置由 Firefox 全局控制,请在浏览器「侧边栏」菜单中切换到右侧(非扩展故障)。
- Firefox:按 F 后 2 倍速成功,但全屏失败? 确认重载了包含原生输入中继的最新版,并让目标标签页处于当前 Firefox 窗口前台。工具返回
native_pending 表示旧路径尚在等待/未完成;最新路径应返回原生输入证据,并以 document.fullscreenElement 最终状态为准。延迟查到 userActivation.isActive=false 可能是全屏成功后已消耗,不是单独的失败证据。
- Firefox:拦截后页面暂时发白? 常见原因是主 HTML 已返回,但同页的 JS/CSS/接口等仍在拦截队列;请在拦截列表继续放行或使用侧栏「一键放行」(多为串行处理)。
- Firefox:在页面内浮窗放行主文档后按钮短暂失灵? 主文档继续加载会重建嵌入浮窗所在 DOM,属架构限制;主文档与整页资源链放行请改用侧边栏(§14)。
- Firefox:点「批量导入」后主弹窗不见了? 这是正常现象:请在随后出现的小窗口里选好表格文件,看到导入结果后,再点一次工具栏上的扩展图标即可继续(详见 §4.1)。
安全提醒:请仅在你有授权的系统上测试。AI 分析可能上传你选中的报文内容,务必注意脱敏。
13. 软件授权、试用与设备标识(Chrome / Firefox 通用说明)
- 激活(单击状态徽章):未获得正式授权且不在试用期内时,扩展会自动回落到社区版,仅专业功能不可用。单击弹窗右上角状态徽章,打开「软件激活」窗口,分为 在线激活 与 离线激活 两个 Tab;已授权时单击打开尊享说明。试用期内徽章显示试用剩余时间,单击行为相同。
- 社区版与专业版:主要差异见下表。
- 在线激活:在「软件激活」→ 在线激活 Tab 开通订阅或永久会员。联网时会自动同步权益并缓存到本机;断网后可在缓存有效期内继续使用专业版(永久会员长期有效,订阅在有效期内有效)。界面展示用户 ID(权益凭证,请妥善保存)与会员状态;可点击「开通会员 / 我的会员」进入购买流程。
- 离线激活:在 离线激活 Tab 使用传统机器码 + 激活码模式,校验在本机离线完成,无需连接外部授权服务器。订阅会员可在提示区查看精确到秒的剩余时间(自动刷新),并通过「续期」链接购买新激活码;永久会员可更换激活码或双击徽章查看授权详情。
- 权益遗失:若重装浏览器导致在线用户 ID 变更,或离线机器码变更导致授权无法使用,请联系客服 hx0studio@foxmail.com,并提供付款记录及原/现 ID 或机器码等信息,由客服协助核实与恢复。
- 试用与回落:首次安装可试用专业版全功能 30 分钟;试用结束且未激活时,会自动切换为社区版。在社区版中点击高级功能,会先展示该功能说明,再进入激活窗口引导购买或输入激活码。
- 授权详情(双击状态徽章):当您已持有有效的正式授权(按天订阅或永久)时,双击同一枚状态徽章可打开授权详情面板:展示机器码、激活时间、剩余使用时间(按天订阅精确到秒并自动刷新;永久显示为「永久」)。当前激活码默认不直接展示在界面上,需点击眼睛图标(闭眼为隐藏、点击后睁眼)才显示全文,再次点击可隐藏。按天订阅用户可在同面板填写新激活码并「替换并激活」,例如续期或升级为永久授权。每次校验成功的激活后,扩展会在本机保存最近一次激活码与激活时间,便于您核对;若本地尚无这两项记录,界面会给出说明性提示。
- 试用:同一使用周期内可申请一次试用;当前版本默认试用时长为 30 分钟,并记在本机,到期后与未授权状态一致。
- 设备标识(申请授权时备用):扩展会为本机当前浏览器环境生成一组相对稳定的标识(与授权详情中的机器码一致),用于与您的授权信息对应。在同一浏览器用户配置下,即使重装扩展,该标识通常不变,便于您向 Hx0战队(微信公众号 / 知识星球:Hx0战队)申请或续期授权时提供一致的参考信息。
| 功能项 |
社区版 |
专业版 |
| 抓包开关 |
✅ |
✅ |
| 目标域名 / IP 设置 |
✅ |
✅ |
| 抓包类型 / 后缀设置 |
✅ |
✅ |
| 历史列表查看 |
✅ |
✅ |
| 当前页面 / 全部数据包切换 |
✅ |
✅ |
| Host / 方法 / 状态码基础筛选 |
✅ |
✅ |
| Pretty / Raw / Hex / Render 视图 |
✅ |
✅ |
| 请求 / 响应复制、标题点击复制 URL、单条下载 |
✅ |
✅ |
| 敏感信息查看(内置规则) |
✅ |
✅ |
| 普通重放 |
✅ |
✅ |
| 悬浮球 |
✅ |
✅ |
| 另存为新标签 |
✅ |
✅ |
| 基础编解码(MD5 / SM3 / SHA-1 / SHA-256 / ROT13 / Base32 / Base64 / URL / Hex) |
✅ |
✅ |
| 拦截改包 / 放行 / 丢弃 |
✅ |
✅ |
| WebSocket 抓包 / 帧查看 / 帧重放 / 拦截改包 |
✅ |
✅ |
| 智能代理分流器(智能转发流量到 Burp/Yakit 等) |
✅ |
✅ |
| 页面内重放 |
❌ |
✅ |
| 微型 Fuzz / 页面内 Fuzz / 标记注入点 |
❌ |
✅ |
| WebSocket 微型 Fuzz |
❌ |
✅ |
| 页面脚本(脚本库 / 油猴导入 / GM 菜单 / AI 创建·优化 / GM_hx0CallTool) |
❌ |
✅ |
| 切换请求方法 / 目标域名切换 |
❌ |
✅ |
| 高级编解码(SHA-512 / HMAC-SHA256 / Base64URL / Unicode / HTML / JSON / JWT / 时间戳) |
❌ |
✅ |
| 加密逻辑智能分析(结合当前请求上下文与同页 JS / HTML 线索研判编码 / 摘要 / 签名链路) |
❌ |
✅ |
| AI 分析设置 |
❌ |
✅ |
| AI结果分析 / AI分析 / AI生成用例 |
❌ |
✅ |
| 暗链检测 / 报告下载 / 报告缓存恢复 |
❌ |
✅ |
| 全量深度搜索 |
✅ |
✅ |
| 自定义规则 / 关键词库 / 批量导入导出 / 一键清空 |
✅ |
✅ |
| 高信誉顶级域配置 |
❌ |
✅ |
| 批量工作台(批量导出 / 删除 / 重放 / AI / 暗链 / 报告) |
❌ |
✅ |
| AI 任务台(渗透 / CTF 双模式、工具链调度、运行中补充线索) |
❌ |
✅ |
| 浏览器级 Agent / Agent 模式(仅有效试用或专业版授权) |
❌ |
✅ |
| AI 技能 Skills(内置知识库 / 导入 / 任务级子模块) |
❌ |
✅ |
合规提示:请按许可范围使用本产品;商业场景请购买正版授权。
14. Chrome 与 Firefox:界面与使用差异(按需阅读)
以下仅说明界面与使用层面的差别。抓包、历史、拦截、重放、微型 Fuzz、敏感、暗链、AI、授权等核心能力两版一致;部分可选设置(如 Chrome 为补齐内网/自签名 HTTPS 响应体而提供的「被动监听」)可能因浏览器而异,以实际界面为准。
- 侧栏托管方式:Chrome 使用 Side Panel(侧栏)API,由浏览器统一提供侧栏容器。Firefox 使用浏览器原生侧边栏;侧栏显示在左侧或右侧由 Firefox 全局设置决定,请在浏览器「侧边栏」相关菜单中调整,扩展无法强制固定到某一侧。
- 抓包界面快捷键:两版默认都是
Ctrl+H(Mac 为 Control+H)。Chrome 切换 Side Panel,改键只能走 chrome://extensions/shortcuts。Firefox 先打开页面内浮窗,再按一次关闭;可在高级设置录制新组合。详见 §4。
- 页面内浮窗 / 悬浮球:两版均可提供页面内快捷入口(浮层/浮球)。Firefox 的浮窗嵌入在网页文档中;当对当前标签页主文档执行放行导致整页重新加载时,浮窗所在 DOM 可能被重建,出现短暂不可点——此时请改用侧边栏完成主文档放行、整页资源链放行或「一键放行」。Chrome 在类似场景下同样建议优先使用侧栏处理主文档与高风险的批量放行。
- 拦截列表与整页资源:现代页面除主 HTML 外常依赖其他 Host 的脚本、样式与接口。Firefox 拦截视图会尽量展示与当前页相关的跨 Host 条目;「一键放行」按队列串行处理,并可能在主文档放开后继续接住新出现的资源。若页面暂时残缺或发白,请先检查拦截队列是否仍有待放行项。
- 内网 / 自签名 HTTPS 响应体(被动监听):仅 Chrome 版提供该设置——用于在 Chrome 受限场景下尽量抓全内网/自签名 HTTPS 的响应正文。Firefox 版无对应 UI;在常规抓包流程中通常不需要等价开关也能抓到完整数据包(与浏览器实现差异有关)。
- Firefox 请求头 / 请求体:最新版在抓包启动时提前注册 WebRequest 监听,合并发送前后与页面钩子证据,并对 Host/authority 做回退;POST/PUT/PATCH 会优先保留
formData 或 raw body。GET 没有 body 属正常。更新后需重载扩展并刷新页面产生新记录,旧历史不会被回填。
- MCP 可信输入 / 全屏:Chrome 通过 CDP Input 域分发;Firefox 在受支持桌面环境中对需要 transient activation 的操作可使用本机原生键鼠中继。目标标签页必须在前台;全屏成功后
isActive 可能被消耗,请以输入证据与 fullscreenElement 为准(见 §3.1)。
- MCP 截图:两版默认都只返回图片;显式传
save_to_file:true 时由本地 Server 保存文件,不增加任何外联。视口截图时绑定标签页应保持活动。
- 「正在调试」类提示:仅 Chrome 在开启拦截时较常见,属浏览器自身提示;Firefox 通常不会出现。
- WebSocket 观察:两版均支持在页面内捕获 WebSocket 帧;Chrome 会尽量补全握手与帧观察信息。目标页面需在当前浏览器标签页内保持连接。
- 敏感规则 CSV 批量导入:Firefox 会在独立小窗口中选文件,避免主弹窗被系统文件框关掉导致导入中断(见 §4.1);Chrome 一般在弹窗内直接选文件即可完成导入。
- 页面脚本权限:Chrome 安装清单已含
userScripts;若仍不可用,请在扩展详情手动开启「允许用户脚本」。Firefox 为可选权限,按工作台引导授权;更新扩展后请在 about:debugging 重载。
- 页面脚本与油猴兼容:导入
.user.js 识别常见元数据;@require 与 GM_xmlhttpRequest 尽量走扩展后台以绕开页面 CORS。内置轻量 jQuery 兼容层可覆盖常见 DOM 操作。带 GM_registerMenuCommand 的脚本:侧栏展开后自动拉取菜单,并可在非匹配当前页时从其它已打开的匹配标签读取(见 §4.2)。iframe 场景请开启 iframe 也注入。
- 授权、试用与设备标识:两版适用规则一致,详见 §13。
15. 与 Burp Suite、Yakit、浏览器 HackBar 等工具对比(详表)
下表按产品形态、会话一致性、工作流与专项能力做并列说明,便于按场景选型或组合使用;各工具侧重点不同,并无绝对优劣。表中 Hx0 鹰眼能力以当前发行版为准(含 AI 任务、Skills 知识库、智能代理分流等)。Burp / Yakit 在企业级主动扫描、Intruder 级大规模变异、非浏览器全流量等方面仍是常用平台,细节以各厂商文档为准。
| 维度 |
Hx0 HawkEye |
Burp Suite |
Yakit |
HackBar / 简易扩展类 |
| 形态与部署 |
浏览器扩展;侧边栏为主工作台,可选悬浮球;无需单独安装 JVM 或监听端口 |
独立 Java 代理 + 浏览器证书;完整安全测试套件 |
独立客户端 + 引擎/插件;偏安全测试与协作平台 |
多为地址栏旁小面板或单条请求辅助工具 |
| 上手与日常成本 |
安装后可在扩展内完成主流程,不强制修改系统全局代理;中英界面,操作集中在侧栏 |
需配置代理、信任根证书,并熟悉 Proxy / Repeater 等模块 |
需单独安装客户端并熟悉其工作流与插件体系 |
上手快,适合零散操作;一般不提供完整项目级工作区 |
| 浏览器会话 / 登录态 |
抓包与重放基于当前标签页同源会话,与页面实际发出的请求一致 |
经代理转发;复杂站点可能需在 Repeater 中手工同步 Cookie / Header |
多经代理或引擎路径,与「扩展内嵌页面」的实现方式不同 |
多依赖手工拼接 Header / Cookie |
| 现代前端 API(XHR / Fetch / SPA) |
在页面内捕获 fetch / XHR;支持 multipart 上传等场景的 Raw / Hex 审计(受扩展存储上限约束) |
代理层可见完整 HTTP(S) 流量,Repeater / Intruder 等模块成熟 |
流量采集与插件可覆盖复杂 Web 场景 |
多数聚焦 URL / 参数片段,持久历史与 Hex 视图较少见 |
| 历史、检索与工作台 |
本地持久历史;Host / 方法 / 状态码 / 敏感命中 / 搜索多维筛选;详情、重放、编解码、Fuzz、AI 可在同一侧栏完成;专业版另有批量工作台 |
Proxy History 功能完善,适合大规模流量管理与项目协作 |
平台化记录、PoC 与协作能力较强 |
通常不提供或仅提供弱历史与批量能力 |
| 系统代理 / 非浏览器流量 |
侧重浏览器内 HTTP(S),不覆盖手机 App、桌面客户端等经代理的全局流量 |
支持系统级代理,可拦截多类客户端流量 |
支持 MITM / 监听端口,可接入多种流量来源 |
一般不涉及系统代理 |
| 与 Burp / Yakit 等代理协同 |
社区版「智能代理分流器」可按站点将命中的浏览器请求转发到上游代理(如 Burp / Yakit 监听端口),未命中仍直连;便于组合使用,不替代对方扫描与流水线能力 |
自身为常用 HTTP(S) 代理与套件中枢 |
提供 MITM 端口与插件 / 工作流,可与其他工具串联 |
一般无代理协同能力 |
| 拦截与改包 |
队列式拦截;在侧栏中逐条或批量放行、改包后再发 |
Proxy 拦截,Repeater 改包重发,生态与文档丰富 |
支持 MITM 拦截与工作流编排 |
多数无拦截队列,或仅支持 URL / 参数级修改 |
| 重放 / 变异 / Fuzz |
重放台编辑原始报文;微型 Fuzz;页面内重放 / 页面内 Fuzz 用于 WAF 动态 HTML(GET 或 urlencoded POST);专业版含 AES/DES/RSA/SM 加解密、智能套娃解码、加密逻辑智能分析、crypto.logic.analyze 与 upload/header/WS 等内置工具链(AI 任务中调用) |
Repeater / Intruder 成熟,适合复杂字典、并发与脚本化变异 |
Web Fuzzer 等模块,适合工程化流水线与批量 PoC |
通常无结构化 Fuzz 与多轮对比工作流 |
| 敏感信息 / 暗链 / 初筛报告 |
内置敏感规则 + 列表角标 + 详情聚合;暗链规则扫描;报告可导出并与历史联动 |
Scanner、BApp 插件生态可扩展各类检测 |
插件与 PoC 库丰富,可按场景组合 |
较少内置此类规则与报告能力 |
| AI 点状辅助与批量总结 |
可选 BYO API(DeepSeek / OpenAI 兼容等),请求发往用户配置的 Endpoint。专业版:单条 AI 分析、批量 AI 独立标签页汇总(见 §9 / §10) |
可通过 BApp、第三方脚本或自建服务接入 AI,能力与界面因插件而异 |
平台侧持续扩展 AI 模块,可与引擎 / 流水线联动 |
少见;多为单次编码或拼接,缺少批量与结构化输出 |
| AI 长程编排与 Skills |
专业版 AI 任务台:多回合工作流,模型通过 JSON 驱动内置工具链(历史拉取、重放 / 变异、crypto.logic.analyze 加密逻辑研判、codec.transform 高级编解码、上传 / 头 / WebSocket 探测、llm.history/llm.chat 多轮套话等)在页面同源会话下真实发包;支持渗透 / CTF 双模式、Skills 知识库注入(内置渗透 / CTF 模块、可编辑 / 导入)、智能脚本调用、测试方向与子模块联动、运行中补充线索与安全策略门控。不替代企业级主动扫描与超大规模 Intruder 流水线 |
产品形态以 Scanner、宏、Repeater / Intruder、BApp 为主;AI 编排方式与扩展侧栏内嵌路径不同 |
以 MITM / 引擎与平台化工作流为主;AI 与自动化分布在各模块 |
不具备多回合工具编排与报告闭环 |
| 主动扫描 / 大型自动化 |
非主要定位;侧重人工驱动的高频抓包—重放—验证闭环 |
Burp Scanner、宏、插件生态,适合全站扫描与复杂自动化 |
批量 PoC、协作流与流水线检测 |
一般不具备 |
| 资源占用 |
随浏览器进程运行,额外占用相对较小 |
独立代理 + JVM,占用随扫描规模与插件配置变化 |
客户端 + 引擎,占用视场景与插件而定 |
占用极低,功能面也相应较窄 |
| 授权方式 |
扩展内激活(在线会员 / 离线激活码,见 §13) |
商业许可证(Community / Professional 等版本) |
开源核心 + 商业组件等模式 |
因产品而异 |
适用场景小结:Hx0 鹰眼适合需要在浏览器真实会话下完成「抓包 → 筛选 → 改包重放 → 轻量 Fuzz → 敏感 / 暗链初筛 → 可选 AI(含 AI 任务与 Skills)」一体化闭环的场景,例如前后端联调、验收自检、授权范围内的接口审计、WAF 动态页取证、CTF / 靶场练习。Burp Suite适合需要系统级代理、大规模 Intruder 变异、Scanner 主动扫描与成熟插件生态的项目。Yakit适合偏平台化 PoC、流水线与协作的安全测试流程。HackBar 类扩展适合 URL / 参数级的快速手工试探。四者可以组合:例如鹰眼作浏览器侧主工作台,经智能代理分流把部分流量送入 Burp / Yakit 做深度分析。
协作建议:按任务阶段选型,而非非此即彼。日常浏览器内调试与验证可优先使用 Hx0 鹰眼;遇到全站主动扫描、超大规模字典、非浏览器客户端流量或团队已有 Burp / Yakit 规范流程时,可叠加专业代理平台。社区版「智能代理分流器」支持按站点把部分浏览器流量转发至 Burp / Yakit,其余流量仍直连。
16. Skills 知识库(专业版)
入口:弹窗 高级设置 → AI 技能(Skills)。内置库随发行版提供,亦可导入外部 Agent 技能包;只有在此保持勾选的 Skill 才能使用。普通 Skill 还需在每个新 Agent 会话点击 Skills;用户明确要求“记住”后生成的 Agent 沉淀 Skill 则会在相似任务中自动匹配。Skill 是注入 Agent 上下文的知识/指令模块,不是 MCP/API 工具,也不是用户脚本;在 Agent 中询问“当前有哪些 Skill”会直接列出这里启用的模块,不会去查询 UserScript。内容保存在浏览器本地;注入 AI 任务或 Agent 时随你配置的模型 Endpoint 发送,请仅在授权环境使用。
让 Agent 把流程或错误沉淀为 Skill
- 必须明确触发:例如“请记住这次登录流程”“把刚才的错误教训保存成 Skill”。普通聊天、页面文案、附件或工具输出中的“记住”不会触发;“不要记住”会明确阻止保存。
- 以证据为准:Agent 会在当前任务结束后,从用户要求、成功/失败的工具 observation 和修正结果中提炼触发条件、复用步骤、验证标准与避坑项,不会把网页或附件内的指令直接写成规则。
- 隐私与真实性:沉淀请求固定开启脱敏,Cookie、Authorization、Token、密码、个人数据、真实会话值与绝对本地路径不会写入 Skill;只有校验并实际写入后才显示成功,失败不会假装已经记住。
- 去重与管理:相似经验会更新原 Skill 而不是反复新增。列表中带
Agent 沉淀 标记,可像其他自定义 Skill 一样查看 Markdown、编辑、导出、取消勾选或删除。
内置知识库子模块一览
下列模块可在高级设置与 AI 任务面板中单独勾选;hawkeye-runtime / hawkeye-ctf-runtime 为工具契约与 judge JSON,建议保持启用。用户编辑过的子模块会覆盖默认 markdown。
Hx0 渗透测试知识库(19)
| 子模块 ID | 覆盖方向 |
hawkeye-runtime | 工具清单、JSON judge、禁止外链 CLI(必读) |
methodology | L1–L4 抓包驱动决策环 |
product-fingerprint-recon | OA/ERP/DevOps/网安/VPN/中间件识别 |
injection-attacks | SQLi / NoSQL / XSS / RCE / SSTI / XXE |
framework-deserialization-rce | Shiro / Fastjson / Struts2 / Log4j2 |
logic-auth-access | 越权 / JWT / 鉴权 / 业务逻辑 |
session-cookie | Cookie 属性 / 会话固定 |
web-logic-misc | CSRF / 开放重定向 / OAuth / 竞争 |
api-security | Swagger / REST BOLA / GraphQL / @type |
crypto-flaws | 弱 AES/RSA、可预测 token |
js-reverse | 前端 JS 逆向、sign/token、硬编码密钥 |
file-upload-ssrf-lfi | 上传 fuzz / SSRF / LFI |
protocol-headers-ws | CORS / Header / WebSocket / CRLF |
encoding-waf-bypass | codec.transform + WAF 绕过 |
sensitive-disclosure | Actuator / Druid / Swagger 泄露 |
dark-link-detection | 暗链 / 挂马 / 静态威胁(darklink.scan) |
ai-llm-security | Prompt 注入 / Agent / MCP(OWASP LLM) |
ai-site-workflow | AI 站点 Phase 0–2 侦察 + P1–P7 + 八步流水线 |
reporting-triage | 风险分级与报告结构 |
Hx0 CTF 知识库(28)
| 子模块 ID | 题型 / 场景 |
hawkeye-ctf-runtime | 工具、flag 格式、judge、禁止项(必读) |
ctf-web-basics | 开题、备份、.git、注释 hint |
ctf-framework-hints | 框架指纹定方向 |
information-disclosure | Actuator / Swagger / .env |
encoding-waf-bypass | WAF + codec 绕过 |
misc-encoding | Misc 编码:Morse/Bacon/猪圈/套娃等 |
js-reverse | 混淆/sign/token/webpack |
protocol-ws-headers | Header / WS / CORS / DOM |
command-injection | RCE、$IFS$1、flag 过滤绕过 |
sql-injection | Union/盲注/读 flag 表 |
file-inclusion | LFI/RFI、伪协议 |
ssti | 模板注入 |
xss | 反射/存储/DOM |
file-upload | 上传信号分轮 fuzz |
xxe | 实体注入、php://filter |
deserialization | PHP/Java/Pickle POP |
framework-deserialization-rce | Shiro/Fastjson/… |
ssrf | 内网、gopher/Redis、metadata |
idor-auth | 越权、JWT |
session-cookie | 会话属性 |
api-security | Swagger/@type/GraphQL |
crypto-flaws | 弱加密、token 可预测 |
code-audit | 白盒 source→sink |
ctf-ai-basics | AI 赛道开题与题型路由 |
prompt-injection | 直接越狱 / system 泄露 |
ctf-ai-indirect-rag | 间接/RAG/上传/URL 注入 |
ctf-ai-agent-tools | Agent / Tool / MCP 滥用 |
ctf-ai-output-chain | 输出链 / XSS / 沙箱逃逸 |
CTF 模式优先引用 CTF 库;智能渗透优先引用渗透库。两库可同时启用,冲突以任务模式为准。LDAP/NoSQL 深度内容见渗透库 injection-attacks。
AI 任务面板:智能启用
- 在 AI 任务 页的 Skills 列表中,每个主知识库(如
Hx0 渗透测试知识库、导入的自定义 Skill)右侧有 智能启用 开关;悬停可查看 tooltip。
- 关闭(默认):本次任务对该库只注入你在展开子模块后手动勾选的 reference;任务中途不会为该库自动追加模块。适合你想精确控制 prompt 体积与专题范围时。
- 开启:除初始注入外,当 Agent 根据流量/判定发现新漏洞类型时,可为该库追加匹配的子模块(受高级设置全局启用列表约束)。日志会出现
任务中途 Skills 动态注入,注入摘要也会标注「智能启用」或「仅手动选择」。
- 须先勾选该主 Skill 的总复选框,「智能启用」才可操作;Skills 总开关关闭时整个注入链路不生效。
AI 生成技能(专业版)
- 入口:弹窗 高级设置 → AI 技能 →
AI 生成技能(需专业版且已在 AI 分析设置中配置 Base URL / Key / Model)。
- 输出类型:
单个技能 生成一份 SKILL 正文;技能集合 一次生成 2–6 个相互关联的模块(结果页顶部可切换标签分别编辑)。
- 生成约束:扩展内置 prompt 要求模型引用 Hx0 工具 ID(
packet.mutate、replay.request、crypto.logic.analyze 等),避免 curl/sqlmap 等外部 CLI 工作流。
- 保存到:
独立 Skill:加入导入技能列表,可在 AI 任务面板启用;
渗透测试知识库 · 子模块 / CTF 知识库 · 子模块:写入对应内置库的 AI 生成 reference(可编辑/删除,仅本机生效);
新建 · 独立 Skill(含子模块):生成父 Skill + references/ 结构;
追加到已有导入 Skill:下拉选择已有自定义技能,将生成内容作为新 reference 追加。
- 后续操作:保存前可编辑 Markdown;支持
导出 为文件、重新生成 返回描述页。生成过程会将你的描述与 prompt 片段发往你配置的 AI 端点;保存后的正文仍驻留本机,启用 Skills 时随 AI 任务一并注入。
导入外部技能(两种方式)
- 导入技能文件:选择单个
SKILL.md、.skill / .zip 技能包(zip 压缩,内含 SKILL.md 与可选 references/),或兼容命名的 skill markdown。.skill 是 Cursor / Claude Code / Agent Skills 的标准打包格式,可一键导入整包(含子模块)。
- 导入技能目录:选择包含
SKILL.md 的文件夹;扩展会扫描同目录下 references/ 或 reference/ 中的 .md 子模块并一并导入。适合未打包的技能目录整包迁移。
推荐目录结构
my-skill/
├── SKILL.md
└── references/
├── sql-injection.md
└── file-upload.md
也兼容常见 Agent 路径,例如 .cursor/skills/my-skill/SKILL.md、.agents/skills/…/SKILL.md,以及路径中含 /skills/ 的 markdown 文件。将上述目录打成 zip 并改后缀为 .skill 后,可用「导入技能文件」一键导入整包。
文件格式要求
- 主文件为 Markdown;文件名推荐
SKILL.md / skill.md / Skill.md。也可以导入 .skill / .zip 技能包(zip,内含该 Markdown 与可选 references)。
- 文件开头可选 YAML frontmatter(首尾
--- 包裹)。常用字段:
name(强烈建议):技能显示名称;
description(强烈建议):一句话说明,用于列表展示与 AI 摘要;
- 可选
nameEn / descriptionEn 供英文界面显示。
--- 之后为技能正文,会在启用时追加到 AI 的 system prompt(与已选 reference 子模块合并)。
- reference 子模块(可选):放在
references/ 下的 .md 文件。第一行 # 标题 用作模块名;行首 > 摘要 可选。导入后可在高级设置与 AI 任务面板中单独勾选。
AI 任务 / 页面脚本共用工具(编写技能或脚本时请引用)
以下工具由 AI 任务台 经 JSON tool_calls 调度,也可由页面脚本经 GM_hx0CallTool 直接调用(详见 §4.3)。自定义技能正文里写步骤时,请使用工具 ID 并说明用途,便于模型在浏览器同源会话下真实发包验证,而不是写 curl/外部脚本替代。
| 工具 ID |
能力说明 |
典型用途 |
capture.history |
拉取当前目标站点的历史抓包记录 |
找相邻接口、参数名、Cookie/登录态上下文 |
browser.navigate / browser.back / browser.forward | 控制绑定的真实测试标签页并返回新快照;默认限制在任务目标域 | 复用现有登录态导航,无需另装 Browser MCP |
browser.snapshot | 生成无障碍页面快照与元素 ref(密码值脱敏);boxes: true 可附带视口坐标 | 先理解页面结构,再按 ref 精确操作 |
browser.click / browser.hover / browser.type / browser.select_option / browser.press_key | 按 ref 点击、悬停、输入、选择或按键 | 登录、搜索、菜单、弹窗与交互验证 |
browser.wait / browser.console / browser.screenshot / browser.resize | 等待动态 UI、读取控制台日志、截取视口/整页/元素证据、模拟响应式视口 | SPA 状态、脚本错误、Canvas/验证码、手机/平板布局 |
source.audit |
审计页面 HTML / 响应体中的源码、注释与隐藏线索 |
CTF 源码题、前端泄露、注释 hint |
replay.request |
重放一条 HTTP 原始请求并返回响应 |
验证单个假设,形成 request/response 证据闭环 |
replay.dom |
页面内重放:浏览器真实导航或 urlencoded 表单 POST 后提取 DOM(可选 dom_wait_ms) |
密文/挑战页/WAF 动态 HTML;与重放台「页面内重放」同源;单请求验证用此工具,批量 §注入点§ 用 microfuzz.run(use_dom:true) |
packet.mutate |
基于已有 raw 请求,对指定参数注入 payload 变体 |
SQLi / XSS / 命令注入等单参数试探 |
fuzz.plan |
在你提供 seed_values 时扩展 Fuzz 变体计划 |
有证据的种子值上做小规模变体,非盲字典扫描 |
codec.transform |
MD5/SM3/SHA/HMAC、Base64/Hex/URL/Unicode、JWT/JSON/时间戳、AES/DES/RSA/SM2/SM4、auto_probe 智能套娃解码;AES/RSA/SM 可传 key/iv/mode;无 chain[],多步请多轮调用 |
CTF 编码题、JWT 篡改、前端加密验证、过滤绕过前的解码分析 |
crypto.logic.analyze |
结合 rawRequest、可选 parameter/fieldName 与同页 JS/HTML,研判 sign/token/密码等字段的加密逻辑链路 |
前端 sign 题、登录加密、JS 逆向前的链路定位;与重放台「加密逻辑智能分析」同源 |
llm.history / llm.chat |
识别页面 Chat API;拉取历史或追加 user 消息做多轮对话 |
CTF 提示词注入 / LLM 题型多轮套话 |
upload.probe |
识别页面中的上传表单、字段名与上传面 |
文件上传题入口发现、字段定位 |
upload.fuzz |
生成 multipart 上传绕过变体(扩展名/双扩展/空字节/图片马等),可选执行 |
上传过滤、Content-Type 绕过验证 |
ws.probe |
从页面 HTML 识别 WebSocket 端点(ws:// / wss://) |
WebSocket 入口发现 |
ws.fuzz |
经后台 WebSocket 重放发送 JSON / 文本帧 |
WS 消息注入、协议逻辑探测 |
header.probe |
识别 internal / 403 等页面的 HTTP 头绕过线索 |
内网页、管理后台、路径保护场景 |
header.fuzz |
生成 Referer / X-Forwarded-For / X-Role 等头绕过矩阵并通过 raw 重放验证 |
头鉴权绕过、IP 限制绕过 |
settings.read |
读取界面语言、AI 是否已配置等运行时设置 |
脚本/浮层 i18n、启动前检查 AI 配置 |
sensitive.scan |
对 URL/HTML/响应体做敏感规则匹配,返回 items[] 具体匹配文本 |
页面情报、凭证/密钥泄露初筛 |
darklink.scan |
单页暗链检测;可选 use_dom 走 DOM 分析 |
页面浏览时实时暗链摘要 |
darklink.batch |
对多条 recordId 或同 host 历史批量暗链扫描 |
批量暗链工作台、历史复核 |
capture.inspect |
单条抓包记录的敏感 + 暗链 + flag 线索联合分析 |
CTF 单包深挖、联合研判 |
microfuzz.run |
在 raw 请求 §注入点§ 上批量 payload,可选 use_dom |
微型 Fuzz 自动化、脚本编排 |
fuzz.execute |
执行 Fuzz 计划并自动重放验证 |
有计划的小规模变体验证 |
ai.complete |
复用鹰眼 AI 配置生成文本(prompt 必填) |
智能渗透助手、动态报告文案 |
markdown.render |
将 Markdown 转为 HTML |
浮层展示 AI 输出报告 |
编写示例:「先用 capture.history 找带 sign 的 POST,再 crypto.logic.analyze 研判签名链路,用 codec.transform 验证 MD5/Base64 假设,packet.mutate 改写 sign 后 replay.request 闭环。」页面脚本调用方式见 §4.3。
编写内容建议
- 写清适用场景、不适用场景;验证步骤请引用上表工具 ID 与能力,便于 AI 任务台或页面脚本组织可回放的低噪动作。
- 正文宜分节(步骤、表格、示例 payload / 请求片段),避免超长无标题段落。
- Payload 与利用细节请限定在授权测试、CTF 靶场或自有实验环境;勿在技能中硬编码真实账号口令。
容量与数量限制
- 最多保留 32 个导入技能(内置知识库不计入)。
- 单技能正文约 80 KB;每个 reference 约 32 KB;每个技能最多 24 个 reference 文件。
导入后管理
- 在高级设置列表中可启用/停用、删除(内置库不可删)、展开子模块勾选、点编辑修改 markdown(改动存本机)。
- 新导入的技能默认启用;全局子模块默认全选,可在 AI 任务内再缩小本次注入范围(见 §10)。
Firefox 用户 · 导入技能:与 §4.1 批量导入类似,Firefox 会在独立小窗口中选择文件或目录(避免主弹窗被系统文件框关闭)。完成后请再点一次工具栏扩展图标回到弹窗查看导入结果。
17. 联系作者
使用问题、Bug 反馈、商业合作等,欢迎通过以下方式联系 Hx0战队:
0. What is this tool?
Hx0 HawkEye is a browser extension for Chrome and Firefox: the toolbar popup toggles capture/intercept, edits target rules, and opens the capture UI; the sidebar is the main workspace for history, intercept, and replay. Shared behavior is documented here; browser differences are in §14.
The Community path is Capture → Inspect → Intercept & tamper → Normal replay → Basic crypto & encode. Pro builds on top of that with browser-level Agent, Browser Automation MCP, DOM Replay, Micro Fuzz, Page Script Injection, Dark-link scan, AI analysis, AI Tasks, Skills knowledge bases, and batch workbenches.
Beginner-friendly
Fast packet capture
Replay support
Sensitive detection
AI analysis
Browser-level Agent
Browser Automation MCP
v1.0.6Release highlights
- HawkEye Browser Automation MCP (PRO): positioned like a security-specialized Playwright MCP, it combines navigation, clicks, input, and snapshots with HawkEye capture, replay, mutation, sensitive-data, and evidence tools over stdio, Streamable HTTP, or legacy SSE.
- Browser-level Agent capability (PRO): Agent Mode requires an active trial or Professional license. It plans and executes multi-turn navigation, complex controls / iframe interaction, traffic analysis, replay verification, and downloads inside the user's real browser session—not merely chat or one-shot AI analysis.
- Community capabilities opened since v1.0.5: Smart Proxy Router, Full Deep Search, built-in/custom Sensitive Matching, and keyword libraries are available in Community starting with v1.0.6.
- Capture, replay, and WebSocket performance is improved for large responses, files, and high-volume pages while preserving binary-message integrity.
- Trusted input and evidence preservation on Chrome / Firefox: hardened trusted keyboard/mouse input plus Firefox native-input fallback for protected
userActivation actions such as fullscreen; browser_screenshot can now optionally save PNG/JPEG evidence to a local file.
- AI-task and long-running reliability is improved through safer log persistence, timeout / cancellation cleanup, and robust MCP reconnection.
- Chrome / Firefox parity is reinforced with automated integrity and regression checks.
- Capture UI shortcut: default
Ctrl+H (Control+H / ⌃H on Mac, not Command or Option); you do not need to open the popup first. Chrome toggles the capture side panel—change the combo at chrome://extensions/shortcuts. Firefox toggles the in-page capture float (use “Dock to sidebar” inside it); record a new combo in Advanced Settings, and press again to close.
0909 release update: Models and memory: add DeepSeek V4.1 Flash (image-capable) as a candidate, switch the OpenAI default to GPT-6 Astra while keeping GPT-5.6, and honor max/low thinking parameters; history-summary recall is off by default; a new default persona, “HawkEye Universal Browser Assistant,” is added. Agent UX: Import Conversation is now a small header button to the left of “+”, restoring tool cards from exported Markdown; Skills start off, the picker opens up-and-right from the Skills button, a second click closes it and deselects the button, and smart routing no longer caps how many skills load; task suggestions cover everyday browsing (for example opening Bilibili, searching Ultraman, and playing a result) as well as security troubleshooting. Reliability: fixes stale-tab actions after a switch, crashes after closing the task tab, unintended downloads during file discovery, and checkpoint limits blocking new tasks; improves Goal/Plan progress retention, interruption recovery, and duplicate-submission protection; Skill save now shows a real receipt, and empty responses / exhausted output budgets retry at most once.
1. 5-minute beginner setup
Install the ZIP release: for Chrome, extract the ZIP to a stable folder, open chrome://extensions, enable Developer mode, choose Load unpacked, and select the folder containing manifest.json. For Firefox, extract the ZIP, open about:debugging#/runtime/this-firefox, choose Load Temporary Add-on, and select manifest.json (load it again after restarting Firefox). Official releases are ZIP-only, with no CRX/XPI: this avoids Chrome disabling externally installed CRX packages and gives both browsers one inspectable unpacked-install path. Before upgrading, export anything important; replace the old folder contents and click Reload in the extension manager.
- Turn on Capture only (leave Intercept off first).
- Set capture target hosts (e.g.
*.example.com). Fresh installs enable XHR/Fetch, WebSocket, HTML, JS, JSON, and XML for a high-value default; on very busy sites, temporarily keep only XHR/Fetch + WebSocket to reduce noise.
- Browse your app and trigger requests.
- In the popup click Capture UI to open the sidebar, or press the default shortcut
Ctrl+H (Control+H on Mac, not Command; see §4). Switch to History; it defaults to current page. Filter by host/method/status/search.
- Expand details: start with
Pretty, then Raw (unformatted text), Hex, Render, Sensitive as needed.
- Use
Replay to modify and verify behavior. The Community edition already covers the core closed loop of capture → inspect → normal replay.
- Step 7 (Pro · optional): try the four detail-bar Pro actions—Detect dark links / AI Analyze / AI Script / Smart Crypto Logic Analysis (see §5.2); enable built-in Page Intel / Smart Decode / Smart Pentest scripts while browsing (see §4.4); open AI Tasks when you need full auto verification (see §10).
Tip: Start with capture + inspect + normal replay; then add intercept/tamper as needed. Pro adds DOM replay, Micro Fuzz, Page Scripts, dark-link, and AI.
2. Popup overview
Click the extension icon in the toolbar to open the Hx0 HawkEye popup. The header has three tabs:
- Basic: capture/intercept toggles, target hosts, capture types, proxy router—see §3.
- Advanced: language, page scripts, AI, Skills, sensitive rules, dark-link—see §4.
- Capture UI: opens the sidebar workspace (History / Intercept / Replay / AI Tasks).
The status badge (top-right) shows Community / trial / Pro. Single-click opens activation; double-click (when licensed) opens license details—see §13. Chrome also offers a dedicated options page via chrome://extensions → Details → Extension options.
You do not need to open the popup every time: the default shortcut Ctrl+H (Control+H on Mac) toggles the capture UI. Chrome toggles the side panel; Firefox toggles the in-page float. See §4 and §14 for remapping and browser differences.
3. Basic settings
Controls what to capture, from which sites, and which resource types, plus intercept, proxy routing, and Chrome passive body capture.
- Capture: must be on to record new packets.
- Capture & intercept target hosts (one shared field):
- Multiple lines or comma-separated;
*.example.com wildcards supported.
- Empty = all domains (noisy—not recommended for beginners).
- Same rules apply to the intercept queue when intercept is on.
- Capture types / suffixes:
- Recommended fresh-install default: enable
XHR/Fetch, WebSocket, HTML, JS, JSON, and XML; leave CSS, Other text, BINARY, and Flash off. This captures APIs, entry documents, frontend endpoint/signing logic, JSON/XML configuration, and WebSocket frames without most style/binary asset noise.
- Keep JS on by default for hidden APIs, sign/token logic, source maps, and dynamic resources. Disable it temporarily only when a script-heavy site creates excessive noise.
- Custom suffixes e.g.
php, asp, aspx; * disables suffix filter (very noisy).
- Capture and intercept share filters. Keep the full default set for capture; while intercepting, narrow the target host and prefer XHR/Fetch + WebSocket so pausing HTML/JS/XML does not stall the entire page.
- Smart Proxy Router (Community): below capture types, collapsed by default. Its upstream preset uses the same custom selector style as the model menu and closes automatically after selection.
- Route matched browser requests to an upstream proxy (e.g. Burp/Yakit); others stay direct.
- Firefox: Compatibility mode vs Takeover mode—see §14.
- Click Save after changes; trust upstream CA for HTTPS.
- Intercept (Community): pause matching requests for edit/release/drop in the sidebar.
- Intranet/self-signed HTTPS body (passive) (Chrome only): enable and refresh when bodies look incomplete. Firefox has no equivalent toggle—see §14.
- Floating ball: toggles the in-page quick entry.
Useful profiles: default capture → XHR/Fetch + WebSocket + HTML + JS + JSON + XML; high-volume noise reduction → XHR/Fetch + WebSocket; precise intercept → narrow target host + XHR/Fetch.
3.1 HawkEye Browser Automation MCP (PRO)
Access: this feature carries a PRO label. The guide and server download remain visible; an active trial or license enables the extension bridge and MCP tools.
The MCP server is not an AI model or chat client. It is a local bridge that exposes HawkEye browser, capture, intercept, replay, and evidence tools to an MCP Host/Agent such as Codex, Cursor, or Claude Code.
Install the single-file server
- Install Node.js 18+ and verify it with
node -v.
- In popup Basic settings, click Download MCP Server. The downloaded
hawkeye-mcp-server.mjs is a single zero-third-party-dependency file; no npm install and no companion module are required.
- Click Copy universal config. HawkEye records the browser's actual download path and places that absolute path in
args.
Configure an MCP Host
Use stdio when possible: the Host starts the server automatically, so you do not run it manually. The placeholder below is documentation syntax only:
{
"mcpServers": {
"hx0-hawkeye": {
"command": "node",
"args": ["/ABSOLUTE/PATH/hawkeye-mcp-server.mjs", "--port", "19016"]
}
}
}
- Claude Code, Cursor, LM Studio: use the
mcpServers command/args form above.
- Codex: use
[mcp_servers.hx0-hawkeye] with the same command and args.
- OpenCode: create a local MCP whose command array contains
node, the absolute file path, --port, and 19016.
- OpenClaw, Hermes, TeleAgent, DeepSeek Harness, DeepSentry, and custom agents: use their standard local/stdio or HTTP MCP configuration. HawkEye has no product-name allowlist.
- DeepSeek and Ollama supply models/runtime; select them inside an MCP-capable host, then register HawkEye with that host.
Codex TOML example:
[mcp_servers.hx0-hawkeye]
command = "node"
args = ["/ABSOLUTE/PATH/hawkeye-mcp-server.mjs", "--port", "19016"]
For URL-only hosts, run node "/absolute/path/hawkeye-mcp-server.mjs" --port 19016 and connect to http://127.0.0.1:19016/mcp (or legacy /sse).
Connect and verify
Restart the host, open a normal HTTP(S) tab, enable the HawkEye MCP switch to bind that tab, and wait for MCP Server connected. Test with: Use hx0-hawkeye to open https://example.com, read the title, and take a screenshot.
If the bridge is unavailable, reload HawkEye on the browser extensions page. On recent Chrome versions, choose Allow if the first enable asks for local-network access. If it stays on waiting, verify Node.js, the absolute path, and matching port. The bound tab must be active for screenshots; browser-internal pages cannot be automated.
Tool coverage: 31 browser/research tools plus 20 capture/security-evidence tools. The browser layer covers stable accessible targeting, screenshots, frames/Shadow DOM, forms, responsive testing, native downloads, first-party authorized CAPTCHA assistance, structured TLS evidence, and multi-source research. HawkEye tools add capture history, replay/mutation/controlled fuzzing, Scope/findings, local codec auto-probing, page scripts, sensitive/dark-link scans, and intercept-queue control. Third-party anti-bot challenges remain manual.
Trusted input, fullscreen, and userActivation
- Chrome prioritizes CDP
Input.dispatchKeyEvent / Input.dispatchMouseEvent. On supported desktop environments, Firefox can fall back to a local native keyboard/mouse relay for protected operations such as fullscreen.
- HawkEye normalizes stale page focus before keyboard input so
F is not swallowed by a button or text field. For sites such as Bilibili, ask the Agent to play the video and press F for fullscreen.
navigator.userActivation.isActive is transient and may already be consumed after fullscreen succeeds. Judge the result using returned eventEvidence.isTrusted/isActive, userActivationObserved, and the actual document.fullscreenElement state—not a delayed isActive check alone.
Optionally save screenshots as local evidence
Calls without the new fields keep the original behavior: image output only and no disk write. To preserve a WriteUp/evidence file:
{
"save_to_file": true,
"file_path": "/absolute/path/evidence.png",
"overwrite": false
}
- An absolute path is used directly. A relative/missing path is resolved below
HAWKEYE_SCREENSHOT_DIR, or $CWD/screenshots/ when the variable is unset, with a sanitized generated name.
- Directories are created only when saving is requested. Existing files are protected unless
overwrite:true. Success returns the absolute path plus saved_to, file_path, and file_bytes.
- A permission/disk failure never breaks the original image response; text reports that the screenshot was generated but could not be saved.
Efficient browser work: snapshot → locate → act → verify
Following Playwright MCP's structured snapshots and explicit element references, read page structure first and take screenshots when images, Canvas, or layout require them. Check tool receipts and the resulting page state after acting.
- Read the relevant area: start with
browser_snapshot, which defaults to a compact viewport snapshot. Use browser_find for known text and focus for a region. Request viewport_only=false when offscreen content is needed. Continue large results with page_token against the same cached page; never rerun a write just to obtain the next page.
- Use current references: use a
ref from the latest snapshot. Refresh after navigation, list replacement, or switching tabs. If a reference expires, locate the current target before another click.
- Reduce round trips: fill known fields together with
browser_fill_form. Wait for text, URL, or element state with browser_wait_for. Use diff=true to track changes and request boxes only when coordinates are needed.
- Respect action order: run navigation, clicks, typing, and submissions sequentially on the same tab. Only independent read operations should use limited concurrency. Tool annotations help the Host assess effects; they do not grant authorization.
Cancellation, busy responses, and disconnects: cancellation ends the server wait and asks the extension to stop subsequent work. Browser actions already dispatched cannot be rolled back. Read the current page before retrying after a timeout or disconnect. If the server is busy, wait for active calls to finish. After an extension update, download the matching MCP Server again and restart the Host.
Stable pagination and capability profiles: context.next_page_token points at one immutable result, valid for two minutes in the current MCP session. Continue with page_token alone. Mixing a numeric cursor or changing focus is rejected instead of silently joining a different snapshot. Use --profile core or --caps to shrink the tool catalog. Slow stdio clients and oversized output are backpressured; that transport may close while HTTP sessions remain available.
3.2 MCP vs Agent, and how HawkEye compares with mainstream Browser MCPs
Three related but different concepts
| Name | What it is | Setup | Best fit |
| HawkEye MCP | A local tool server exposing real-browser control and HawkEye capture/intercept/replay/evidence to an external AI Host; it contains no model | Node.js 18+, the single-file server, and MCP config in Codex/Cursor/Claude Code/etc. | You already work in an external Agent and want it to use HawkEye |
| Built-in Agent Mode | HawkEye's own multi-turn planning/chat UI, directly calling its tool runtime | No third-party MCP Host; requires trial/Pro plus a configured Base URL, API key if needed, and model | You want conversational browsing, analysis, verification, and reporting inside the extension |
| AI Tasks | A repeatable workflow with Scope, directions, Skills, safety gates, and structured reports | Shares Agent AI settings; also configure task scope, directions, and Skills | Authorized security reviews, CTF, evidence batches, and repeatable reports |
Set up and use the built-in Agent
- Open Advanced → AI analysis settings; select a provider and enter Base URL, API key if required, and Model. Run one ordinary AI analysis first to verify connectivity.
- Open the target HTTP(S) page. For traffic analysis, turn capture on and set a precise target host first.
- Open Capture UI → Agent Mode, start a conversation, choose the safety level and eligible Skills, then state the outcome. Example:
Open the current site's login page, observe requests, and explain the auth flow without submitting data.
- Review receipts/confirmations for sends, downloads, replay, mutation, or other consequential actions. Do not let built-in Agent and an external MCP Agent drive the same tab at the same time.
Smart search in Agent and MCP
browser_search preserves the main query and adds evidence variants from queries; includeDomains matches any listed domain. Automatic engines follow query language and duplicate links are merged. Research shares a three-tab concurrency limit within the extension; cancellation stops subsequent stages and closes temporary tabs.
Use maxFetches or browser_research to verify page bodies. Research prioritizes different domains and excludes challenge pages from usable evidence. Ranking scores measure retrieval relevance only. Check degradation, stale-cache and truncation indicators; refine queries or read selected sources before concluding.
Choices that offer to provide information, including custom input, close the dialog and wait for actual text in the composer. No model request runs while waiting. Repeated identical tool observations trigger recovery guidance and then an explicit unfinished pause.
Goal mode: pause, resume and completion
- The goal remains until the Agent explicitly confirms the entire outcome. A finished reply, queued download or partial step does not clear it.
- Use Pause to save progress and Resume to continue the same goal, even with an empty input queue. Confirmed operations are skipped; uncertain submissions require verification.
- Missing information or the turn limit leaves the goal blocked. Reply with the missing details or “continue”. Editing stops the previous goal first; deleting stops execution while preserving the conversation and queued inputs.
Positioning against mainstream browser MCPs
Based on public official documentation available on 2026-08-30. Projects evolve; use the official links below for current details.
| Project | Browser/session | Main strength | Capture/intercept/security workbench | Best fit |
| Hx0 HawkEye MCP | Chrome + Firefox; binds the user's existing logged-in tab | Accessible snapshots + optional vision, trusted input, browser actions and security evidence in one path | Built in: request headers/bodies, responses, WebSocket, intercept/edit/release/drop, replay, mutation/fuzz, sensitive/dark-link evidence, Scope/findings, and screenshot file save | Authorized in-browser security review, forensics, CTF, capture-driven analysis, especially a real Firefox session |
| Microsoft Playwright MCP | Launches Chrome/Firefox/WebKit/Edge with persistent or isolated profiles; its existing-browser extension path is primarily Chrome/Edge | Accessibility-tree targeting, cross-browser automation, forms, network mocking, tracing, tests, and CI | Strong general network/automation features, but not positioned as a persistent HawkEye-style intercept/replay/fuzz security workbench | Cross-browser functional testing, isolated sessions, test code, and CI |
| Chrome DevTools MCP | Chrome / Chrome for Testing; can attach to running Chrome | DevTools/Puppeteer debugging, Console, Network, performance traces and recommendations | Deep Chrome debugging evidence, but not a Chrome+Firefox intercept queue and security replay/fuzz/sensitive-evidence workflow | Chrome frontend debugging, performance, Console/Network diagnosis |
| Browser MCP | Chrome extension + local server; connects an existing logged-in tab | Low-friction local navigation, clicks, forms, snapshots, and screenshots | Official docs focus on general browser automation and do not list HawkEye's full capture/intercept/tamper/replay/fuzz/evidence or Firefox path | General Agent actions in an existing logged-in Chrome session |
Selection guide: choose Playwright MCP for isolated cross-browser automation and CI; Chrome DevTools MCP for deep Chrome performance/DevTools work; Browser MCP for simple existing-Chrome actions; HawkEye when you need capture + intercept + tamper + replay + security evidence + a consistent Chrome/Firefox workflow. They can also be combined by task phase.
Official sources: Playwright MCP · Chrome DevTools MCP · Browser MCP.
4. Advanced settings
Language, page scripts, AI, Skills, deep search, sensitive matching, dark-link, and payload encoding. Items marked Pro require a license.
- Language: UI locale (also affects AI prompt language).
- Capture UI shortcut: default
Ctrl+H; on Mac this is Control+H (⌃H), not Command or Option. It works while the web page has focus—you do not need to open the popup first.
- Chrome: toggles the capture side panel. Chrome does not let extensions change this shortcut themselves. Advanced Settings shows the current combo and an Open settings button that opens
chrome://extensions/shortcuts. Find “Toggle the Hx0 HawkEye capture panel” and rebind; the page display is authoritative.
- Firefox: toggles the in-page capture float (not the native sidebar). Use “Dock to sidebar” inside the float; press the same shortcut again to close. Click Record then press a new combo, or Reset to restore the default.
- Page Scripts (Pro): master switch, enabled count, script workbench entry, and browser permission status. Usage is covered in §4.2.
- AI analysis settings (Pro): OpenAI, DeepSeek, Anthropic, Kimi, Zhipu GLM, Xiaomi MiMo, SiliconFlow, local LM Studio, and custom profiles are stored independently. Provider, Base URL, API key, model, and related toggles save automatically after changes.
- Automatic endpoint detection: HawkEye infers the provider and billing route from the Base URL; there are no separate Coding Plan / Token Plan / pay-as-you-go buttons. Zhipu standard API or token bundles use
https://open.bigmodel.cn/api/paas/v4, while Coding Plan uses https://open.bigmodel.cn/api/coding/paas/v4. Xiaomi pay-as-you-go uses https://api.xiaomimimo.com/v1; Token Plan uses the regional URL shown on the plan page, for example https://token-plan-cn.xiaomimimo.com/v1. Known provider/URL crossovers, including legacy swapped GLM/MiMo profiles, are repaired automatically.
- Current model presets: the OpenAI default is now
gpt-6-astra (GPT-6 Astra), with GPT-5.6 still selectable. DeepSeek adds deepseek-v4.1-flash-expires-on-0910 with text and image input. Saved model choices are preserved. The GPT-6 Astra deep-thinking toggle uses max / low; versioned and dated DeepSeek V4 model names also receive the thinking preference.
- Multimodal image input: selecting a model in the built-in vision catalog automatically enables the checkbox—for example
glm-5.3-flash, deepseek-v4.1-flash-expires-on-0910, deepseek-v4-flash-vision-exp, gpt-6-astra, claude-opus-5, kimi-k3/kimi-k2.6, and mimo-v2.5. Unknown/custom models default off and may be confirmed manually. A manual override persists until the model changes and capability detection runs again. mimo-v2.5-pro is not auto-enabled for image input.
- Context window: all preset and custom values are measured in tokens, not KB/MB;
128K is about 131072 tokens, and 1M is 1000000 tokens. Choose Custom to enter the official model limit, or leave it blank for automatic detection.
- Auto-redact before send is on by default for AI analysis and AI Tasks. Disable it only for an authorized workflow when replacing cookies/auth headers prevents correct analysis.
- AI Skills (Pro, below AI settings):
- Built-in knowledge bases (HawkEye-native):
Hx0 Pentest Knowledge Base (19 sub-modules) and Hx0 CTF Knowledge Base (28, Web/Misc + AI track). Verification uses in-extension tools only—no sqlmap/curl CLI required. CN/EN reference pairs; stored locally; sent to your configured model endpoint when injected.
- Sub-module management: toggle per module; Edit overrides markdown (saved locally). Full catalog in §16.
- Direction linkage:
Custom directions auto-selects matching modules (e.g. SQLi → injection-attacks); AI decides starts with hawkeye-runtime + methodology + fingerprint recon. Each main skill on the AI Tasks panel has a Smart inject toggle (hover for tooltip): when on, that library may append sub-modules mid-task from evidence (log: “Mid-task Skills injection”); when off, only your manually selected modules are injected at task start.
- Expanded topics: pentest
js-reverse, ai-site-workflow, ai-llm-security; CTF misc-encoding, js-reverse, prompt-injection, and four ctf-ai-* modules.
- AI Generate Skill (Pro): click
AI Generate Skill in the Skills section (AI endpoint required). Describe methodology or vuln types in natural language; output a single skill or a collection (2–6 related modules). Generated content aligns with HawkEye tool IDs (replay/mutate/capture, etc.); edit, export, or regenerate before save. Save targets: standalone Skill, pentest/CTF built-in sub-module, standalone Skill with references, or append to an imported skill—see §16.
- Agent learning: only an explicit Agent command such as “remember this workflow,” “remember this mistake,” or “save this as a Skill” distills verified steps and lessons into a standalone Skill. Every attempt gets a truthful success/failure receipt. The
Agent learned Skill can be viewed, edited, disabled, or deleted here.
- External import + authoring rules in §16 (max 32 custom skills).
- Global allowlist: only main Skills and sub-modules checked in Advanced Settings are eligible for AI Tasks or Agent Mode. Relevance matching cannot bypass an unchecked Skill. Enable Skills by default in AI Tasks affects only AI Tasks; it never enables Skills in Agent Mode. Task usage is in §10.
- Payload smart encoding: optional URL-encoding of selected payload characters.
- Deep full-body search (Community): sidebar search scans entire bodies (slower on large histories).
- Sensitive matching:
- Built-in rules (ID/phone/card, JWT/Shiro fingerprints, IP, domain, CTF flag, etc.)—Community.
- Regex + second-pass validation: ID checksum, bank-card Luhn, JWT structure, email/domain/IPv4 context filters, Shiro path/Cookie features, CTF prefix whitelist—reduces JS domain fragments, semver IPs, asset filenames.
- IPv4/IPv6/domain rules are off by default; enable in Advanced when needed (still validated).
- Custom regex/keywords + batch import/export—Community, see §4.1.
- Dark-link / static threat (Pro): built-in rules (CSS hide, off-screen, nested resources, dynamic text, hard-coded IPs); CDN/analytics whitelist + high-trust roots; chameleon-only or a11y
sr-only alone no longer alerts. Usage in §9.
Model refresh and configuration changes: refreshing discovery updates the available list while preserving an entered model, including older names and private deployments. A new recommendation never silently upgrades it. Changing provider, Base URL, or key cancels the previous discovery request; late results cannot overwrite newer settings. Each provider uses its own key, so a new profile requires its own credentials. You can still enter a model manually if discovery fails. Use a complete HTTP(S) Base URL, enter the API key separately, and omit URL credentials and #fragments.
Streaming and capability contracts: the background now streams when the provider allows it and records first-token latency, total time, tokens, and retries. 429/5xx responses honor Retry-After within the overall budget; incomplete streams are not paid-retried. Native tools, structured output, images, and thinking fields follow the current model contract and are not silently treated as success when unsupported. Cancellation stops further retries.
4.1 Custom regex & keywords: batch import, export, clear all
Open Advanced → Sensitive matching → Manage custom regex or Manage keyword library. Built-ins, custom regex, keyword libraries, and batch import/export are all available in Community.
- Add rule: fill name, pattern or keywords, color—then tap the blue Add rule button.
- Clear all: red button next to Add rule; clears the current list in that dialog (regex and keywords are cleared separately). Confirmation is shown first.
- Download template: downloads a small table with headers. The first data row under the header is a sample; it is skipped on import—you usually do not need to edit it.
- Batch import: pick your filled file. Custom regex CSV must have columns
name, pattern, color (typically #RRGGBB). Keyword library uses name, keywords, color.
- Batch export: exports current rules for backup or moving to another machine.
- Import summary: after import you see counts for added / skipped / invalid rows. If a color collides with built-ins, the extension nudges colors to reduce duplicates.
Firefox · batch import: choosing a file and clicking Open often closes the main toolbar popup. HawkEye opens a small extra window so the import can finish. Follow the on-screen text, then click the extension icon again to reopen the popup and see updated rules. That helper window follows your Advanced → Language choice.
4.2 Page Script Injection (Pro)
Open Advanced → Page Scripts in the popup for the master switch and status; click Open Script Workbench to jump to the sidebar Scripts tab. The workbench offers New, AI Create, Import, and Export; from the History list you can also right-click Create page script from traffic with AI. In plain terms: stop pasting into DevTools Console—save scripts once and run them on the current page or matched domains.
- Step 1: create a script: open the
Scripts tab, click New or AI Create, and give it a clear name.
- Step 2: write code: the Script Code editor supports line numbers, keyword search, one-click formatting, and basic syntax check. If something looks wrong, click
Check Syntax first.
- Step 3: choose safe defaults: beginners should keep
After page load (Recommended), Safe isolated world (Recommended), and Run manually.
- Step 4: run manually: click
Save, then Inject Current Page. Only HTTP/HTTPS pages are supported; extension pages, browser-internal pages, and non-web URLs are blocked with a hint.
- Step 5: enable auto-injection only after testing: after confirming the script works on the target site, switch scope to
Auto-inject matched domains and enter rules such as *.example.com, example.com, or full URL patterns. Auto-inject all pages has the widest impact and is not recommended as the first choice.
- Import Tampermonkey scripts: import a
.user.js file or paste code with a // ==UserScript== header. HawkEye detects @name, @match, @include, @require, @grant, @run-at, and @noframes. @require dependencies are loaded through background GM requests where possible to avoid page CORS and mixed-content blocking. If a script depends on jQuery and external CDNs are unavailable, HawkEye falls back to a built-in lightweight jQuery compatibility layer for common selectors, events, and DOM edits.
- Captcha script setting: enable
Inject iframes too when the captcha or login field is inside an iframe. Tampermonkey normally runs matching scripts in frames unless the script declares @noframes.
- AI create & optimize:
AI Create in the workbench is for a blank start when you do not yet have a concrete packet. Create from traffic with AI (detail bar AI Script, row action, or multi-select) is for when you have already found the key request in History and need a script grounded in real URLs, param names, response fields, and auth headers—far more reliable than describing the site from memory. After saving, AI Optimize can improve structure, error handling, or wire in GM_hx0CallTool (the system auto-increments the @version patch and appends an optimization note). Always Inject Current Page to verify before enabling auto-injection.
- GM script menus: scripts using
GM_registerMenuCommand show menu buttons under the expanded sidebar item and are auto-fetched (you usually do not need to switch to a matching tab or refresh the page). If another open tab matches @match, HawkEye prefers that tab for probe/inject; when the sidebar page does not match, menus may still appear with a hint such as “menus from matching tab #xx”. If still empty, click Inject and refresh menu.
- What the options mean:
After page load waits until the page is mostly ready; After DOM is ready runs earlier; At page start is earliest and fits early hook/override scripts. Safe isolated world is steadier; use Page main world only when the script must modify the page’s own window globals.
- Permission differences: Chrome includes
userScripts in the install manifest; if the API is still unavailable, manually enable Allow User Scripts under chrome://extensions → this extension’s details (browser policy—extensions cannot flip it for you). Firefox lists userScripts as optional—follow the workbench guide; after updating the extension, reload it once in about:debugging before injecting again.
- Import/export: the workbench supports JSON backup and migration. Import only trusted scripts and use auto-injection only on sites you are authorized to test.
- Call HawkEye tools: custom scripts can reuse capture, replay, sensitive/dark-link scan, codec, fuzz, and more via
GM_hx0CallTool—see §4.3.
4.3 Custom page scripts & HawkEye tool API (Pro)
This section explains how to call HawkEye’s tool runtime from your own page scripts instead of re-implementing capture, replay, sensitive/dark-link scans, or codecs in the page. AI Tasks and page scripts share the same tool IDs; AI Tasks schedule them via JSON tool_calls, while your script calls them directly in JavaScript.
Prerequisites
- Pro + page scripts master switch enabled in Advanced (§4.2).
- Declare
// @grant GM_hx0CallTool in metadata (HawkEye can auto-add grants from code).
- For
capture.history, recordId, or combined analysis: enable capture in the popup and generate traffic on the target tab first.
- Before
ai.complete: configure API Key / model under Advanced → AI analysis; use settings.read to check aiConfigured.
- Use only on authorized tests, CTF labs, or your own sandboxes.
Minimal template
// ==UserScript==
// @name My HawkEye helper
// @match *://*/*
// @grant GM_hx0CallTool
// @grant GM_addStyle
// @run-at document-idle
// ==/UserScript==
(function () {
'use strict';
async function call(tool, input) {
if (typeof GM_hx0CallTool !== 'function') {
throw new Error('Run inside HawkEye page-script environment');
}
return GM_hx0CallTool(tool, input || {});
}
call('settings.read', {}).then(function (cfg) {
console.log('lang', cfg && cfg.uiLanguage, 'aiConfigured', cfg && cfg.aiConfigured);
});
})();
Hx0.callTool('replay.request', input) is equivalent to GM_hx0CallTool. Calls go through the extension background with the current tab context; default timeout is about 120s. Failures reject the Promise with an error field.
HawkEye ships three built-in user scripts (Page Intel / Smart Decode / Smart Pentest). Enable them as-is or fork their code. Full feature and usage details: §4.4.
Tool API reference (page scripts & AI Tasks)
Common patterns
1
Scan current page for sensitive hits and dark links
var html = document.documentElement.outerHTML.slice(0, 120000);
var payload = { url: location.href, html: html, responseBody: html };
Promise.all([
GM_hx0CallTool('sensitive.scan', payload),
GM_hx0CallTool('darklink.scan', Object.assign({ use_dom: true }, payload))
]).then(function (rows) {
console.log('sensitive', rows[0] && rows[0].items);
console.log('darklink', rows[1] && rows[1].threats);
});
2
Recent capture for same host
GM_hx0CallTool('capture.history', { targetHost: location.hostname, limit: 20 })
.then(function (res) { console.log((res && res.rows) || []); });
3
Replay (need raw request from capture or sidebar)
GM_hx0CallTool('replay.request', {
rawRequest: 'GET /api?id=1 HTTP/1.1\\nHost: example.com\\n\\n',
url: 'https://example.com/api?id=1'
}).then(function (res) { console.log(res && res.status, res && res.responseRaw); });
4
Codec / advanced crypto
GM_hx0CallTool('codec.transform', { action: 'jwtparse', text: 'eyJhbGciOi...' })
.then(function (res) { console.log(res && res.output); });
GM_hx0CallTool('codec.transform', {
action: 'aesdec', text: 'BASE64_CIPHERTEXT', key: '0123456789abcdef', iv: '0000000000000000', mode: 'cbc'
}).then(function (res) { console.log(res && res.output); });
5
Crypto logic triage (needs raw request; Pro)
GM_hx0CallTool('crypto.logic.analyze', {
rawRequest: 'POST /login HTTP/1.1\\nHost: example.com\\n\\nuser=1&sign=abc...',
parameter: 'sign', url: 'https://example.com/login', reason: 'sign may be client-side MD5'
}).then(function (res) { console.log(res && res.summary, res && res.steps); });
6
AI-generated copy (check aiConfigured via settings.read first)
GM_hx0CallTool('ai.complete', {
prompt: 'Summarize likely test entry points on this page in three sentences',
context: 'URL: ' + location.href
}).then(function (res) { console.log(res && res.content); });
Authoring tips
- Prefer callTool: capture, replay, sensitive/dark-link, codec, fuzz, upload/header/WS probes—all via tool API. Your script should collect DOM, render UI, and orchestrate workflows.
- settings.read first: then pick UI language and whether to prompt for AI setup.
- Error handling:
.catch(function () { return { ok: false }; }) so one tool failure does not break the page; scans may return skipped: true when the feature is off in Advanced.
- World & timing: DOM-only scripts →
USER_SCRIPT + document-idle; hook page window → MAIN + document-start (§4.2).
- AI-assisted authoring: workbench “AI generate / optimize” is tuned for
GM_hx0CallTool; always inject manually on the target site before enabling auto-inject.
- vs AI Tasks: AI Tasks auto-schedule tools via JSON; your scripts can provide live intel panels, annotations, and menu helpers while the user browses. Tool IDs match §16 Skills reference.
Debugging: console.log in DevTools Console; tool error explains missing capture, recordId, or AI config. Sidebar Scripts tab → Inject current page for quick trials.
4.4 Built-in user scripts (Pro)
HawkEye includes three built-in page scripts, seeded on first install (marked with a built-in badge). Entry: popup → Advanced → Page Scripts for the master toggle; sidebar → Scripts to enable, edit, inject, or sync each script. Deleting a built-in script restores it on the next extension startup; use Sync from built-in after updates. For automation tied to one captured packet, prefer detail-bar AI Script (§5.2) over blank workbench creation.
| Script | Default | Injection | Main capability |
| Hx0 Page Intel Assistant | On | Manual | Attack-surface collection + sensitive/dark-link scan + DOM highlights |
| Hx0 Smart Decode Assistant | On | All pages (auto) | Decode on text selection + hash/crypto hints |
| Hx0 Smart Pentest Assistant | On | Manual (needs AI) | Capture + source audit + AI pentest triage brief |
① Hx0 Page Intel Assistant
What it does: Collects DOM attack surface on authorized targets and summarizes it in a bottom-right overlay—good for quick recon before manual testing. It does not auto-attack the site.
How to run:
- Ensure Page Scripts is enabled in Advanced; keep this script enabled (default).
- Open the target HTTP/HTTPS page → sidebar Scripts → select Hx0 Page Intel Assistant → Inject current page (or use the GM menu after expanding the script row).
- A Page Intel panel appears bottom-right. Expand the script in the sidebar for GM menu Hx0 Rescan page intel to refresh anytime.
Panel sections (each collapsed by default; click the title to expand):
- Overview: URL, form/hidden/link/endpoint counts, sensitive and dark-link hit totals.
- Forms: Each
<form> action, method, and fields (including hidden/readonly).
- Hidden fields: Scored by high-value names, credential-like values, or noise params—surfaces token/csrf/redirect fields first.
- Links & resources: URLs from a/form/iframe/script, ranked by api/admin/upload/redirect patterns; long URLs expand for copy.
- Script/API endpoints: Inline JS regex extracts fetch/axios/XHR/Request paths.
- Sensitive hits:
sensitive.scan with matched snippets.
- Dark-link threats:
darklink.scan with use_dom: true—threat type and target.
DOM highlights: Forms get a blue solid outline; hidden inputs get an orange dashed outline (hover for name/value preview).
Other actions: Drag, collapse/expand the whole panel, copy JSON (full intel, same as window.__HX0_SCRIPT_INTEL__), close. UI language follows HawkEye settings.read.
Note: Sidebar per-packet dark-link reports remain for deep review/export; this script is a one-screen summary while you browse.
② Hx0 Smart Decode Assistant
What it does: On any page, select suspicious text to auto-try common encodings/classical ciphers and flag MD5/SHA, OpenSSL Salted__, Morse, Brainfuck, etc. Irreversible hashes/ciphertext are labeled accordingly.
How to run: Injected on all pages by default—no manual inject needed:
- Select 2–4000 characters (too short/long is ignored).
- Within ~200ms a Smart Decode panel opens bottom-right with readable results and an algorithm-hints block.
- Copy per row or Copy all; panel is draggable and remembers position.
- GM menu Hx0 toggle smart decode panel reopens/closes for the current selection. To disable global listening, turn the script off or switch to manual injection in the workbench.
Auto decode attempts (sample; multiple hits ranked by readability/nest depth):
- Common: Hex, Base64, Base32, URL, HTML entities, Web/JSON/JavaScript escapes (
\uXXXX, \u{...}, \xNN, %uXXXX), Quoted-Printable, UUencode, binary/decimal/octal ASCII.
- CTF-style: Morse, tap code, Brainfuck, AAEncode, JSFuck, Base58/62/85/92, ROT13/Caesar brute, Atbash, Bacon, affine, Vigenère/Playfair/autokey, rail fence, column route, multi-layer nested chains.
- Hints only: MD5/SHA/SM3 lengths, bcrypt/Argon2, PEM headers, OpenSSL Salted__, high-entropy Base64 blobs—points you to sidebar Advanced Crypto when keys are needed.
vs replay workbench: This script is select-and-decode lightweight use. AES/DES/RSA/SM2/SM4, JWT, auto_probe nested decode, and crypto.logic.analyze live in the sidebar codec menu (§6, Pro).
③ Hx0 Smart Pentest Assistant
What it does: On authorized targets, feeds page context + same-host HawkEye capture + lightweight probes + quick source audit to AI, producing an evidence-first Markdown triage brief—not a full auto-exploit chain (see AI Tasks in §10 for that).
Prerequisites:
- Pro + Page Scripts master toggle on.
- Advanced → AI configured (check
aiConfigured via settings.read).
- Capture enabled in the popup and same-host traffic recorded (otherwise the brief notes missing capture).
How to run:
- Interact with the target (login, navigation) to build capture history.
- Sidebar Scripts → Hx0 Smart Pentest Assistant → Inject current page.
- Loading state, then rendered brief; GM menu Hx0 Refresh pentest analysis re-fetches capture and re-runs AI.
Evidence assembled automatically:
- Page: URL, title, form count, high-value hidden fields, inline JS API hints.
- Capture:
capture.history for the host (prefers rows related to current URL, non-static, api/upload/auth paths)—method/status/request/response snippets.
- Source audit:
source.audit tech stack, notes, flag/sensitive hints.
- Light probes (read-only, no fuzz by default):
header.probe, ws.probe; upload.probe with execute: false when upload UI is detected.
Brief structure (four fixed sections; language follows HawkEye UI):
- Confirmed evidence: Table Evidence | Source | Security meaning—facts only.
- High-value attack surface Top 5: Ranked by testing ROI with controllable points and confidence.
- Verification queue: 3–5 low-noise tests with Tool/Target/Action/Observe/Stop (prefer replay, mutate, upload/header/ws tools).
- Deprioritized / do not test yet: Weak or noisy leads to skip.
Other actions: Drag, collapse, copy full brief, close. If truncated, refresh or use a model with a higher output limit.
vs AI Tasks: This script is a one-shot browsing brief; AI Tasks (§10) auto-schedule tool_calls and produce evidence-backed reports. Use both: brief for direction, Tasks for deep verification.
Maintenance & forking: Source is viewable/copyable in the workbench. After extension updates, use Sync from built-in if behavior looks stale. Export JSON before heavy edits; built-ins restore on next startup.
5. UI terms
- History: completed requests; defaults to current page. Toggle to "All packets" for all domains.
- Intercept: paused request queue; defaults to all domains to avoid missing cross-subdomain XHR. In the expanded detail, you can edit both the request and any response that has already arrived, then
Release with the current editor content. Firefox also tries to surface other hosts tied to the current tab so you do not release only the main document and leave the page broken (§14). Note: History and Intercept use different default scopes—History favors “this tab’s traffic”; Intercept favors “don’t miss queued items”. Switching tabs updates History; the intercept queue keeps pending rows.
- Replay tab: third top tab in the sidebar opens the replay workbench. Usually you pick a row in
History and click Replay to load that packet.
- All packets / Current page: scope toggle to switch between all domains and current tab domain.
- Pretty: formatted, readable view (JSON/HTML/JS prettified).
- Raw: unformatted original text (same name in CN/EN); available next to Pretty in detail, replay, and Micro Fuzz.
- Hex: hex dump view for binary/encoding issues.
- Render: sandbox HTML render of response.
- Sensitive: grouped hits (IDs, tokens, IPs, component fingerprints, etc.); after enabling in Advanced, a sensitive filter dropdown appears in the toolbar.
- Sidebar toolbar: type chips, host/method/status filters, scope (all packets / current page), sort, search; Refresh, Refresh active tab, Open as full page, Clear history. Intercept view adds Release all and Drop all (works with the popup intercept toggle).
- Open as full page: from the side panel, opens a standalone browser tab with the same capture UI (History / Intercept / Replay, etc.) and tries to collapse the side panel for a wider layout; click again on the standalone page to collapse back to the side panel. Switching while an AI Task is running may interrupt it—wait for completion or cancel first. The tab title shows Hx0 HawkEye - current view (e.g. “Hx0 HawkEye - History”) and updates when you switch top tabs.
5.1 Sidebar tips: Request / Response titles
- In History inline detail (split panes), the Replay workbench, and Micro Fuzz result detail, the title areas above the Request and Response panes are clickable (hover styling hints interactivity).
- Click Request title: parses the raw request and copies the full URL to the clipboard (scheme, host, path, query—respecting the current text and smart URL encoding settings). A short toast reports success or failure.
- Click Response title (often shows status): downloads a UTF-8
.txt that concatenates the current request and response raw text with labeled REQUEST / RESPONSE sections, for archiving or external tools.
This is full-URL copy and a REQUEST/RESPONSE .txt built from the current editor text in both panes—not the same as §5.2’s per-pane Copy buttons or the Burp-style Download from storage.
5.2 Info Architecture panel (inline split detail)
Open it from sidebar History or Intercept: click a row’s Detail to expand the split view (request left, response right; Pretty / Raw / Hex, etc.). The replay modal and Micro Fuzz result detail reuse the same title-click behavior as §5.1 and also expose per-pane Copy—below focuses on the History inline panel.
- Copy next to each pane (one on the request side, one on the response side): copies the currently displayed text for that pane in the active mode (Pretty / Raw / Hex, …). Use this to paste bodies into notes or other tools; it does not parse and copy a full URL like §5.1’s Request title click.
- Direct tamper inside Intercept: in the Intercept view, both the request pane and any response already shown on the right can be edited inline. When you click
Release, the page receives the edited result you see in the pane.
- Download in the bottom action bar: same as the row action
Download—exports a Burp-style text file for the stored record (e.g. HawkEye-<id>.txt). That differs from §5.1’s Response-title download, which serializes the current in-UI request/response editor text into labeled REQUEST/RESPONSE sections. If you edited the packet inline, prefer §5.1 for a WYSIWYG export.
- Other bottom actions:
Collapse, Replay, Download, Delete, Format JSON, plus four Pro shortcuts below (see Four Pro action buttons). Row actions also expose Detail, Download, Delete, Replay, AI Analyze, and AI Script without expanding detail first.
- Replay workbench / Micro Fuzz: each pane has a
Copy button. In Render mode, response copy may be blocked with a hint; in AI result mode, response-side copy usually copies the AI output text.
Row actions vs detail bottom bar
| Where | Actions | When to use |
| List row |
Detail, Download, Delete, Replay, AI Analyze, AI Script |
Quick replay/export/delete or start AI analyze / traffic-based script generation before opening the split editor. |
| Expanded detail · bottom bar |
Collapse, Replay, Download, Delete, Format JSON + four Pro buttons |
After editing in the split panes—run Detect dark links, AI Analyze, Smart Crypto Logic Analysis, or generate a script while reading the packet. |
| Expanded detail · title row |
Per-pane Crypto & Encode + scope dropdown + Copy |
MD5/Base64/smart nested decode in place on the current packet without jumping to the replay workbench (same menu as §6). |
Title-row “Crypto & Encode” (inline codec)
Where: after expanding detail, each of the Request and Response title rows has a Crypto & Encode button plus a scope dropdown (Selection / Param values / URL line). This is the replay workbench codec menu as a shortcut—decode/hash while still in the History/Intercept list.
- How: switch to
Raw (or select text in Pretty) → pick scope → click Crypto & Encode → choose MD5, Base64, smart nested decode, AES, etc. Results write back into the current editor (or open a config dialog first).
- Scope:
Param values and URL line apply to the request only; on the response side use Selection. Same rules as §6.
- vs the four Pro bottom buttons: inline codec is a deterministic tool (hash/decode); Smart Crypto Logic Analysis is AI reasoning about signing/encryption chains—use both: analyze first, then verify with inline codec or replay
codec.transform.
- vs Smart Decode Assistant (§4.4): the assistant pops on any page text selection for lightweight browsing; inline codec targets this HTTP record and includes AES/RSA/smart nested decode.
Four Pro action buttons (detail bottom bar · Pro)
Where: sidebar History or Intercept → expand a row’s Detail → bottom toolbar to the right of Format JSON. All four require Pro. Results appear in the report area below the split panes (downloadable and cached per packet).
| Button | What it does | How to use | Prerequisites / notes |
| Detect dark links |
Static threat / dark-link rule scan on the record’s response body—hidden links, suspicious scripts, inline-style risks—with threat type, target, and jump-to-source in the report. |
Expand detail → click Detect dark links. No AI config needed. Cached reports restore instantly on re-click. |
Enable dark-link detection in popup Advanced. DOM hints used when the active tab is available (same as darklink.scan). See §9. |
| AI Analyze |
Sends request/response excerpts to your configured model for a Markdown brief: risk level, tech fingerprint, issues, sensitive hints. |
Click AI Analyze → optional focus note (empty = default flow) → Analyze. Report renders below; downloadable. Cached separately from dark-link and crypto reports. |
Configure API Key / model under Advanced → AI. Auto-redaction before send is on by default (can disable in Advanced). See §9. |
| AI Script |
Turn the packet you just captured into a reusable page script—AI reads the real URL, method, headers/body, response, and recordId, then generates Tampermonkey code with plausible @match, field names, JSON paths, and GM_hx0CallTool calls. |
After you have found the interesting traffic: expand detail → AI Script → describe intent only (the packet is already in context) → generate → save in the workbench and Inject current page. Row action and multi-select batch work the same way. |
Pro Page Scripts + AI API Key. vs blank AI Create: see callout below. |
| Smart Crypto Logic Analysis |
Infers likely encoding, digest, signing, or mixed crypto chains for fields like sign, token, password from packet context + same-page JS/HTML—reasoning chain and verification hints only (no auto key recovery). |
Recommended: in request or response (Raw), select the suspicious fragment → click Smart Crypto Logic Analysis → optional note → run. Without a selection, auto scope on the whole request. Also available from replay workbench Crypto & Encode menu (§6, same engine). |
AI API Key required. Re-run after editing the packet or switching environments. AI Tasks use the same flow via crypto.logic.analyze (§10). |
Why “AI Script” from traffic—not blank “AI Create” in the workbench?
- Pain point: In practice you first find the packet in History—the login call, the POST with
sign, the JSON that returns a token, the upload endpoint. What you need next is automation for that exact interface / page behavior: mark matching DOM fields, pull a token from the response into the page, one-click replay variants, or call GM_hx0CallTool('replay.request') for semi-auto checks. Blank AI Create only knows your vague description (and maybe the tab URL). The model will guess wrong param names, @match rules, and API paths, and you end up copy-pasting packet text into the prompt yourself.
- What traffic gives you: HawkEye attaches the selected packet’s full request/response excerpt (URL, status, Burp-style raw snippet) and instructs the model to infer
@match, what to watch on the page, and which JSON fields matter. You only state intent, e.g. “surface accessToken from this response next to the form”, “highlight inputs that submit to this POST path”, or “on button click, replay this request via GM_hx0CallTool and diff the response”.
- Typical uses: ① token API after login → page helper to show/copy token; ② signed params → script to label sign-related fields + codec helpers; ③ SPA XHR you just captured → DOM markers for the related UI; ④ select login + business packets → script that wires both contexts.
- vs built-ins (§4.4): built-ins are general-purpose; AI Script is this packet, this site, this API. Always inject manually first; save and enable auto-inject only after it works.
Note: dark-link, AI analyze, and crypto reports share one visible report slot—the latest click replaces the on-screen report, but each kind is cached separately and restores when you re-open the same packet. Row AI Analyze matches the bottom-bar button.
6. Replay workbench
- Edit request, click
Replay, view response; undo/redo; find-in-pane for request/response.
- DOM Replay (In-page): Pro-only. For sites with WAF dynamic defense, normal replay returns encrypted/challenge pages. Click
DOM Replay for a real navigation (GET) or a form POST when Content-Type: application/x-www-form-urlencoded, then extract DOM. multipart/JSON POST is not supported here—use normal replay. Reuses same-origin tab if already open.
- Replay still works with Intercept on: both normal
Replay and DOM Replay are intentionally whitelisted inside the tool, so they do not fall back into the intercept queue.
- AI generate cases: Pro-only and requires AI settings in Advanced.
AI generate cases opens a picker (types, counts, optional custom prompt) and builds structured cases from the current request. Cloud providers usually need an API key; local LM Studio follows on-screen hints.
- Clear test cases: clears all replay test tabs except Draft, including both AI-generated cases and manually sent tabs.
- Save as new tab: adds another session tab in the replay modal tab bar (not a new browser tab) for parallel edits.
- Change request method: Pro-only. Sits to the right of
Save as new tab and flips GET ↔ POST. On GET → POST, HawkEye prefers moving the query into the body and auto-fills common Content-Type / Content-Length. On POST → GET, it tries to move application/x-www-form-urlencoded data back into the URL and removes stale browser-context headers such as Origin, Referer, and Sec-Fetch-*. For JSON, multipart, signed requests, or custom semantics, still review manually.
- Crypto & encode: Community includes the basic set—
MD5, SM3, SHA-1, SHA-256, ROT13, and Base32 / Base64 / URL / Hex encode/decode. Pro unlocks SHA-512, HMAC-SHA256, Base64URL, Unicode, HTML, JSON, JWT parsing, timestamp conversion, Smart nested decode (auto-tries nested codec combinations and shows a report), AES encrypt/decrypt (CBC/ECB/CFB/OFB/CTR with Key/IV), DES/3DES, RSA, SM2/SM4, and Crypto logic intelligent analysis. Symmetric/asymmetric menu items open Key/IV/mode dialogs; AI Tasks and page scripts can pass key/iv/mode/keyFormat via codec.transform to verify hypotheses. The replay toolbar adds a Target pane dropdown next to Crypto & encode: Request / Response. Scope is still Selection, Params only, Full URL line: Params only and Full URL line apply to the request only; when the target pane is Response, only Selection is supported (switch the response pane to Raw, select text, then pick an action). Inline history detail also exposes per-pane codec buttons; behavior matches the above.
How to use Crypto logic intelligent analysis: first locate the suspicious field in the request or response pane (inside replay), or in the detail pane, for example password, sign, token, timestamp, or nonce. Then choose the scope that matches your goal: use Params only when you only care about the value itself; use Selection when the key name, delimiters, or concatenation format may matter; use Full URL line when you want the model to reason over the whole query string, path, or route pattern (when targeting response, use Selection only). Then open Crypto & encode → Crypto logic intelligent analysis. The result prioritizes the current URL, params, headers, body, response clues, and same-page JS / HTML hints such as suspicious crypto functions, field names, and submit logic to infer whether the frontend performs encoding, hashing, signing, or mixed encryption, and to suggest what to inspect next. If you changed the Cookie, timestamp, nonce, signature fields, or target environment, run it again. This feature is a triage assistant; it does not automatically recover keys or rewrite the request for you.
- Injection marker: Pro-only. Wrap selection with
§...§ for Micro Fuzz.
- Target override: Pro-only. Change Target to test the same endpoint in different environments.
- View modes: Pretty, Raw, Hex, Render (response), Sensitive; AI result is Pro-only and starts analysis after you switch to the tab. The in-progress message follows Advanced → Language, e.g. English UI shows an English “Analyzing...” line.
7. WebSocket capture, replay, and Fuzz
- Capture: enable
WebSocket in popup Capture types / suffixes, then use the sidebar WebSocket type filter. The handshake appears as GET 101; data frames appear as WS. OUT means browser to server, IN means server to browser.
- Host filtering: host and current-page filters understand
ws:// / wss:// URLs. For local testing, localhost and 127.0.0.1 are matched as closely as possible. If you only see the handshake, check type, host, and all-packets/current-page filters.
- Detail panes: outbound frames are shown in the request pane; inbound frames are shown in the response pane. Raw text starts with
WEBSOCKET OUT or WEBSOCKET IN plus connection=... to avoid confusing frames with HTTP packets.
- Frame replay: clicking
Replay on a WebSocket frame opens the normal replay workbench. Edit the payload on the left and click Replay; HawkEye sends it through the active page WebSocket that is still OPEN, then shows the next received server message on the right.
- Replay limits: frame replay does not re-send the
GET /ws handshake and cannot impersonate a server push. Even when you open replay from an IN frame, the payload is sent as a client outbound message. If the page was refreshed, the socket is closed, or no active page socket exists, replay reports the connection as unavailable.
- Micro Fuzz: mark one injection point with
§...§ in the WebSocket replay request, then open Micro Fuzz. WS Fuzz sends payloads serially and treats the next inbound frame as the response result. DOM Fuzz is an HTTP/DOM workflow and does not apply to WebSocket frames.
- Intercept / tamper: when intercept is enabled and the host rule matches, page-created WebSocket frames can enter the frame queue for edit, release, or drop.
- Scope: this is a browser-extension WebSocket workbench, not a system MITM proxy. It covers WebSockets created by page JavaScript; it does not transparently modify native apps, other browsers, extension background scripts, or browser-internal traffic. Binary frames are preserved and displayed with text-first plus Base64/Hex views when possible.
8. Micro Fuzz
- Edition note: Micro Fuzz, DOM Fuzz, and the injection-marker workflow are Pro-only.
- Requires exactly one
§...§ pair in the request.
- Start Fuzz / DOM Fuzz:
Start Fuzz uses normal HTTP replay; DOM Fuzz loads each payload in browser, runs JS, extracts decrypted DOM—for WAF dynamic defense sites. Same rules as DOM Replay: GET or urlencoded POST.
- No self-lock under Intercept:
Start Fuzz and DOM Fuzz use the same internal whitelist, so they still send even when intercept is enabled.
- Baseline request is sent first for comparison.
- Focus on status code, response length, response time.
- Use Render, Sensitive, AI result for qualitative analysis.
- Copy Raw yields unformatted original text.
9. Dark-link scan & AI analysis
Per-packet entry points: detail bottom bar in §5.2 — Detect dark links, AI Analyze, Smart Crypto Logic Analysis, and traffic-based AI Script. Below: engine behavior, reports, and batch workbench.
- Edition note: dark-link scan, AI analysis, AI result view, report download, report restore, and the batch AI / dark-link workbenches are all Pro-only.
- Dark-link scan: rule-based detection for hidden links, suspicious scripts, inline style risks in HTML; when the current tab is available, DOM analysis is used (same as
darklink.scan with use_dom) for higher accuracy than raw string matching. The engine merges <style> class rules, whitelists common CDN/analytics scripts, skips semver-like IPv4 and chameleon-only/a11y-only false positives; Advanced settings include a high-trust domain/TLD list for same-site/trusted sources. Usage: detail bottom bar → Detect dark links (§5.2).
- Page Intel Assistant: built-in page script (§4.4) calls
sensitive.scan / darklink.scan after manual inject; sidebar per-packet dark-link reports remain for deep review and export.
- Raw code jump: clicking "Raw code" in dark-link report switches to Raw view and scrolls to the snippet.
- AI analysis / AI result: sends the current request together with its paired response to your configured model for explanation, quick summary, and risk hints. Usage: detail bottom bar or row action → AI Analyze (§5.2); optional focus note before run. Output includes risk level and a tech-fingerprint section.
- Report cover: risk level, timestamp, model, report ID, target domain, request number.
- Download: both AI and dark-link reports can be downloaded.
- Report cache: both reports are kept per packet and restored when switching back.
- Batch AI / batch dark-link workbench: In sidebar History, select multiple rows, then click Batch AI analysis or Batch dark-link scan in the toolbar. A new browser tab opens with per-packet raw request/response (line numbers + syntax highlighting), model/engine output, summaries, and report export. Complements single-packet AI/dark-link actions. For display, the first request line is usually
GET /path?query HTTP/2 (path + query only), matching common origin-style formatting. Use the Copy button next to each section title for that block.
10. AI Tasks (Pro)
- Where to open it: open the side panel and switch to the
AI Tasks tab. Pro feature; configure provider, Base URL, API Key, and model under Advanced → AI first.
- Step 1: choose a target: select a site from the dropdown, type one manually, or click
Use current site. Browse the target first so history contains login state, forms, and real API requests.
- Step 2: choose test directions: use
AI decides when you want the tool to choose directions from the current site. Use Custom directions when you only want specific checks such as SQLi, XSS, Command Injection, SSRF, IDOR, XXE, Deserialization, or File Upload. Custom directions are strict: if you only select SQLi, it will not intentionally run XSS tests.
- Step 3: choose a mode:
Pentest is for authorized security assessment and reports vulnerabilities, impact, and remediation. CTF is for labs and competitions where the goal is to capture a flag.
- Step 4: add task context: expand the task context box and describe scope, focus areas, features to avoid, and preferred approach. Before any test payloads are sent, the extension uses AI to interpret this text into a structured test scope (keywords are fallback only):
- Empty +
AI decides: broad evidence-driven testing.
- Hard limit: e.g. “
only test dark links” → only matching checks (e.g. darklink.scan), no other vuln-family injection payloads.
- Exclude: e.g. “
no SQLi” in Prohibit/skip → still broad discovery, but SQLi payloads are filtered out.
- Hints only: e.g. “focus on login” without “only/no” → ranking preference, not a hard lock.
- Log card
0. Task scope shows the parsed scope (with source tags like [ai]). For CTF, include challenge statement, hints, flag format, and what you already tried.
- Step 5: review safety options: keep smart queue release enabled in most cases. Enable unattended high-risk approval only for labs, CTFs, or clearly authorized test environments. Without it, high-risk actions such as writes, command execution, SSRF, uploads, or identity parameter changes may pause for confirmation or be blocked.
- Step 6: configure Skills (optional): the AI Tasks page provides a
Skills master switch and config panel (enable at least one knowledge base in §4 Advanced first).
- Two layers: Advanced settings defines which knowledge bases/sub-modules are available globally; the AI Tasks panel decides which sub-modules are injected for this task. When the master switch is off, no knowledge-base text is sent to the model.
- Defaults:
Pentest mode selects only the Hx0 Pentest Knowledge Base by default; CTF mode selects only the Hx0 CTF Knowledge Base. Imported custom skills are not auto-selected—enable them manually in the task panel.
- Manual selection wins: skills/sub-modules you check or uncheck (cross-mode built-ins, custom imports) are injected as chosen; the extension will not force-remove them.
- Sub-module recommendations when untouched:
Pentest + AI decides defaults to only Hx0 HawkEye Runtime (required) and HawkEye pentest methodology; Custom directions with specific types sync matching modules. Manual choices are not overwritten.
- Mode/direction changes: reset to the mode’s default built-in base only when you have not manually configured task Skills; manual choices are kept (still filtered to globally enabled skills).
- Smart inject (per main skill): off by default. Off = inject only sub-modules you manually checked for that skill at task start; no mid-task append for that library. On = initial injection plus evidence-driven sub-module append for that skill during the run. Hover the label or switch for the tooltip.
- Built-in tool chain & smart scripts: the model schedules the same tool API as §4.3 via JSON
tool_calls for real in-browser verification—not curl-only advice. Common patterns:
- Capture & mutate:
capture.history → capture.inspect / source.audit → packet.mutate → replay.request (use replay.dom for encrypted/challenge HTML)
- Codec & crypto: on sign/token/client-crypto clues,
crypto.logic.analyze first, then codec.transform (with key/iv/mode when needed), then packet.mutate + replay.request; switch to replay.dom when responses are WAF/challenge HTML
- Specialized probes:
upload.probe/upload.fuzz, header.probe/header.fuzz, ws.probe/ws.fuzz, microfuzz.run, darklink.scan when evidence warrants
- LLM challenges (CTF):
llm.history for chat context, then llm.chat for multi-turn probing
- Smart script dispatch (optional):
script.list / script.run to invoke page scripts from §4.2 alongside built-in tools
Replay-workbench “Crypto logic intelligent analysis” and AI Task crypto.logic.analyze share the same multi-round engine; the difference is manual menu vs Agent auto-call with test-capsule backfill.
- Step 7: start the task: click
Start AI Task. The top progress bar shows 7 stages:
- Traffic collection: create a baseline.
- Asset discovery: identify pages, forms, links, JS, and API candidates.
- Attack modeling: choose useful test entry points.
- Smart scheduling: decide the next request to send.
- Vulnerability probing: send real requests and record responses.
- Result judgement: decide whether a finding or suspected risk exists.
- Report generation: show and export the final report.
- While it is running (log UI):
- Split panes: left =
Execution log, right = Analysis report; drag the vertical splitter to resize. Clear in the log header wipes the current session log only.
- Timeline cards: timestamp + vertical rail + colored badge cards (not plain monospace spam). Long text wraps for scanability.
- Badge types: Stage (7-step pipeline), AI (planning/inference), Test (real HTTP sends), Warning (skipped/conservative), Done/Error (finish, flag hit, failure/cancel).
- Structured fields: cards parse keys such as Summary, Input, Output, Plan, Security policy, Response diff, Judgement, Status (CN/EN)—with “show more” for long values.
- Tool-call cards: each
tool_calls execution shows tool name, duration (ms), success/error; click header to expand formatted input/result JSON (large HTML/rawRequest truncated with char counts).
- Test capsules in the timeline: capsule buttons embed in the log (status dot, label, HTTP code). Click to open the AI Test Capsule modal (Pretty/Raw/Hex/Sensitive, copy, send to Replay). Selected capsule highlights in the log.
- Mid-task Skills injection: applies only to main skills that are checked and have Smart inject on. When sub-modules are appended, a
Mid-task Skills injection card lists trigger reason and added module groups.
- Top metrics: packet/candidate counts, duration, summary—complements the timeline.
- Mid-run hints: toolbar
Add hints while running; submits appear as log entries and append to later AI rounds (does not replace pre-start task context). Bounded queue; no real secrets.
- How to read the report:
- Cover: shows report ID, target domain, generation time, request number, and the model name from your settings.
- Summary cards: start with risk level, conclusion status, vulnerability point, trigger parameter, and payload. Payloads prefer the actual modified parameter value, such as
stunum=2' or target=127.0.0.1; id. With multiple confirmed issues, trigger params may show “Multiple (see inventory)”.
- Vulnerability inventory: in Pentest mode, a severity-sorted Findings Inventory table lists every confirmed issue instead of collapsing into one line. CTF mode focuses on WriteUp, exploit chain, and reproduction steps.
- Request/response evidence: reports and downloaded JSON include
request_response_evidence, aligned with timeline test capsules and tool outputs for manual review.
- Full AI report: expand it to review the test process, confirmed findings, suspected risks, request coverage, and execution status.
pending or waiting_confirm means not actually executed or waiting for confirmation; it is not vulnerability evidence.
- Export / continue: click
Download report to archive it, or continue testing from the report to reuse current clues.
- Common choices:
- SQLi-only:
Custom directions, select only SQLi, confirm injection-related Skills are checked.
- Dark-link only (works with
AI decides too): task context “only test dark links” — expect scope constraint in the log and darklink.scan-style checks, not XSS/SQLi payloads.
- Broad testing but no SQLi: keep
AI decides, put “no SQLi” under Prohibit/skip.
- File upload only: custom directions, select only
File Upload, confirm upload/SSRF Skills are checked.
- Unsure where to start: keep
AI decides with empty context; enable Smart inject per skill when you want mid-run module append.
- Test with login state: log in through the browser first, then click
Use current site.
- Client sign/token/password crypto: keep
AI decides or enable relevant Skills (e.g. JS reverse, crypto-flaws); the Agent will try crypto.logic.analyze + codec.transform, or run replay-workbench analysis manually first and paste conclusions into task context.
- Uploads, command execution, SSRF, and IDOR tests: confirm scope before enabling unattended mode, and be careful on production systems.
- Notes: use only on authorized targets. External models receive the needed context, so keep redaction enabled when appropriate and avoid sending real secrets. Final conclusions should still be reviewed manually, especially for IDOR, business logic, uploads, and production impact.
10.1 Agent Mode (PRO)
Agent Mode requires an active trial or Professional license. It is its own top-level side-panel tab, next to AI Tasks—not a setting inside AI Tasks. Use Agent Mode for conversational browser and HawkEye operations; use AI Tasks for a scoped, structured security-testing pipeline and report.
- Start: configure model, Base URL, and API Key under Advanced → AI, then open
Agent Mode. Known model context windows are detected automatically; every preset and custom value is measured in tokens. Leave the field blank for auto. Press Enter to send or Shift+Enter for a new line. The send control becomes Stop while a run is active.
- Composer modes and deep thinking: the controls below the composer appear in this order:
Browser · HawkEye Agent, Deep thinking, Skills, Goal, and Plan mode. Deep thinking is stored per conversation, starts off in a new conversation, and is temporarily locked during an Agent run. Known providers use native fields: OpenAI GPT-5 models map off/on to reasoning_effort=none/max; DeepSeek V4 maps to thinking.type=disabled/enabled (max when on); GLM-5.3, including GLM-5.3-Flash, cannot fully disable thinking, so off uses the lowest reasoning_effort=low and on uses max; other controllable GLMs use disabled/enabled; Claude Opus/Sonnet 5 uses disabled/adaptive; and SiliconFlow uses enable_thinking. Kimi, MiMo, local models, and custom endpoints cannot be identified reliably by model name alone: off injects no extra thinking fields and follows the endpoint default, while on tries common compatibility fields. If the backend does not support them, its real error is shown. Cache entries are separated by state so an answer from the other mode is not reused.
- Task ideas: an empty conversation shows four suggestions covering everyday browser tasks and HawkEye capabilities—for example open YouTube and play Ultraman, summarize this page, fill a quiz without submitting, compare public product listings, plus traffic/API triage, sensitive and dark-link review, TLS certificates, mobile/tablet layouts, multi-source research, Burp/Yakit routing, full-response search, codec auto-probing, native downloads, and accessibility of complex controls.
Refresh rotates through the bilingual pool.
- Conversations and titles: sessions persist locally. After the first message, a concise fallback appears immediately and the configured model proactively generates a Codex-like title. Double-click the header title to rename it. Hover a sidebar item to delete it, or delete the current conversation from the header; deletion asks for confirmation.
- Time, editing, and position: every user message, completed AI reply, and tool result has its own timestamp, with date separators at meaningful gaps. Use the pencil action to edit a user message and rerun from that point. If you scroll up, a jump-to-bottom control appears.
- Tool details: click any tool row to expand the actual
Input and Result, each with copy support. Green means success and red means failure. Verify important conclusions against the original History/Replay request and response.
- Markdown rendering: AI replies use restrained GFM styling for headings, bold/italic text, lists, quotes, links, inline code, code blocks, and tables. Before parsing, Agent Mode repairs common model formatting such as CJK text adjacent to
**《Title》** or headings written as ##Title, without rewriting inline or fenced code. Wide tables scroll inside the message.
- Attachments and vision: use the composer
+ to add up to six image, TXT, MD, or CSV files (8 MB each). Text becomes analysis context; images are controlled by Current model supports multimodal image input in Advanced Settings. Known vision models enable it automatically; manually enable it for a newly released, proxy, or custom model only after confirming that its endpoint accepts image_url. Raw attachment bodies are not persisted in conversation storage. With on-demand screenshots enabled, Agent Mode captures the page for visual goals such as images, CAPTCHA, canvas, modal overlays, or blank screens, and when it explicitly determines that DOM evidence is insufficient.
- Copy, export, and shortcuts: copy one message from its action button or copy the full conversation from the header. The header download action exports a Markdown file containing messages, timestamps, and each tool's Input and Result. ⌘/Ctrl+Shift+N starts a new conversation; press / outside a form control to focus the composer.
- Executable capabilities: Agent Mode combines browser MCP and HawkEye tools for navigation, clicks, typing, custom-select choice, capture search, packet inspection, replay, sensitive/dark-link scans, codecs, and response comparison. Nested frames, open Shadow DOM, rich editors, and custom dropdowns use accessible, frame-scoped refs. For quizzes/forms it can extract structured questions and fill choice, true/false, and text answers without final submission.
- Local OpenSSL/CryptoJS AES decryption: for OpenSSL
Salted__ Base64 ciphertext beginning with U2FsdGVkX1, Agent passes the ciphertext and password to built-in hawkeye_codec with openssl_decrypt and decrypts locally in the extension background. It neither injects crypto code into the current page nor loads an external CDN. Unknown actions, a missing/wrong password, a non-Salted__ value, or incompatible KDF/cipher parameters produce an explicit failure; an empty output is no longer reported as success.
- General file downloads: requests to download page video, audio, Word, Excel, PDF, ZIP, RAR, or other files use
browser_download_file. Agent Mode resolves the real HTTP(S) resource from page media/download links or captures scoped to the current tab. When discovery yields one usable candidate, it requests any required safety approval and deterministically continues into the browser-native download queue, inferring a useful extension from Content-Type/Content-Disposition. It reports success only after receiving nativeDownloadStarted=true and a downloadId; finding a URL, opening it, or seeing a player is not completion. For blob: media it searches current-tab traffic for the underlying request.
- Agent Skills and explicit learning: ordinary Skills still require two gates—new conversations start with Skills off, and after the user clicks the
Skills chip only Skills/sub-modules enabled in Advanced Settings may match. Agent first searches lightweight metadata for the current task, then reads whatever Skills or references the task needs; smart routing does not cap how many can load, but it never bulk-injects every enabled Skill body into model context. Skill inventory/content questions are answered by the model from real on-demand lookup results, not fixed prose. A checked Agent learned Skill created from an explicit remember request becomes a candidate for similar future tasks and its body is read only when actually needed. Uncheck or delete it in Advanced Settings to stop all future use.
- Current page and autonomous web research: Agent locks onto the real HTTP(S) tab you are viewing, even when Agent itself is expanded into a full extension page. When knowledge is insufficient, recent, or conflicting, it can choose
browser_search, browser_fetch, or browser_research for multi-source evidence. Temporary background tabs close automatically and do not replace the current page. Results expose cache hits, engine telemetry, evidence scores, failures, source URLs, and gaps; only successfully read sources may support the answer. This is a HawkEye-owned implementation and does not install, invoke, or depend on Wigolo.
- Plan repair, empty-response recovery, and long context: malformed JSON, missing fields, unknown tools, compatible terminal aliases such as
success/completed/done, and prose summaries are normalized first; remaining errors are returned to the model for regeneration. If HTTP 200 contains empty content with thinking enabled, reasoning-only output, or an exhausted output budget such as finish_reason=length, Agent makes at most one recovery attempt within the remaining retry and time budgets. It reduces or disables thinking as supported, removes structured-format constraints while retaining local validation, increases an exhausted output budget within a bound, and requests a concise complete response. An unexplained ordinary empty response is not automatically retried. If recovery remains empty, the error includes finish_reason, reasoning character count, and token usage to distinguish reasoning-only output, an exhausted output budget, and endpoint incompatibility. When verified tool observations already exist, Agent produces a deterministic grounded handoff from the current run instead of letting the final empty completion erase verified results. Context is estimated in tokens, with room reserved for system rules, on-demand Skill reads, tool evidence, and output. Skill bodies are read on demand with no smart-routing count cap, still bounded by the context window, and remain active only for the current Agent run; a later task must select them again by relevance. Near the overall budget, older messages roll into durable task memory that separately preserves the original goal, user corrections, constraints, verified facts, completed work, pending work, and exact errors while keeping recent turns verbatim. A deterministic local summary prevents a failed compression request from interrupting the run. Editing a past user message invalidates old memory and branches from that point. Large MCP snapshots remain pageable through context_budget_chars and page_token.
- Skill selection and smart routing: new conversations start with Skills off and the chip unselected. Click the composer Skills chip (or the header ✦) to open a compact popover that grows upward and to the right from that button, without covering chips to its left; select any number of enabled Skills, and choices save on click. Click Skills again to close the popover and turn Skills off. Clicking outside or pressing Esc only dismisses the popover and keeps the current selection. With smart routing off, only selected Skills are available; when enabled, Agent can discover and load as many relevant enabled Skills as the task needs. Global disablement still applies.
- Import conversation: use the small header button to the left of
+ to load a HawkEye Markdown (.md) export as a separate conversation. User and assistant messages restore their original Markdown; tool records restore as expandable tool cards with input/result, not as raw JSON in the transcript. History is not executed, and queues, permissions, or goals are not restored. Image attachments retain only their exported names. Limits: 2 MB, 500,000 characters, 600 messages.
- Save as a Skill: ask “save this as a skill” to send the verified workflow through the separate generation, validation, and local-save pipeline. The absence of a
hawkeye_skill_upsert tool does not prevent saving and does not require a UserScript. To update an existing custom or learned Skill, ask “update this Skill”: Agent reads the target, then uses hawkeye_skill_update to append or replace a unique exact passage by ID, preserving untouched content, references, and selection and verifying the saved result. Built-in Skills cannot be overwritten. Sufficient existing evidence avoids repeat browsing or reproducing the whole document. The actual platform save receipt confirms persistence; failures are reported without claiming success prematurely.
- Cross-conversation summary memory and personas: history recall is off by default. When unchecked, conversations stay independent: no goals, preferences, completed work, or open loops are recalled from other conversations, and no new cross-conversation summaries are generated. Current-conversation messages and compacted task memory remain available. Enabling recall generates and retrieves relevant summaries without injecting full old transcripts or treating summaries as instructions. Existing toggle choices are preserved; disabling recall does not delete saved summaries or chats. The memory manager still supports viewing, editing, deleting, and clearing summaries. The new default HawkEye Universal Browser Assistant uses HawkEye for tabs, navigation, iframes, forms, dialogs, uploads, downloads, and multistep tasks, observing before acting and verifying results. Seven presets now include this assistant, HawkEye Security Partner, Web pentesting, CTF, frontend/API debugging, research, and long-term conversation. Custom personas and saved selections are retained; choose the new assistant or restore presets in settings. Personas cannot override user instructions, permissions, or tool evidence.
- Goal, Plan mode, and recommended choices: use the
Goal chip below the composer to set an objective for the conversation. Once Agent verifies that the task is complete, the Goal is cleared rather than remaining as an in-progress template. The Goal stays while you are choosing an Ask option or approving a plan. Editing or deleting a Goal while a run is active syncs to the background task; delete stops the current run. Plan mode is read-only research plus a concrete Markdown proposal (scope, prerequisites, steps, verification, risks). It must not navigate, reload, or move the current page, download files, or save screenshots to disk. When a decision is needed, it follows Codex Ask: you pick among the presented options, and nothing is implemented yet. After a complete plan, the approval dialog keeps a scrollable rendering of the plan with Execute plan, Revise plan, and Do not execute. Only approval leaves plan mode and starts real actions.
- Progress and approvals: a thinking/progress response appears immediately after send, and the Stop control has a clear label. The header security menu offers
Request approval, Ask for risky actions, and Full access. The default intercepts consequential submissions, deletion, sending, replay/fuzzing, and scope changes. Full access skips per-action prompts and keeps a visible consequence warning.
- Continue in context: follow up with constraints such as “current host only,” “fill but do not submit,” or “continue from the previous result.” If a turn reaches its limit, send “continue”; the conversation retains prior messages and tool observations.
- Authorization and privacy: operate only on owned or explicitly authorized targets. State boundaries for submissions, deletion, writes, uploads, and authorization checks, and review consequential actions before they execute. Models receive task context, so redact real credentials and personal data when appropriate.
Stopping and completion: stopping while a tool approval is pending prevents that tool from running even if approval arrives later. Failed response recovery preserves an unfinished Goal and hands back verified results; pending tools prevent premature Goal completion. A download from an earlier run cannot prove success for the current task. A download being queued does not mean the file is complete—check the browser download status. On exit, Agent stops capture that it temporarily enabled while preserving capture that was already enabled. Text and attachments share the context budget and may be compacted or shortened; state critical requirements explicitly in the latest message.
Tabs, downloads, and completion: after Agent selects or binds a tab, subsequent actions target that page. Closing the task tab still allows a summary; select or create a tab before more page actions. File discovery only lists candidates and downloads require a separate action. A download receipt is checked against remaining work. Titles and historical memories are maintained in the background without blocking the next task; explicitly requested Skill saving remains part of completion.
Background resume and checkpoints: Agent execution is no longer tied to the sidebar page. Closing the sidebar, reloading the extension, or a background restart keeps confirmed steps from running again. A write whose result is unknown pauses at “verify interrupted operation”; you choose completed / not done / stop, and the system never auto-resubmits. Reopening the sidebar reconnects to background progress and will not overwrite a newer checkpoint with an older local transcript. Network recovery retries read-only work from the checkpoint; writes still require your confirmation.
11. Batch ops & typical scenarios
- Edition note: batch export, batch delete, batch replay, batch AI analysis, batch dark-link scan, and batch report export are Pro-only.
- Batch ops: select multiple records to batch export, delete, batch AI analysis, batch dark-link scan (opens the §9 new-tab workbench), or batch replay.
- Debugging: capture → find target → replay with modified params → compare response.
- Sensitive audit: capture → switch to Sensitive view → locate hits.
- Security screening: dark-link scan → AI analysis → export report.
12. FAQ
- Status badge: single-click vs double-click? Single-click opens Software activation or the member welcome screen (same during trial). With an active paid license (time-limited or permanent), double-click opens License details (machine ID, activated-at time, remaining time, revealable activation code)—see §13.
- First launch / policy gate? Scroll the policy summary to the bottom in the popup, tick agree, then continue (full text can open in a new tab).
- Shortcut does not open the capture UI? The default is
Ctrl+H; on Mac press Control, not Command or Option. You do not need to open the popup first. On Chrome, if you rebound it at chrome://extensions/shortcuts, that page wins. On Firefox the shortcut opens the in-page float, not the native sidebar; press again to close. If a web page steals the combo, rebind in Advanced Settings (Firefox) or the extension shortcuts page (Chrome). See §4.
- No packets? Check capture toggle, capture target match, and capture type/suffix filters.
- The request pane shows only “GET /path HTTP/1.1” and no headers? That is the request line, not the request body. Current v1.0.6 merges Firefox WebRequest/page-hook header evidence and restores Host authority. Reload the current build in
about:debugging or the extension manager, turn capture on, then hard-refresh the target to create fresh records; old history cannot be retroactively completed. Browsers may still hide HTTP/2 pseudo-headers or protected headers.
- Is the request body broken?
GET/HEAD normally have no body. Verify with a newly generated POST/PUT/PATCH; Firefox reads formData or raw bytes. A body may still be absent for non-replayable streams, browser privacy restrictions, or truncation at the configured size limit.
- Which capture types should be enabled by default, and why JS? Use XHR/Fetch + WebSocket + HTML + JS + JSON + XML. JS reveals hidden APIs, sign/token logic, source maps, and dynamic requests. Reduce temporarily to XHR/Fetch + WebSocket on high-volume pages; use an even narrower profile while intercepting—see §3.
- WebSocket only shows the
GET 101 handshake? Make sure WebSocket is enabled in capture types, the list is not restricted to XHR/Fetch, and host/current-page/search filters are not hiding frames. Data frames appear as WS; outbound is shown on the request side, inbound on the response side.
- WebSocket replay failed or received nothing? Frame replay needs the original page to still have an
OPEN WebSocket. If the page was refreshed, the socket closed, you switched away from the source tab, or the server does not reply, the response pane may show unavailable/timeout. This is frame replay, not a fresh HTTP handshake replay.
- Want Burp/Yakit to show only target-site traffic? Open Smart Proxy Router in Basic settings, configure the upstream proxy and site rules, then choose Compatibility mode or Takeover mode as needed.
- Size / history limits? Each stored request/response body is capped (very large multipart bodies may be truncated in the UI); history count is also capped—clear history if needed.
- Empty response body? On Chrome with intranet/self-signed HTTPS, try enabling passive body capture in settings and refreshing. Firefox has no such control—check the capture toggle, host rules, and type filters; do not expect a “passive” switch there as the fix.
- Response is ciphertext/challenge page? For WAF dynamic defense sites, use
DOM Replay or DOM Fuzz to load in browser and extract decrypted content.
- DOM Replay / DOM Fuzz and POST? They need a real navigation or form submit in-page. POST is supported when
Content-Type: application/x-www-form-urlencoded; for multipart/JSON, use normal replay.
- Why do Replay / Fuzz still send when Intercept is on? By design.
Replay, DOM Replay, Micro Fuzz, and DOM Fuzz use an internal whitelist so your own tool traffic does not get trapped again.
- Should I still verify after clicking Change request method? Yes. The button handles common GET / form-POST cases, but JSON, multipart, signatures, timestamps, or custom validation logic may still need manual fixes.
- Can AI Tasks run crypto logic analysis automatically? Yes (Pro). The Agent calls
crypto.logic.analyze—the same multi-round engine as replay-workbench “Crypto logic intelligent analysis.” You can also analyze manually first and paste conclusions into task context. For hash/codec verification it uses codec.transform (with key/iv/mode when needed), then packet.mutate + replay.request to close the loop; for encrypted/challenge HTML it switches to replay.dom.
replay.dom vs replay.request? Use replay.request for normal APIs/static HTML (fast background HTTP). Use replay.dom when responses are WAF-decrypted, JS challenge, or encrypted HTML (same as workbench “In-page replay”). For batch §marker§ variant probes, use microfuzz.run with use_dom:true.
- Too many sensitive false positives? Built-ins use second-pass validation; disable IPv4/IPv6/domain if still noisy; Community can also add custom regex and keyword rules.
- Too many dark-link false positives? Add your CDN/partners to high-trust roots in Advanced; focus on “hidden style + external link” combos; ignore chameleon-only or a11y-only hits.
- Encode/decode not working? Check scope; for "Selection" you must select text first. Detail title-row Crypto & Encode matches the replay menu—response side does not support Param values / URL line.
- What do the four Pro detail buttons do? Detect dark links: rule scan on response/HTML, no AI. AI Analyze: model summary of risk and fingerprints for the whole packet. AI Script: turn this packet into an injectable page script (see §5.2 callout). Smart Crypto Logic Analysis: infer sign/token crypto chains. Reports are cached per kind, but only the last clicked kind is visible at once.
- AI Script vs workbench “AI Create”? You already captured the key packet and want automation for that API → row or bottom-bar AI Script (packet in context). Only a vague idea, no traffic yet → workbench
AI Create. See §4.2 and §5.2.
- Which web encodings does Smart Decode support? Common URL percent encoding, HTML entities, Base64/Base64URL, Hex, JSON unescape, JavaScript/JSON
\uXXXX Unicode escapes, and nested detection. For example, a complete \u8d44\u6e90\u4e0d\u5b58\u5728 selection should decode to Chinese; include each full \u sequence rather than selecting only the hex digits. Pro detail/replay menus also offer explicit Unicode Decode and JSON Unescape.
- Smart Decode Assistant keeps popping up? Sidebar Scripts → disable Hx0 Smart Decode Assistant or switch it to manual; GM menu Hx0 Toggle smart decode panel toggles on the current page. Use the assistant for browsing; AES/nested decode on packets stays in inline detail or replay (§5.2, §6).
- AI no result? Verify that Base URL, API Key, Model, and purchased billing route match, then check the network. Zhipu error
1113 means the current account/endpoint has no available balance or bundle: Coding Plan and the standard API require their respective endpoints. Xiaomi tp- Token Plan keys and sk- pay-as-you-go keys are also not interchangeable. The detected provider/route appears below Base URL; reselect the provider or reload the updated extension to auto-repair a crossed provider, URL, or model.
- Why are some advanced entries missing or unavailable in Community? Community keeps the core path of capture → inspect → intercept/tamper → normal replay → basic crypto/encoding. DOM replay, Micro Fuzz, Page Script Injection, AI, dark-link, batch workbenches, and advanced codec/data tools are Pro-only. Clicking a Pro entry shows feature guidance and activation flow.
- Reports lost when switching? Each packet caches AI analyze, dark-link, and crypto logic reports separately; collapse/re-expand or re-select the row to restore (only the last opened kind shows on screen at once).
- Firefox: sidebar not on the right? Placement is controlled globally by Firefox from the sidebar menu—not an extension bug.
- Firefox: 2× playback works but F does not enter fullscreen? Reload the latest build containing the native-input relay and keep the target tab foreground in the active Firefox window. A returned
native_pending indicates the older path has not completed; the current path should return native-input evidence. Judge the final result by document.fullscreenElement. A delayed userActivation.isActive=false may simply mean successful fullscreen consumed transient activation.
- Firefox: page stays blank while intercepting? Often the main HTML returned but JS/CSS/API calls are still queued—keep releasing from Intercept or use sidebar release-all (sequential).
- Firefox: float panel buttons freeze after releasing the main document? Reloading the host page rebuilds the embedded overlay—use the sidebar for main-document and bulk release (§14).
- Firefox: main popup disappears after Batch import? Expected: finish picking the file in the small helper window, read the summary, then click the extension icon again (see §4.1).
Security: Test only on systems you are authorized to. AI may upload selected content; redact as needed.
13. Licensing, trial, and device identifier (Chrome / Firefox)
- Activation (single-click the status badge): Without a valid license and outside the trial window, the extension falls back to the Community Edition, where Pro-only features become unavailable. Single-click the status badge to open Software activation with Online and Offline tabs; when licensed, single-click opens the member welcome screen. During trial, the badge shows remaining trial time.
- Community vs Professional: Key differences are listed in the table below.
- Online activation: In Software activation → Online tab, subscribe or buy lifetime membership. When online, benefits sync and are cached locally so Pro features continue offline while the cache/subscription remains valid. Your User ID is the entitlement credential—keep it safe. Use Open membership / My membership for checkout.
- Offline activation: In the Offline tab, use classic machine ID + activation code, verified locally without a licensing server. Timed subscriptions show second-precision remaining time (live refresh) and a Renew purchase link; permanent licenses can replace codes or open license details via double-click on the badge.
- Lost entitlements: If reinstalling the browser changes your User ID, or a machine ID change breaks offline activation, contact hx0studio@foxmail.com with payment proof and old/new IDs or machine codes; support will verify and assist recovery.
- Trial and fallback: The first install includes 30 minutes of full Pro access. When the trial ends without activation, the extension automatically falls back to the Community Edition. Clicking a Pro-only feature in Community mode first shows a short feature description, then opens the activation window.
- License details (double-click the status badge): When you have an active paid license (time-limited subscription or permanent), double-click the same badge to open License details: machine ID, activated-at time, time remaining (subscription updates every second; permanent shows “Permanent”). The current activation code is hidden by default—tap the eye control (closed-eye = hidden; open-eye = visible); tap again to hide. Subscription users can paste a new activation code in the same panel to replace the license (e.g. renew or upgrade to permanent). After each successful activation, the extension stores the last code and activation timestamp locally for your reference; if those values are not stored yet, the panel shows a short explanatory note.
- Trial: One trial per usage cycle; the current default trial length is 30 minutes, recorded on this device. After expiry, behavior matches “not licensed”.
- Device identifier (for license requests): The extension derives a relatively stable identifier for your current browser environment—the same value shown as machine ID in License details—and associates it with your license. Under the same browser profile, reinstalling the extension usually keeps the same identifier, which helps Team Hx0 (Hx0战队) process requests consistently via WeChat Official Account or Zsxq (知识星球): Hx0战队.
| Feature Group |
Community |
Professional |
| Capture toggle |
✅ |
✅ |
| Target domain / IP settings |
✅ |
✅ |
| Capture type / suffix filters |
✅ |
✅ |
| History list |
✅ |
✅ |
| Current-page / all-packets scope switch |
✅ |
✅ |
| Basic Host / method / status filters |
✅ |
✅ |
| Pretty / Raw / Hex / Render views |
✅ |
✅ |
| Request / response copy, title-click URL copy, single-item download |
✅ |
✅ |
| Built-in sensitive-info view |
✅ |
✅ |
| Normal replay |
✅ |
✅ |
| Floating ball |
✅ |
✅ |
| Save as new tab |
✅ |
✅ |
| Basic codec set (MD5 / SM3 / SHA-1 / SHA-256 / ROT13 / Base32 / Base64 / URL / Hex) |
✅ |
✅ |
| Intercept / tamper / release / drop |
✅ |
✅ |
| WebSocket capture / frame view / frame replay / tamper |
✅ |
✅ |
| Smart Proxy Router (Burp/Yakit etc.) |
✅ |
✅ |
| DOM Replay |
❌ |
✅ |
| Micro Fuzz / DOM Fuzz / injection markers |
❌ |
✅ |
| WebSocket Micro Fuzz |
❌ |
✅ |
| Page scripts (script library / Tampermonkey import / GM menus / AI create·optimize / GM_hx0CallTool) |
❌ |
✅ |
| Request-method switch / target switching |
❌ |
✅ |
| Advanced codec & data tools (SHA-512 / HMAC-SHA256 / Base64URL / Unicode / HTML / JSON / JWT / timestamp) |
❌ |
✅ |
| Crypto logic intelligent analysis (use current request context + same-page JS / HTML clues to infer encoding / digest / signing flow) |
❌ |
✅ |
| AI settings |
❌ |
✅ |
| AI result / AI analyze / AI case generation |
❌ |
✅ |
| Dark-link scan / report download / report restore |
❌ |
✅ |
| Full deep search |
✅ |
✅ |
| Custom rules / keyword libraries / batch import-export / clear all |
✅ |
✅ |
| Trusted domain/TLD configuration |
❌ |
✅ |
| Batch workbenches (batch export / delete / replay / AI / dark-link / reports) |
❌ |
✅ |
| AI Task desk (pentest / CTF modes, tool-chain scheduling, in-run clue intake) |
❌ |
✅ |
| Browser-level Agent / Agent Mode (active trial or Professional license only) |
❌ |
✅ |
| AI Skills (built-in knowledge bases / import / task-level sub-modules) |
❌ |
✅ |
Compliance: Use the product within the scope of your license; commercial use requires a proper license.
14. Chrome vs Firefox: UI & usage differences
Implementation and UX differences only. Core features match across builds; popup-only options (e.g. Chrome’s passive body capture for intranet/self-signed HTTPS) may differ—follow the UI.
- Sidebar container: Chrome uses the Side Panel API. Firefox uses the native sidebar; left/right placement is set globally in Firefox’s sidebar UI—the extension cannot force a side.
- Capture UI shortcut: both editions default to
Ctrl+H (Control+H on Mac). Chrome toggles the Side Panel and can only be remapped at chrome://extensions/shortcuts. Firefox opens the in-page float first and closes it on the next press; record a new combo in Advanced Settings. See §4.
- In-page float / floating entry: Both may offer an embedded overlay. On Firefox, releasing the main document can reload the tab and tear down the overlay—prefer the sidebar for main-document release, full resource chains, and bulk release-all. Chrome: same recommendation for safest bulk operations.
- Intercept scope & full page load: Pages depend on JS/CSS/APIs from multiple hosts. Firefox tries to list related cross-host items; release-all runs sequentially and may pick up new items after the main response. A “white” or broken layout usually means more queued intercepts remain.
- Passive response body capture: Chrome-only UI—an extra path because Chrome sometimes needs it to record full response bodies on intranet/self-signed HTTPS. Firefox does not expose it and generally captures those bodies without an equivalent toggle.
- Firefox request headers / bodies: the current build registers WebRequest listeners when capture starts, merges before/after-send and page-hook evidence, and restores Host/authority as a fallback. POST/PUT/PATCH prefer
formData or raw body; a bodyless GET is normal. Reload the extension and refresh the page to create new records after an update—old history is not backfilled.
- MCP trusted input / fullscreen: Chrome dispatches through CDP Input. On supported desktop environments, Firefox can use a local native keyboard/mouse relay for operations requiring transient activation. Keep the target tab foreground; after fullscreen succeeds,
isActive may be consumed, so use input evidence and fullscreenElement (see §3.1).
- MCP screenshots: both builds return images only by default. With explicit
save_to_file:true, the local server writes the evidence file without any new outbound connection. Keep the bound tab active for viewport screenshots.
- Debugging banner: Mostly a Chrome behavior when intercept is enabled; Firefox usually shows nothing similar.
- WebSocket observation: both editions capture WebSocket frames in-page; Chrome may enrich handshake and frame observation when possible. The target page must keep the socket open in the current browser tab.
- Sensitive-rule CSV import: Firefox opens a small helper window so the system file picker does not close the main popup mid-import (see §4.1); Chrome normally finishes import inside the popup.
- Page script permission: Chrome includes
userScripts in the manifest; if still unavailable, enable Allow User Scripts manually. Firefox uses optional permission—follow the workbench guide; reload in about:debugging after extension updates.
- Tampermonkey compatibility:
.user.js imports detect common metadata; @require and GM_xmlhttpRequest prefer the extension background to bypass page CORS. The built-in lightweight jQuery layer covers common DOM tasks. Scripts with GM_registerMenuCommand auto-fetch menus in the sidebar and can read from other open matching tabs when the current page does not match (see §4.2). Enable Inject iframes too for iframe captchas.
- Licensing: Same licensing, trial, and device-identifier rules as §13.
15. Comparison with Burp Suite, Yakit, HackBar-style tools (detailed)
Side-by-side notes on product shape, session fidelity, workflow, and specialties—for picking or combining tools by scenario. Each product has different strengths; none is universally “best.” HawkEye rows reflect the current release (AI Tasks, Skills knowledge bases, Smart Proxy Router, etc.). Burp / Yakit remain common choices for enterprise active scanning, large Intruder-style runs, and non-browser traffic—see each vendor for authoritative specs.
| Area |
Hx0 HawkEye |
Burp Suite |
Yakit |
HackBar / light extensions |
| Deployment |
Browser extension; sidebar-first workspace + optional float; no separate JVM or listener port |
Standalone Java proxy + browser trust store; full security testing suite |
Desktop client + engines/plugins; platform-style security tooling |
Small toolbar panels or one-off request helpers |
| Day-to-day friction |
Main flows stay inside the extension; no mandatory global system proxy; CN/EN UI centered on the sidebar |
Requires proxy setup, CA trust, and familiarity with Proxy / Repeater modules |
Separate client install and workflow/plugin learning curve |
Quick to start for ad-hoc edits; usually no full project workspace |
| Browser session / auth |
Capture and replay use the active tab’s same-origin session, matching what the page actually sent |
Traffic via proxy; complex sites may need manual Cookie / Header sync into Repeater |
Often proxy/engine path, different from in-page extension capture |
Mostly manual Header / Cookie assembly |
| Modern APIs (XHR / Fetch / SPA) |
Captures fetch / XHR in-page; multipart uploads auditable in Raw / Hex (within storage limits) |
Full HTTP(S) visibility at the proxy; mature Repeater / Intruder modules |
Traffic + plugins cover advanced Web scenarios |
Usually URL / parameter focused; persistent history and Hex views are uncommon |
| History & workspace |
Local persistent history; filter by host/method/status/sensitive/search; details, replay, codec, fuzz, AI in one sidebar; Pro batch workbench |
Excellent Proxy History for large traffic sets and project workflows |
Strong platform records, PoC, and collaboration |
Usually no or limited history and batch features |
| System proxy / non-browser apps |
Browser HTTP(S) only; not for mobile/desktop clients routed through a system proxy |
System-level proxy; intercepts many client types |
MITM / listener ports; multiple traffic sources |
Generally not involved in system proxy |
| With Burp / Yakit-class proxies |
Community Smart Proxy Router: forward matched browser requests to an upstream (e.g. Burp / Yakit listener) by site rule; others stay direct—combines with proxy tools, does not replace their scanning/pipelines |
Canonical HTTP(S) proxy and suite hub |
MITM ports + plugin/workflow ecosystem; chains with other tools |
None |
| Intercept / tamper |
Queued intercept; release/edit/resend from the sidebar |
Proxy intercept; Repeater edit/resend; rich docs and ecosystem |
MITM intercept and workflow orchestration |
Usually no intercept queue, or URL/parameter-level edits only |
| Replay / fuzz |
Raw replay editor; micro fuzz; in-page replay / in-page fuzz for WAF’d HTML (GET or urlencoded POST); Pro AES/DES/RSA/SM crypto, smart nested decode, Crypto Logic Analysis, crypto.logic.analyze, and upload/header/WS tools in the AI Task chain |
Repeater / Intruder; strong for complex dictionaries, concurrency, scripting |
Web fuzzer modules; pipeline-style batch PoC |
Little structured fuzz or multi-round diff workflow |
| Sensitive / dark-link / reports |
Built-in sensitive rules + row badges + detail aggregation; dark-link scan; exports tied to history |
Scanner + BApp ecosystem for extended checks |
Rich PoC/plugins composable by scenario |
Few built-in rules or report features |
| AI snippets & batch summarize |
BYO API (OpenAI-compatible, DeepSeek, etc.); traffic only to endpoints you configure. Pro: per-record AI, batch AI tab (see §9 / §10) |
AI via BApps, scripts, or self-hosted services—UX varies by plugin |
Evolving AI modules tied to engines/workflows |
Rare; usually one-off encoding, no batch + structured output |
| AI orchestration & Skills |
Pro AI Task desk: multi-turn workflow—JSON drives built-in tools (history, replay/mutation, crypto.logic.analyze, advanced codec.transform, upload/header/WebSocket probes, llm.history/llm.chat, etc.) with real HTTP under the tab session; pentest / CTF modes; Skills injection; smart script dispatch; direction-linked sub-modules; mid-run hints and safety gates. Not a replacement for enterprise active scanning or huge Intruder campaigns |
Centered on Scanner, macros, Repeater/Intruder, BApps—different orchestration model from an in-sidebar extension loop |
MITM/engine + platform workflows; AI spread across modules |
No multi-turn tool orchestration or report loop |
| Active scan / heavy automation |
Not the primary focus; human-in-the-loop capture → replay → verify loop |
Burp Scanner, macros, BApps—suited to site-wide scanning and complex automation |
Batch PoC, collaboration flows, pipelines |
Not applicable |
| Resource use |
Runs inside the browser process; relatively small extra footprint |
Standalone proxy + JVM; varies with scan scope and plugins |
Client + engines; scenario-dependent |
Very low footprint; narrower feature set |
| Licensing |
In-extension activation (online membership / offline code—see §13) |
Commercial license (Community / Professional tiers, etc.) |
Open core + commercial components |
Varies by product |
Scenario fit: Hx0 HawkEye fits integrated browser-session loops—capture → filter → tamper/replay → micro fuzz → sensitive/dark-link triage → optional AI (Tasks + Skills)—for dev QA, acceptance checks, authorized API review, WAF dynamic-page forensics, CTF/labs. Burp Suite fits system proxy, large Intruder runs, Scanner active testing, and mature plugin workflows. Yakit fits platform PoC, pipelines, and team collaboration. HackBar-style extensions fit quick manual URL/parameter tweaks. Tools can be combined—e.g. HawkEye as the browser hub with Smart Proxy Router forwarding selected traffic to Burp/Yakit.
How to combine: Choose by task phase, not either/or. Use HawkEye for day-to-day in-browser verification; add Burp/Yakit for full active scanning, huge dictionaries, non-browser clients, or existing team proxy workflows. Community Smart Proxy Router can forward matched browser traffic to Burp/Yakit while other sites stay direct.
16. Skills knowledge bases (Pro)
Open popup Advanced → AI Skills. Built-in libraries ship with the extension and external packs can be imported; only checked Skills can be used. Ordinary Skills also require the Skills chip in each new Agent conversation. A checked Agent learned Skill created from an explicit remember request may auto-match a similar future task. A Skill is a knowledge/instruction module injected into Agent context—not an MCP/API tool or a UserScript. Asking Agent which Skills are available lists the enabled modules directly and never queries UserScripts. Content stays in the browser; injection into AI Tasks or Agent sends selected text to your configured model endpoint—authorized use only.
Ask Agent to preserve a workflow or mistake as a Skill
- Explicit trigger only: say “please remember this login workflow” or “save the previous mistake as a Skill.” Ordinary conversation, page text, attachments, and tool output cannot trigger it; “do not remember this” prevents persistence.
- Evidence-grounded: after the current run, Agent distills user intent, successful/failed tool observations, and the correction into triggers, reusable steps, verification, and pitfalls. Instructions found inside a page or attachment are treated as data unless the user explicitly endorses them.
- Privacy and truthful receipts: this persistence path always redacts credentials. Cookies, Authorization, tokens, passwords, personal data, live session values, and absolute local paths are not written into the Skill. Success is reported only after validation and storage complete.
- Deduplication and control: a similar lesson updates the existing Skill instead of adding duplicates. The
Agent learned badge identifies it; view/edit/export it like another custom Skill, or uncheck/delete it to stop future matching.
Built-in sub-module catalog
Toggle modules in Advanced settings and the AI Tasks panel. Keep hawkeye-runtime / hawkeye-ctf-runtime enabled. User edits override default markdown locally.
Hx0 Pentest Knowledge Base (19)
| Module ID | Coverage |
hawkeye-runtime | Tool contract, judge JSON, no external CLI (required) |
methodology | L1–L4 capture-driven loop |
product-fingerprint-recon | OA/ERP/DevOps/security/VPN/middleware fingerprinting |
injection-attacks | SQLi / NoSQL / XSS / RCE / SSTI / XXE |
framework-deserialization-rce | Shiro / Fastjson / Struts2 / Log4j2 |
logic-auth-access | IDOR / JWT / auth / business logic |
session-cookie | Cookie attributes / session fixation |
web-logic-misc | CSRF / open redirect / OAuth / race |
api-security | Swagger / BOLA / GraphQL / @type |
crypto-flaws | Weak AES/RSA, predictable tokens |
js-reverse | Front-end JS reverse, sign/token, hardcoded secrets |
file-upload-ssrf-lfi | Upload fuzz / SSRF / LFI |
protocol-headers-ws | CORS / headers / WebSocket / CRLF |
encoding-waf-bypass | codec.transform + WAF bypass |
sensitive-disclosure | Actuator / Druid / Swagger leaks |
dark-link-detection | Dark-link / malware / static threats (darklink.scan) |
ai-llm-security | Prompt injection / Agent / MCP |
ai-site-workflow | AI-site Phase 0–2 recon + P1–P7 + 8-step pipeline |
reporting-triage | Risk grading and report structure |
Hx0 CTF Knowledge Base (28)
| Module ID | Challenge type |
hawkeye-ctf-runtime | Tools, flag format, judge (required) |
ctf-web-basics | Open challenge, backups, .git |
ctf-framework-hints | Framework fingerprint hints |
information-disclosure | Actuator / Swagger / .env |
encoding-waf-bypass | WAF + codec bypass |
misc-encoding | Misc: Morse/Bacon/pigpen/nested decode |
js-reverse | Obfuscation / sign / webpack |
protocol-ws-headers | Headers / WS / CORS / DOM |
command-injection | RCE, $IFS$1, flag-filter bypass |
sql-injection | Union/blind, read flag table |
file-inclusion | LFI/RFI, wrappers |
ssti | Template injection |
xss | Reflected/stored/DOM |
file-upload | Upload signal rounds |
xxe | XXE, php://filter |
deserialization | PHP/Java/Pickle POP |
framework-deserialization-rce | Shiro/Fastjson/… |
ssrf | Internal, gopher/Redis, metadata |
idor-auth | IDOR, JWT |
session-cookie | Session attributes |
api-security | Swagger/@type/GraphQL |
crypto-flaws | Weak crypto, predictable tokens |
code-audit | White-box source→sink |
ctf-ai-basics | AI track routing |
prompt-injection | Direct jailbreak / system leak |
ctf-ai-indirect-rag | Indirect/RAG/upload/URL injection |
ctf-ai-agent-tools | Agent / Tool / MCP abuse |
ctf-ai-output-chain | Output chain / XSS / sandbox escape |
CTF mode prefers the CTF library; Pentest mode prefers the pentest library. Both may be enabled; task mode wins on conflict.
AI Tasks panel: Smart inject
- On the AI Tasks Skills list, each main knowledge base (e.g.
Hx0 Pentest Knowledge Base, imported custom skills) has a Smart inject toggle on the right; hover for the tooltip.
- Off (default): for that library, only the reference sub-modules you manually checked before the task are injected; no mid-task append for that library. Use when you want tight control over prompt size and topic scope.
- On: in addition to initial injection, when the agent finds new vuln types from traffic/judgments, matching sub-modules for that library may be appended (still constrained by the global enabled list in Advanced settings). The log shows
Mid-task Skills injection; the injection summary tags Smart inject vs Manual only.
- You must check the main skill checkbox first before Smart inject is usable; if the global Skills switch is off, the whole injection path is disabled.
AI Generate Skill (Pro)
- Entry: popup Advanced → AI Skills →
AI Generate Skill (Pro license + configured Base URL / Key / Model).
- Output type:
Single skill produces one SKILL body; Skill collection produces 2–6 related modules (result tabs let you edit each).
- Generation constraints: built-in prompts require HawkEye tool IDs (
packet.mutate, replay.request, crypto.logic.analyze, etc.)—not external curl/sqlmap workflows.
- Save to:
Standalone Skill: added to imported skills, enable in AI Tasks;
Pentest / CTF knowledge base · sub-module: written as an AI-generated built-in reference (editable/deletable locally);
New standalone Skill (with sub-modules): parent Skill + references/ layout;
Append to imported Skill: pick an existing custom skill from the dropdown.
- After generation: edit Markdown before save;
Export to file; Regenerate returns to the prompt panel. Your description and prompt fragments are sent to your configured AI endpoint during generation; saved bodies stay on-device and inject with AI Tasks when enabled.
Import external skills (two modes)
- Import skill file: a single
SKILL.md, a .skill / .zip pack (zip archive with SKILL.md and optional references/), or compatible skill markdown. .skill is the standard Cursor / Claude Code / Agent Skills package format and imports the whole pack (including sub-modules) in one click.
- Import skill folder: a directory containing
SKILL.md; the extension also loads .md files under references/ or reference/. Best for migrating an unpacked agent skill folder.
Recommended layout
my-skill/
├── SKILL.md
└── references/
├── sql-injection.md
└── file-upload.md
Also accepts common agent paths such as .cursor/skills/my-skill/SKILL.md, .agents/skills/…/SKILL.md, and markdown under a /skills/ path segment. Zip that folder and rename to .skill to import the whole pack via Import skill file.
Format requirements
- Main file is Markdown; preferred names:
SKILL.md, skill.md, Skill.md. You can also import a .skill / .zip pack (a zip containing that Markdown plus optional references).
- Optional YAML frontmatter at the top (between
--- lines). Common keys:
name (strongly recommended): display title;
description (strongly recommended): one-line summary for the list and AI context;
- optional
nameEn / descriptionEn for English UI.
- Body after frontmatter is injected into the AI system prompt when enabled (merged with selected reference modules).
- Reference modules (optional):
.md files under references/. First # heading is the module title; leading > quote line is an optional summary. Toggle per module in Advanced settings and AI Tasks.
Shared tools for AI Tasks & page scripts
Scheduled by AI Tasks via JSON tool_calls, or called directly from page scripts via GM_hx0CallTool (§4.3). In custom skill bodies, cite the tool ID and intent so the model verifies in the browser session—not external curl/scripts.
| Tool ID |
Capability |
Typical use |
capture.history |
Fetch capture history for the current target host |
Find adjacent APIs, param names, cookie/session context |
browser.navigate / browser.back / browser.forward | Control the bound real test tab and return a fresh snapshot; navigation stays in the authorized target by default | Reuse the current login session without installing Browser MCP |
browser.snapshot | Produce an accessibility snapshot and element refs (password values are masked) | Understand the page before precise ref-based interaction |
browser.click / browser.hover / browser.type / browser.select_option / browser.press_key | Click, hover, type, select, or send keys by ref | Login, search, menus, dialogs, and interaction checks |
browser.wait / browser.console / browser.screenshot | Wait for dynamic UI, read console logs, or capture visual evidence | SPA states, script errors, canvas/CAPTCHA/challenge pages |
source.audit |
Audit HTML/response for source snippets, comments, hidden hints |
CTF source challenges, front-end leaks, comment hints |
replay.request |
Replay one raw HTTP request and return the response |
Verify a single hypothesis; close the evidence loop |
replay.dom |
In-page replay: real navigation or urlencoded form POST then extract DOM (optional dom_wait_ms) |
Encrypted/challenge/WAF HTML; same as replay workbench “In-page replay”; single-request use this; batch §marker§ variants use microfuzz.run with use_dom:true |
packet.mutate |
Inject payload variants into named params on an existing raw request |
SQLi / XSS / command injection single-param probes |
fuzz.plan |
Expand fuzz variants when you supply seed_values |
Small variants from evidenced seeds—not blind dictionary scans |
codec.transform |
MD5/SM3/SHA/HMAC, Base64/Hex/URL/Unicode, JWT/JSON/timestamp, AES/DES/RSA/SM2/SM4, auto_probe smart nested decode; AES/RSA/SM accept key/iv/mode; no chain[]—multi-step = multiple calls |
CTF encoding, JWT tampering, client-crypto verification, pre-bypass decoding |
crypto.logic.analyze |
Infer sign/token/password chains from rawRequest, optional parameter/fieldName, and same-page JS/HTML |
Front-end sign challenges, login crypto, pre–JS-reverse triage; same engine as replay-workbench analysis |
llm.history / llm.chat |
Detect page Chat APIs; fetch history or append user messages for multi-turn dialogue |
CTF prompt-injection / LLM multi-turn probing |
upload.probe |
Detect upload forms, field names, and upload surfaces |
File-upload entry discovery |
upload.fuzz |
Build multipart bypass variants (ext/double-ext/null-byte/image-horse, etc.), optional execute |
Upload filter / Content-Type bypass checks |
ws.probe |
Find WebSocket endpoints (ws:// / wss://) from page HTML |
WebSocket entry discovery |
ws.fuzz |
Send JSON/text frames via background WebSocket replay |
WS message injection, protocol logic probes |
header.probe |
Detect header-bypass hints on internal/403 pages |
Internal/admin paths, path protection |
header.fuzz |
Matrix Referer / XFF / X-Role (etc.) bypass headers and verify via raw replay |
Header auth bypass, IP restriction bypass |
settings.read |
UI language, AI configured flag, runtime settings |
Script i18n, pre-flight AI check |
sensitive.scan |
Rule-based sensitive hits on URL/HTML/body; items[] with matched text |
Page intel, credential/key leak triage |
darklink.scan |
Single-page dark-link scan; optional use_dom for DOM analysis |
Live dark-link summary while browsing |
darklink.batch |
Batch scan on recordIds[] or same-host history |
Batch dark-link workbench, history review |
capture.inspect |
Combined sensitive + dark-link + flag hints for one record |
CTF single-packet deep dive |
microfuzz.run |
Batch payloads on §injection§ in raw request; optional use_dom |
Micro Fuzz automation, script orchestration |
fuzz.execute |
Execute fuzz plan with auto replay verification |
Small-scale variant verification with a plan |
ai.complete |
Generate text via HawkEye AI config (prompt required) |
Smart pentest assistant, dynamic report copy |
markdown.render |
Markdown → HTML |
Overlay reports for AI output |
Example: “Use capture.history to find POSTs with sign, run crypto.logic.analyze, verify with codec.transform, packet.mutate on sign, then replay.request to close the loop.” Page-script usage: §4.3.
Authoring tips
- State when to use, when not to use; cite tool IDs and capabilities from the table above so AI Tasks or page scripts can propose low-noise, replayable steps.
- Use headings, tables, and short request/payload examples; avoid huge unstructured blocks.
- Keep exploits scoped to authorized tests, CTF labs, or your own sandboxes—do not embed real credentials.
Limits
- Up to 32 imported skills (built-in bases excluded).
- ~80 KB body per skill; ~32 KB per reference; up to 24 reference files per skill.
After import
- Enable/disable, delete (built-ins cannot be deleted), toggle sub-modules, and edit markdown locally in Advanced settings.
- New imports are enabled by default; global sub-modules default to all on—narrow per task in AI Tasks (see §10).
Firefox · skill import: like §4.1 batch import, Firefox opens a separate small window to pick files/folders so the main popup is not closed by the system file dialog. Click the toolbar icon again after import to review results.
17. Contact
For questions, bug reports, commercial cooperation, and more, reach Team Hx0 (Hx0战队) via: