Intelligent Vulnerability Scanner

Probe

Vulnerability scanner with Nuclei template support. Automatic injection point detection, built-in OAST, and scan profiles from quick to thorough.

KarmaGate - Probe
api.example.com ✓ 4 found
https://api.example.com
Connected
847 / 12,000 templates Complete
●1 ●1 ●1 ●1 ●1
critical 9.8
CVE-2024-1234 - SQL Injection in /api/users
high 7.5
Blind XSS via email parameter
medium 5.4
CORS misconfiguration allows credentials
low 2.1
Server version disclosure in headers
info
Missing X-Content-Type-Options header

12,000+ Nuclei Templates Supported

Full compatibility with Nuclei community templates. Detect CVEs, misconfigurations, exposures, and more.

CVEs

3,500+

Known vulnerabilities with CVE identifiers

Misconfigurations

2,100+

Security misconfigurations and exposures

Exposures

1,800+

Sensitive file and data exposures

Default Credentials

900+

Default login combinations

Takeovers

400+

Subdomain and service takeovers

Nuclei Community

3,500+

Full Nuclei template compatibility

Intelligent Scanning Features

Nuclei Template Support

Full compatibility with Nuclei templates. Access 12,000+ community templates for CVEs, misconfigurations, and exposures.

Built-in OAST (Echo)

Integrated out-of-band testing server with WebSocket support. Detect blind SSRF, XSS, and DNS exfiltration without external services.

Auto Injection Detection

Intelligent injection point detection. Probe automatically identifies where to test your target.

Scan Profiles

Quick, standard, and thorough profiles. Balance speed and coverage for your needs.

Severity Scoring

Automatic CVSS scoring and prioritization. Focus on critical vulnerabilities first.

Integrated Workflow

Send findings to Reap for management. One-click retest in Loop. Complete workflow.

Built-in OAST + WebSocket

Detect blind vulnerabilities without external services. Probe includes built-in out-of-band testing for:

  • Blind SSRF
    Detect server-side request forgery vulnerabilities
  • Blind XSS
    Find stored XSS in admin panels and reports
  • DNS Exfiltration
    Detect data leaks via DNS queries
  • Blind Command Injection
    Find RCE without visible output
# OAST Callback received
Type: HTTP
Source: 10.0.0.42
Target: /api/fetch?url=...
Correlation: Matched
✓ Blind SSRF confirmed

Start scanning smarter

Try Probe today and discover vulnerabilities you've been missing.

Skip to main content