debugHunter Settings

Configure detection behavior and reduce false positives

Detection Strategy

Smart mode combines multiple signals: status code changes, content length, debug keywords, and similarity.

Thresholds

0.90

How similar two responses must be to be considered "the same". Lower = more aggressive (more FPs). Used as secondary check in Smart mode.

200

Minimum bytes difference to consider a response "changed". Higher = fewer false positives from minor dynamic content.

480

How often to re-check the same URL. Default: 480 minutes (8 hours).

Dynamic Content Filters

Regex patterns for dynamic content to strip before comparing responses. Examples: timestamps, CSRF tokens, nonces.

Default patterns include: Unix timestamps, ISO dates, UUIDs, CSRF tokens, session IDs, nonces, and common cache busters. Add custom patterns here if you're seeing false positives from specific dynamic content.

Rate Limiting

300

Minimum delay between requests to the same domain. Auto-increases on rate limiting.

How many different check types can run in parallel (params, headers, paths).

Whitelist

Domains to skip scanning. Supports wildcards (*.example.com).