Skip to main content
TurenOS includes a bounded HTTP testing workflow for systems you are explicitly authorized to assess.
Never configure a target you do not own or have written authorization to test. TurenOS does not expand scope automatically.

1. Define the target

Configure one HTTP or HTTPS base URL, an authorization note, and exact allowed URL prefixes. Requests outside those prefixes are rejected.

2. Capture a baseline flow

Send a bounded request inside scope. TurenOS retains a redacted flow with sensitive headers and bodies protected.

3. Inspect and replay

List captured flows, inspect one by ID, and replay it with a deliberate method, header, or body mutation. Replay remains inside the configured URL scope.

4. Preserve evidence

Attach a concise analyst note to the relevant flow. Claims should identify the request, observed response, security impact, and uncertainty without storing credentials.

5. Report and cancel

Pentest runs expose durable execution state, findings, evidence, board state, cancellation, and report generation through the TurenOS API. Cancel a run when authorization changes or the target behaves unexpectedly. The HTTP testing tools do not perform arbitrary network scans, browser exploitation, credential attacks, or out-of-scope requests.