TurenOS includes a bounded HTTP testing workflow for systems you are explicitly authorized to assess.
Never configure a target you do not own or have written authorization to test. TurenOS does not expand scope automatically.
1. Define the target
Configure one HTTP or HTTPS base URL, an authorization note, and exact allowed URL prefixes. Requests outside those prefixes are rejected.
2. Capture a baseline flow
Send a bounded request inside scope. TurenOS retains a redacted flow with sensitive headers and bodies protected.
3. Inspect and replay
List captured flows, inspect one by ID, and replay it with a deliberate method, header, or body mutation. Replay remains inside the configured URL scope.
4. Preserve evidence
Attach a concise analyst note to the relevant flow. Claims should identify the request, observed response, security impact, and uncertainty without storing credentials.
5. Report and cancel
Pentest runs expose durable execution state, findings, evidence, board state, cancellation, and report generation through the TurenOS API. Cancel a run when authorization changes or the target behaves unexpectedly.
The HTTP testing tools do not perform arbitrary network scans, browser exploitation, credential attacks, or out-of-scope requests.