File: parameter-digger.md | Updated: 11/18/2025
The Param Digger is a tool that can be used for parameter discovery. It identifies hidden, unlinked, and โobscureโ parameters that can be useful for increasing the attack surface, thus easing the process of finding vulnerabilities. It uses a given URL as a seed and performes brute force guessing attacks to identify parameters. Itโs primarily based on James Kettle โs research and implementation: Practical Web Cache Poisoning and Web Cache Entanglement .
The Param Digger can be configured and started using the Param Digger dialog .
It provides:
A menu item under the top level โToolsโ menu.
A basic status panel.
An API component that adds an action endpoint.
Directory listing - 3 item(s) total