Weak security headers, cookies, CSP trust, cache posture, wildcard postMessage, origin allowlists, and an insecure ws:// literal from an HTTPS response.
Representative key, token, webhook, DSN, and private-material patterns embedded in a JavaScript asset.
Node, Java, .NET, Python, and PHP traces together with internal IPs, service names, cluster DNS, and environment hints.
API documentation, GraphQL consoles, specs, persisted-query shapes, and GraphQL schema/error terms.
Security metadata, OIDC/OAuth configuration, JWKS, change-password, robots, humans, and mobile-association files.
Hidden redirect, role, tenant, token, callback, and finance/support fields plus sensitive form actions and dangerous query names.
Tenant routes, scope headers/cookies, tenant slug fields, and switch-org or switch-tenant workflow hints.
Socket.IO, SockJS, SSE, WebSocket upgrade paths, realtime literals, and token placement patterns.
WordPress, Drupal, DWR, database consoles, product consoles, queue dashboards, and debug/admin routes.
Credit cards, SSNs, serialized-object markers, unsafe blobs, and helper links that place secrets in URLs.
| Family | Suggested routes |
|---|---|
| Headers and cache | https://localhost:3443/passive/fixtures/headers/weak-security.html, http://localhost:3080/passive/fixtures/headers/hsts-over-http.html |
| API docs and GraphQL | /passive/swagger-ui/index.html, /passive/openapi.json, /passive/graphql, /passive/graphiql |
| .well-known metadata | /.well-known/openid-configuration, /.well-known/security.txt, /.well-known/jwks.json |
| Workflows, tenant, and auth | /passive/checkout/payment.html, /login, /mfa/verify, /orgs/acme/workspaces/red-team/settings.html |
| Realtime | /passive/realtime/overview.html, /socket.io/?EIO=4&transport=websocket, /passive/realtime/events |