Skip to content

Custom Rules Reference

Auto-generated reference for the JSON Schema accepted by the Escape platform. Both surfaces are covered below.

Shared models (AlertModel, Compliance, CustomRuleID, ...) are documented once in the API reference; the WebApp reference lists only WebApp-specific models and links back to the API section for shared definitions.

API Reference

APICustomRule

Property Type Default Description
alert* AlertModel The alert to raise if the detection conditions are met. See Alerting
detect* List[APILogicalAndDetector,APILogicalNotDetector,APILogicalOrDetector,FingerprintCountDetector,FingerprintsSameDetector,HelpersRequestCrudDetector,HelpersResponseIsSuccessfulDetector,JSONMatchesAllDetector,JSONMatchesCountDetector,RegexMatchesAllDetector,RegexMatchesCountDetector,RequestBodyJSONDetector,RequestBodyTextDetector,RequestHeadersDetector,RequestIsAuthenticatedDetector,RequestMethodDetector,RequestObjectDetector,RequestUserDetector,ResponseBodyJSONDetector,ResponseBodyTextDetector,ResponseDurationDetector,ResponseHeadersDetector,ResponseObjectDetector,ResponseStatusCodeDetector,ScanTypeDetector,SchemaNeedAuthenticationDetector,SchemaPathRefDetector,SchemaUrlDetector,VariableDefinedDetector] The conditions to trigger the alert. See Detectors
extractors List[APIExtractor] The extractors to extract the data from the response. See Extractors
id* CustomRuleID The unique identifier of the custom rule. It's provided by Escape, don't set it manually.
seed List[CurlSeeder,HTTPRAWSeeder,RESTSeeder] A list of requests to seed the scan. See Seeders
transform Middleware null Defines lists of triggers and mutators (combined with AND operators). See Mutators
type Const[API] API The type of the custom rule. It's provided by Escape, don't set it manually.

Objects

APIExtractor

Property Type Default Description
extract* List[RequestArgument,RequestCookieExtractor,ResponseBodyJSONExtractor,ResponseBodyTextExtractor,ResponseCookieExtractor,ResponseDurationExtractor,ResponseHeaderExtractor,ResponseStatusCodeExtractor,SchemaUrlExtractor] The extractions to apply to the request/response. (See below)
trigger* List[APILogicalAndDetector,APILogicalNotDetector,APILogicalOrDetector,FingerprintCountDetector,FingerprintsSameDetector,HelpersRequestCrudDetector,HelpersResponseIsSuccessfulDetector,JSONMatchesAllDetector,JSONMatchesCountDetector,RegexMatchesAllDetector,RegexMatchesCountDetector,RequestBodyJSONDetector,RequestBodyTextDetector,RequestHeadersDetector,RequestIsAuthenticatedDetector,RequestMethodDetector,RequestObjectDetector,RequestUserDetector,ResponseBodyJSONDetector,ResponseBodyTextDetector,ResponseDurationDetector,ResponseHeadersDetector,ResponseObjectDetector,ResponseStatusCodeDetector,ScanTypeDetector,SchemaNeedAuthenticationDetector,SchemaPathRefDetector,SchemaUrlDetector,VariableDefinedDetector] The detectors to trigger the extraction on the request or response. Detectors

APILogicalAndDetector

Property Type Default Description
and* List[APILogicalAndDetector,APILogicalNotDetector,APILogicalOrDetector,FingerprintCountDetector,FingerprintsSameDetector,HelpersRequestCrudDetector,HelpersResponseIsSuccessfulDetector,JSONMatchesAllDetector,JSONMatchesCountDetector,RegexMatchesAllDetector,RegexMatchesCountDetector,RequestBodyJSONDetector,RequestBodyTextDetector,RequestHeadersDetector,RequestIsAuthenticatedDetector,RequestMethodDetector,RequestObjectDetector,RequestUserDetector,ResponseBodyJSONDetector,ResponseBodyTextDetector,ResponseDurationDetector,ResponseHeadersDetector,ResponseObjectDetector,ResponseStatusCodeDetector,ScanTypeDetector,SchemaNeedAuthenticationDetector,SchemaPathRefDetector,SchemaUrlDetector,VariableDefinedDetector] Logical and on a list of detectors
if Const[and] and Use this to apply a logical and on a list of detectors.

APILogicalNotDetector

Property Type Default Description
if Const[not] not Use this to apply a logical not on a detector.
not APILogicalAndDetector, APILogicalNotDetector, APILogicalOrDetector, FingerprintCountDetector, FingerprintsSameDetector, HelpersRequestCrudDetector, HelpersResponseIsSuccessfulDetector, JSONMatchesAllDetector, JSONMatchesCountDetector, RegexMatchesAllDetector, RegexMatchesCountDetector, RequestBodyJSONDetector, RequestBodyTextDetector, RequestHeadersDetector, RequestIsAuthenticatedDetector, RequestMethodDetector, RequestObjectDetector, RequestUserDetector, ResponseBodyJSONDetector, ResponseBodyTextDetector, ResponseDurationDetector, ResponseHeadersDetector, ResponseObjectDetector, ResponseStatusCodeDetector, ScanTypeDetector, SchemaNeedAuthenticationDetector, SchemaPathRefDetector, SchemaUrlDetector, VariableDefinedDetector null Logical not of a detector

APILogicalOrDetector

Property Type Default Description
if Const[or] or Use this to apply a logical or on a list of detectors.
or* List[APILogicalAndDetector,APILogicalNotDetector,APILogicalOrDetector,FingerprintCountDetector,FingerprintsSameDetector,HelpersRequestCrudDetector,HelpersResponseIsSuccessfulDetector,JSONMatchesAllDetector,JSONMatchesCountDetector,RegexMatchesAllDetector,RegexMatchesCountDetector,RequestBodyJSONDetector,RequestBodyTextDetector,RequestHeadersDetector,RequestIsAuthenticatedDetector,RequestMethodDetector,RequestObjectDetector,RequestUserDetector,ResponseBodyJSONDetector,ResponseBodyTextDetector,ResponseDurationDetector,ResponseHeadersDetector,ResponseObjectDetector,ResponseStatusCodeDetector,ScanTypeDetector,SchemaNeedAuthenticationDetector,SchemaPathRefDetector,SchemaUrlDetector,VariableDefinedDetector] Logical or on a list of detectors

AlertModel

Property Type Default Description
category CustomRuleCategory CUSTOM Category of the alert
compliance Compliance null Compliance standards violated by this alert
context* string Context of the alert
description string null Description of the alert
name* string Name of the alert
remediation string null Remediation of the alert
severity* CustomRuleSeverity Severity of the alert

BaseStringMutate

Property Type Default Description
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

Compliance

Property Type Default Description
cra Literal[Annex I-1, Article-11] null
cwe Literal[16, 20, 22, 78, 79, 89, 93, 94, 116, 119, 200, 209, 215, 264, 284, 285, 287, 295, 306, 307, 311, 319, 326, 330, 331, 346, 347, 352, 353, 354, 400, 444, 453, 489, 502, 522, 523, 524, 548, 551, 573, 601, 611, 614, 676, 704, 710, 730, 732, 758, 770, 829, 862, 863, 915, 918, 942, 943, 1029, 1195] null
dora Literal[Article-6, Article-8, Article-9, Article-11] null
fedramp Literal[AC-2, AC-3, AC-4, AC-6, AC-7, AC-14, AC-17, AC-22, CM-2, CM-3, IA-5, SA-11, SC-5, SC-7, SC-8, SC-12, SC-13, SC-17, SC-18, SC-20, SC-28, SI-2, SI-3, SI-4, SI-7, SI-10, SI-11] null
gdpr Literal[Article-5, Article-25, Article-32, Article-33] null
hipaa Literal[Standard-1, Standard-2, Standard-3, Standard-4, Standard-5] null
hitrust_csf Literal[01.c, 01.f, 01.g] null
iec62443 Literal[CR 2.1, CR 3.1, CR 4.1, CR 4.3, CR 5.2, CR 7.1, CR 7.6] null
iso27001 Literal[A.9.1, A.9.4, A.10.1, A.12.1, A.12.2, A.12.3, A.12.6, A.12.7, A.13.1, A.14.1, A.14.2, A.17.1, A.18.1] null
mitre_attack Literal[T1531, T1595, T1557, T1110, T1580, T1059, T1659, T1555, T1486, T1530, T1602, T1213, T1565, T1140, T1499, T1190, T1203, T1211, T1068, T1083, T1606, T1592, T1589, T1590, T1525, T1556, T1542, T1496, T1207, T1505, T1553, T1195, T1082, T1221, T1199, T1552, T1550, T1078, T1102, T1220] null
nis2 Literal[Article-6, Article-21, Article-22, Article-23, Article-28, Article-29, Article-33] null
nist Literal[SP800-40, SP800-41, SP800-44, SP800-52, SP800-53, SP800-63B, SP800-81-2, SP800-92, SP800-95, SP800-123, SP800-161, SP800-190, SP800-207] null
owasp Literal[API1:2023, API2:2023, API3:2023, API4:2023, API5:2023, API6:2023, API7:2023, API8:2023, API9:2023, API10:2023, A05:2021] null
owasp_asvs Literal[V2, V3, V4, V5, V6, V7, V8, V9, V11, V12, V13, V14] null
owasp_llm Literal[LLM01, LLM02, LLM03, LLM04, LLM05, LLM06, LLM07, LLM08, LLM09, LLM10] null
pci-dss Literal[1.2.3, 1.3, 1.3.7, 2.2.2, 2.2.5, 3.4, 3.5, 4.1, 6.1, 6.2, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 7.1, 7.1.2, 8.2, 8.2.1, 10.2.4] null
psd2 Literal[Article-5, Article-21, Article-32, Article-94, Article-95, Article-96, Article-97, Article-98] null
soc2 Literal[CC1, CC2, CC4, CC5, CC6, CC7, CC9] null
wasc Literal[WASC-02, WASC-04, WASC-08, WASC-09, WASC-10, WASC-11, WASC-13, WASC-14, WASC-15, WASC-19, WASC-20, WASC-22, WASC-24, WASC-25, WASC-26, WASC-31, WASC-33, WASC-34, WASC-38, WASC-40, WASC-42, WASC-43, WASC-45, WASC-47, WASC-48] null

CurlSeeder

Property Type Default Description
curl* string The curl command to use for the request.
protocol Const[curl] curl Inject a request specified as a curl command. Useful when you already have a working curl one-liner from browser DevTools (Network tab → Right-click → Copy as cURL) or Postman, and you want to drop it in as-is.
user string null The user to use for the request. If not provided, the request is sent as the scan main user.

CustomRuleID

Property Type Default Description

FingerprintCountDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[helpers.fingerprints.count] helpers.fingerprints.count Use this to select and compare the count of unique fingerprints of the current and original response.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
lt integer null Condition is less than this integer

FingerprintsSameDetector

Property Type Default Description
if Const[helpers.fingerprints.same] helpers.fingerprints.same Use this to determine whether the current and original responses have the same fingerprint.
is boolean null Condition is true
is_not boolean null Condition is false

HTTPRAWSeeder

Property Type Default Description
protocol Const[http] http Inject a request at scan start, formatted as a raw HTTP message with a @Host directive. Use when you need full control over the wire format, want to call a host outside the scan target, or need non-standard headers / methods.
raw* string The raw HTTP request in Nuclei format.
user string null The user to use for the request. If not provided, the request is sent as the scan main user.

HelpersRequestCrudDetector

Property Type Default Description
if Const[helpers.request.crud] helpers.request.crud Use this to select against the detected CRUD operation of the request.
in List[CRUD] null Condition is the request is in this list of CRUD operations (exact match)
is CRUD null Condition is the request is this CRUD operation
is_not CRUD null Condition is the request isn't this CRUD operation

HelpersResponseIsSuccessfulDetector

Property Type Default Description
if Const[helpers.response.is_successful] helpers.response.is_successful True when the response status code is in the 2xx range.
is boolean null Condition is true
is_not boolean null Condition is false

JSONMatchesAllDetector

Property Type Default Description
if Const[helpers.json_matches.all] helpers.json_matches.all Use this to determine whether every the current and original responses contain the same JSON fragment.
is boolean null Condition is true
is_not boolean null Condition is false
jq string Use this to select the exact JSON you want to compare between the current and original response.

JSONMatchesCountDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[helpers.json_matches.count] helpers.json_matches.count Use this to count the number of times a JSON match is in the current and original response.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
jq string Use this to select the exact JSON you want to compare between the current and original response.
lt integer null Condition is less than this integer

JsonValue

Property Type Default Description

Middleware

Property Type Default Description
mutate* List[RequestBodyJSONMutator,RequestBodyTextMutator,RequestHeadersMutator,RequestMethodMutator,RequestObjectMutator,RequestUserMutator,SchemaPathRefMutator,SchemaUrlMutator] The mutations to apply to the request and replay it. See Mutators
trigger* List[APILogicalAndDetector,APILogicalNotDetector,APILogicalOrDetector,FingerprintCountDetector,FingerprintsSameDetector,HelpersRequestCrudDetector,HelpersResponseIsSuccessfulDetector,JSONMatchesAllDetector,JSONMatchesCountDetector,RegexMatchesAllDetector,RegexMatchesCountDetector,RequestBodyJSONDetector,RequestBodyTextDetector,RequestHeadersDetector,RequestIsAuthenticatedDetector,RequestMethodDetector,RequestObjectDetector,RequestUserDetector,ResponseBodyJSONDetector,ResponseBodyTextDetector,ResponseDurationDetector,ResponseHeadersDetector,ResponseObjectDetector,ResponseStatusCodeDetector,ScanTypeDetector,SchemaNeedAuthenticationDetector,SchemaPathRefDetector,SchemaUrlDetector,VariableDefinedDetector] The detectors to trigger the transform on the request or response. Detectors

ObjectMatcher

Property Type Default Description
name StringMatcher null Object scalar name to match
type ObjectTypeMatcher null Object scalar type to match
value StringMatcher null Object scalar value to match

ObjectTypeMatcher

Property Type Default Description
in List[OBJECT_TYPE] null Object type is in the following list
is OBJECT_TYPE null Object type is exactly this type
is_not OBJECT_TYPE null Object type is any this type except this one

RESTSeeder

Property Type Default Description
body string null The body to use for the request.
headers Dict[string, string] null The headers to use for the request. The key is the header name and the value is the header value.
method HTTPMethod null The method to use for the request.
params Dict[string, string] null parameters to use for the request. The key is the parameter name and the value is the parameter value.
path string null The path to use for the request.
protocol Const[rest] rest Inject a REST request at scan start. Host and scheme are automatically filled from the scan target so you only specify the path, method, and any headers / body / query parameters.
user string null The user to use for the request. If not provided, the request is sent as the scan main user.

RegexMatchesAllDetector

Property Type Default Description
if Const[helpers.regex_matches.all] helpers.regex_matches.all Use this to determine whether every the current and original responses match the same regular expression.
is boolean null Condition is true
is_not boolean null Condition is false
regex string Condition is matched on this regex with fullmatch

RegexMatchesCountDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[helpers.regex_matches.count] helpers.regex_matches.count Use this to count the number of times a regex match is in the current and original response.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
lt integer null Condition is less than this integer
regex string Condition is matched on this regex with fullmatch

RegexReplace

Property Type Default Description
pattern* string The regex pattern to match.
replacement* string The replacement, use \1, \2, ... to refer capture groups.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

RequestArgument

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
jq string null JQ query to apply to the JSON body. See stedolan.github.io
key Const[request.argument] request.argument You can use this extractor to extract an argument from request body as a variable.
scalars List[string] null Scalars the argument has to match to be extracted
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

RequestBodyJSONDetector

Property Type Default Description
if Const[request.body.json] request.body.json Use this to select and compare the request body when detected as JSON, using jq-like syntax.
in List[JsonValue] null Condition is in this list of JSON
is JsonValue null Condition is this exact JSON
is_not JsonValue null Condition isn't this exact JSON
jq string null JQ query to match and use as boolean. If use_extraction is True, only this attribute will be parsed (if set).
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

RequestBodyJSONMutator

Property Type Default Description
jq string null JQ query to apply to the JSON body. See stedolan.github.io
key Const[request.body.json] request.body.json Transform the JSON body of the request using a JQ expression. JQ is the most powerful mutator in the DSL: it can add fields, remove fields, walk every string, restructure objects
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

RequestBodyTextDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[request.body.text] request.body.text Use this to select and compare the request body as text, using string compare.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

RequestBodyTextMutator

Property Type Default Description
key Const[request.body.text] request.body.text You can use this mutator to change the body (as text) of the request before resending it.
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

RequestCookieExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[request.cookies] request.cookies You can use this extractor to extract variables from the request cookies.
name* string Cookie name to extract from
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

RequestHeadersDetector

Property Type Default Description
if Const[request.headers] request.headers Use that to select and compare the request headers in a key value dictionary.
key StringMatcher null Key to match
value StringMatcher null Value to match

RequestHeadersMutator

Property Type Default Description
delete boolean null Delete the matched headers.
key Const[request.headers] request.headers You can use this mutator to change the headers of the request before resending it. If no header is matched, a new header will be added and set to the value.
name* string The header name to match, supports regex.
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

RequestIsAuthenticatedDetector

Property Type Default Description
if Const[request.is_authenticated] request.is_authenticated Use this to select whether the request is authenticated.
is boolean null Condition is true
is_not boolean null Condition is false

RequestMethodDetector

Property Type Default Description
if Const[request.method] request.method Use this to select against the request HTTP Method.
in List[HTTPMethod] null Condition is the request is in this list of CRUD operations (exact match)
is HTTPMethod null Condition is the request is this CRUD operation
is_not HTTPMethod null Condition is the request isn't this CRUD operation

RequestMethodMutator

Property Type Default Description
key Const[request.method] request.method Change the HTTP method of the request before resending it.
value HTTPMethod null The value to set.
values List[HTTPMethod] null The values to set, generates multiple queries.

RequestObjectDetector

Property Type Default Description
if Const[request.object] request.object Use this to select and compare the detected object scalars (including custom scalars) in the request, with their kind, name and value.
name StringMatcher null Object scalar name to match
type ObjectTypeMatcher null Object scalar type to match
value StringMatcher null Object scalar value to match

RequestObjectMutator

Property Type Default Description
key Const[request.object] request.object The detected object scalars (including custom scalars) in the request, with their kind, name and value.
mutate* BaseStringMutate
select* ObjectMatcher

RequestUserDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[request.user] request.user Match the user name attached to the request. The value must match a user defined in your scan authentication settings (the special user public represents an unauthenticated caller).
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

RequestUserMutator

Property Type Default Description
drop_user boolean null Remove the user authentication from the request.
key Const[request.user] request.user Replay the request as a different authenticated user (or as anonymous via drop_user: true). The user must be defined in your scan authentication settings.
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

ResponseBodyJSONDetector

Property Type Default Description
if Const[response.body.json] response.body.json Use this to select and compare the response body when detected as JSON, using jq-like syntax.
in List[JsonValue] null Condition is in this list of JSON
is JsonValue null Condition is this exact JSON
is_not JsonValue null Condition isn't this exact JSON
jq string null JQ query to match and use as boolean. If use_extraction is True, only this attribute will be parsed (if set).
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

ResponseBodyJSONExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
jq* string JQ query to apply to the JSON body. See stedolan.github.io
key Const[response.body.json] response.body.json You can use this extractor to extract variables from the response body JSON.
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ResponseBodyTextDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[response.body.text] response.body.text Use this to select and compare the response body as text, using string compare.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

ResponseBodyTextExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[response.body.text] response.body.text You can use this extractor to extract variables from the response body text.
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ResponseCookieExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[response.cookies] response.cookies You can use this extractor to extract variables from the response cookies.
name* string Cookie name to extract from
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ResponseDurationDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[response.duration_ms] response.duration_ms Use this to compare the duration of the request in milliseconds.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
lt integer null Condition is less than this integer

ResponseDurationExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[response.duration] response.duration You can use this extractor to extract the response duration as a variable.
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ResponseHeaderExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[response.headers] response.headers You can use this extractor to extract variables from the response headers.
name* string Header name to extract from
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ResponseHeadersDetector

Property Type Default Description
if Const[response.headers] response.headers Use that to select and compare the response headers in a key value dictionary.
key StringMatcher null Key to match
value StringMatcher null Value to match

ResponseObjectDetector

Property Type Default Description
if Const[response.object] response.object Use this to select and compare the detected object scalars (including custom scalars) in the response, with their kind, name and value.
name StringMatcher null Object scalar name to match
type ObjectTypeMatcher null Object scalar type to match
value StringMatcher null Object scalar value to match

ResponseStatusCodeDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[response.status_code] response.status_code Match against the HTTP response status code.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
lt integer null Condition is less than this integer

ResponseStatusCodeExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[response.status_code] response.status_code You can use this extractor to extract the response status code as a variable.
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

ScanTypeDetector

Property Type Default Description
if Const[scan.type] scan.type Match against the type of scan being performed.
in List[CustomRuleScanType] null The scan type is in this list
is CustomRuleScanType null The scan type is exactly this
is_not CustomRuleScanType null The scan type isn't this type

SchemaNeedAuthenticationDetector

Property Type Default Description
if Const[schema.need_authentication] schema.need_authentication Use this to select whether or not the schema requires authentication.
is boolean null Condition is true
is_not boolean null Condition is false

SchemaPathRefDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[schema.path_ref] schema.path_ref Match the operation name (GraphQL) or the path (REST) of the request.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

SchemaPathRefMutator

Property Type Default Description
key Const[schema.path_ref] schema.path_ref You can use this mutator to change the operation name in GraphQL or the path in REST (keeping the domain) before resending it.
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

SchemaUrlDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[schema.url] schema.url Use this to string compare the URL of the request.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

SchemaUrlExtractor

Property Type Default Description
accept_null boolean false Whether the extractor should accept null values or not.
can_overwrite boolean true Whether the extractor can overwrite the variable if it already exists.
key Const[schema.url] schema.url You can use this extractor to extract variables from the schema URL.
variable* VariableName The variable name (Case Insensitive) to store the extracted data.

SchemaUrlMutator

Property Type Default Description
key Const[schema.url] schema.url You can use this mutator to change the URL of the request before resending it.
regex_replace RegexReplace null Regex replace pattern.
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.
value string null The value to set.
values List[string] null The values to set, generates multiple queries.

StringMatcher

Property Type Default Description
contains string null Contains this substring (case-insensitive)
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

VariableDefinedDetector

Property Type Default Description
if Const[variable.defined] variable.defined Use this to detect if a given variable has been extracted or not yet.
variable_name* string Use this to specify the variable name that has to be defined before proceeding further

VariableName

Property Type Default Description

Enums

CRUD

Value
CREATE
READ
UPDATE
DELETE

CustomRuleCategory

Value
ACCESS_CONTROL
CONFIGURATION
INFORMATION_DISCLOSURE
INJECTION
PROTOCOL
REQUEST_FORGERY
RESOURCE_LIMITATION
SENSITIVE_DATA
SCHEMA
CUSTOM

CustomRuleScanType

Value
GRAPHQL
REST

CustomRuleSeverity

Value
HIGH
MEDIUM
LOW
INFO

HTTPMethod

Value
CONNECT
DELETE
GET
HEAD
OPTIONS
PATCH
POST
PUT
TRACE

OBJECT_TYPE

Value
See Data Types Reference

WebApp Reference

FrontendCustomRule

Property Type Default Description
alert* AlertModel The alert to raise if the detection conditions are met. See Alerting
detect* List[CookieDetector,DialogMessageDetector,FrontendLogicalAndDetector,FrontendLogicalNotDetector,FrontendLogicalOrDetector,HeaderDetector,JSAssertionDetector,LastRequestResponseTextDetector,LocalStorageDetector,PageSelectorDetector,PageStatusCodeDetector,PageTextDetector,SessionStorageDetector] The conditions to trigger the alert. See Detectors
extractors List[object] Extractors aren't currently supported for Frontend custom rules.
id* CustomRuleID The unique identifier of the custom rule. It's provided by Escape, don't set it manually.
seed* List[CheckAction,ClickAction,ClickMailMagicLinkAction,FillAction,FillMailTOTPAction,FillTOTPAction,FocusPageAction,FrontendGotoAction,FrontendRequestAction,SelectAction,SleepAction,SolveCaptchaAction,WaitElementAction,WaitTextAction] A list of requests to seed the scan. See Seeders
type Const[WEBAPP] WEBAPP The type of the custom rule. It's provided by Escape, don't set it manually.

Objects

CheckAction

Property Type Default Description
action Const[check] check
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
locator* string The Playwright Locator to select the checkbox to check
select_first_if_multiple boolean false Whether to select the first element if multiple elements are found. If false, an error will be raised.
timeout integer 30 Timeout in seconds for executing the check action

ClickAction

Property Type Default Description
action Const[click] click
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
locator* string The Playwright Locator to select the element to click on
select_first_if_multiple boolean false Whether to select the first element if multiple elements are found. If false, an error will be raised.
timeout integer 30 Timeout in seconds for executing the click action

ClickMailMagicLinkAction

Property Type Default Description
action Const[click_mail_magic_link] click_mail_magic_link
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
email_address* string The email address where the magic link will be sent.\nMust be a valid scan inbox address matching {alias}.{mailboxId}@scan.escape.tech. The full organization UUID suffix is still accepted for existing configurations. Alias: 1-27 ASCII letters, digits, and hyphens; dots allowed only between characters.
new_page boolean false Whether to create a new page for the navigation or remain on the current page
timeout integer 60 The timeout (seconds) to wait for the page to load

CookieDetector

Property Type Default Description
if Const[cookie] cookie Use this to assert that a cookie is present in the browser.
key StringMatcher null Key to match
value StringMatcher null Value to match

DialogMessageDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[dialog.message] dialog.message Use this to assert that a JavaScript dialog (alert, confirm, prompt) was triggered by the page and inspect its message. Useful for catching reflected XSS payloads that fire alert() once rendered.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

FillAction

Property Type Default Description
action Const[fill] fill
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
auto_submit boolean false Whether the form should be automatically submitted after the fill action
locator* string The Playwright Locator to select the field to fill
one_by_one boolean false Whether the field should be typed one character by one character, like a TOTP code
select_first_if_multiple boolean false Whether to select the first element if multiple elements are found. If false, an error will be raised.
timeout integer 30 Timeout in seconds for executing the input filling action
value* string The value to fill in the field

FillMailTOTPAction

Property Type Default Description
action Literal[fill_mail_totp, fill_email_totp] fill_email_totp Use fill_email_totp. fill_mail_totp is deprecated and can be removed in the future.
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
auto_submit boolean false Whether the form should be automatically submitted after the fill action
email_address* string The email address where the TOTP code will be sent.\nMust be a valid scan inbox address matching {alias}.{mailboxId}@scan.escape.tech. The full organization UUID suffix is still accepted for existing configurations. Alias: 1-27 ASCII letters, digits, and hyphens; dots allowed only between characters.
locator* string The Playwright Locator to select the field to fill
one_by_one boolean false Whether the field should be typed one character by one character, like a TOTP code
select_first_if_multiple boolean false Whether to select the first element if multiple elements are found. If false, an error will be raised.
timeout integer 30 Timeout in seconds for executing the input filling action

FillTOTPAction

Property Type Default Description
action Const[fill_totp] fill_totp
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
auto_submit boolean false Whether the form should be automatically submitted after the TOTP code is filled
locator* string The Playwright Locator to select the field to fill the TOTP code in
secret* string The secret to generate the TOTP code from

FocusPageAction

Property Type Default Description
action Const[focus_page] focus_page
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
url_pattern* string The pattern to find in the URL to focus on a page. Should be a regex allowing to match the page using Python re.findall().

FrontendGotoAction

Property Type Default Description
action Const[goto] goto
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
new_page boolean false Whether to create a new page for the navigation or remain on the current page
timeout integer 60 The timeout (seconds) to wait for the page to load
url* string The URL to navigate to
verify_scope boolean true When true, verify that the URL is within the crawling scope. When false, allow navigation to out-of-scope URLs.

FrontendLogicalAndDetector

Property Type Default Description
and* List[CookieDetector,DialogMessageDetector,FrontendLogicalAndDetector,FrontendLogicalNotDetector,FrontendLogicalOrDetector,HeaderDetector,JSAssertionDetector,LastRequestResponseTextDetector,LocalStorageDetector,PageSelectorDetector,PageStatusCodeDetector,PageTextDetector,SessionStorageDetector] Logical and on a list of detectors
if Const[and] and

FrontendLogicalNotDetector

Property Type Default Description
if Const[not] not
not CookieDetector, DialogMessageDetector, FrontendLogicalAndDetector, FrontendLogicalNotDetector, FrontendLogicalOrDetector, HeaderDetector, JSAssertionDetector, LastRequestResponseTextDetector, LocalStorageDetector, PageSelectorDetector, PageStatusCodeDetector, PageTextDetector, SessionStorageDetector null Logical not of a detector

FrontendLogicalOrDetector

Property Type Default Description
if Const[or] or
or* List[CookieDetector,DialogMessageDetector,FrontendLogicalAndDetector,FrontendLogicalNotDetector,FrontendLogicalOrDetector,HeaderDetector,JSAssertionDetector,LastRequestResponseTextDetector,LocalStorageDetector,PageSelectorDetector,PageStatusCodeDetector,PageTextDetector,SessionStorageDetector] Logical or on a list of detectors

FrontendRequestAction

Property Type Default Description
action Const[send_request] send_request
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
body string The body to use for the request.
headers Dict[string, string] The headers to use for the request.
max_redirects integer The maximum number of redirections to follow.
method HTTPMethod GET The HTTP method to use for the request.
timeout integer 60 The timeout (seconds) to wait for the page to load
url* string The URL to navigate to

HeaderDetector

Property Type Default Description
if Const[header] header Use this to match the browser's document.headers value.
key StringMatcher null Key to match
value StringMatcher null Value to match

JSAssertionDetector

Property Type Default Description
command string null JavaScript command to execute
if Const[js_assertion] js_assertion Use this to execute a JavaScript command and assert it returns true.

LastRequestResponseTextDetector

Property Type Default Description
contains string null Contains this substring (case-insensitive)
if Const[last_request.response.text] last_request.response.text Use this to assert that the last request response text contains a specific substring.
in List[string] null Condition is in this list (case-insensitive)
is string null Condition is this string (case-insensitive)
is_not string null Condition isn't this string (case-insensitive)
regex string null Condition is matched on this regex with fullmatch (case-insensitive)
use_extraction boolean false If True, variable references between {{ }} will be replace with the extracted value (If exists). The string representation of the variable will be used without any extra-processing.

LocalStorageDetector

Property Type Default Description
if Const[local_storage] local_storage Use this to assert that a key is present in the local storage.
key StringMatcher null Key to match
value StringMatcher null Value to match

PageSelectorDetector

Property Type Default Description
contains string null Contains this string
if Const[page_selector] page_selector Use this to assert that a selector exists in the DOM.

PageStatusCodeDetector

Property Type Default Description
gt integer null Condition is greater than this integer
if Const[page_status_code] page_status_code Use this to assert that the page status code is a specific value.
in List[integer] null Condition is in this list of integers (exact match)
is integer null Condition is this exact integer
is_not integer null Condition isn't this exact integer
lt integer null Condition is less than this integer

PageTextDetector

Property Type Default Description
contains string null Contains this string
if Const[page_text] page_text Use this to assert that a text is present in the page.

SelectAction

Property Type Default Description
action Const[select] select
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
locator* string The Playwright Locator to select the dropdown to select from
select_first_if_multiple boolean false Whether to select the first element if multiple elements are found. If false, an error will be raised.
timeout integer 30 Timeout in seconds for executing the click action
value* string The value to select

SessionStorageDetector

Property Type Default Description
if Const[session_storage] session_storage Use this to assert that a key is present in the session storage.
key StringMatcher null Key to match
value StringMatcher null Value to match

SleepAction

Property Type Default Description
action Const[sleep] sleep
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
seconds* number The time to sleep in seconds, between 0 and 40 seconds

SolveCaptchaAction

Property Type Default Description
action Const[solve_captcha] solve_captcha
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
auto_submit boolean false Whether the form should be automatically submitted after the captcha is filled
locator* string The Playwright Locator to select the captcha field to fill

WaitElementAction

Property Type Default Description
action Const[wait_element] wait_element
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
locator* string The selector to wait for
timeout number 10 The timeout (seconds) to wait for the element to be visible

WaitTextAction

Property Type Default Description
action Const[wait_text] wait_text
allow_failure boolean false Allow this action to fail without breaking authentication, defaults to False.
timeout number 10 The timeout (seconds) to wait for the text to be visible
value* string The text to wait for until visible, case-insensitive

Enums