Skip to content

#137 · Reproduce Complex Exploits in Escape: Multi-Step Custom Rules Are Here

Until now, custom rules in Escape were limited to single-request vulnerabilities. You could only define and test one request at a time.

This meant that more complex vulnerabilities, such as those requiring multiple chained steps (e.g., creating a user, then editing that user to escalate privileges), couldn’t be implemented.

That changes today.

Introducing Multi-Step Custom Rules

You can now chain multiple requests together in a single custom rule, allowing you to simulate complex attack flows, just like a pentester would.

With multi-step rules, you can:

  • Extract data from one request (e.g., a token, user ID, or session key)
  • Modify and reinject it into subsequent requests
  • Recreate full exploitation chains that were previously impossible to model in Escape

Plus, you can now learn from bug-bounty and external reports: when a report (for example, a HackerOne finding) describes a multi-step exploit, you can implement it directly in Escape to validate, triage, and create reproducible test cases.

This unlocks the ability to implement virtually **any vulnerability scenario (**even the most advanced ones) directly inside Escape.

Get started: this is available now in our API scanner. See the docs and specific examples here.