Skip to main content

Overview

Vigolium’s native scan pipeline consists of multiple phases that run sequentially. You can run the full pipeline, isolate a single phase with --only, or skip specific phases with --skip. This guide walks through each phase and how to run them independently.

The Full Pipeline

When you run a standard scan, phases execute in this order:
  1. External Harvest: gather endpoints from external sources (Wayback Machine, CommonCrawl, AlienVault, urlscan, VirusTotal)
  2. Discovery: content discovery via wordlists and fuzzing
  3. Spidering: browser-based crawling to discover dynamic content
  4. Known Issue Scan: template-based scanning with Nuclei + Kingfisher secret detection
  5. Dynamic-Assessment: active and passive vulnerability scanning modules
A full scan with all phases enabled:
Source-aware whitebox analysis (SAST, code audit, route extraction) lives in agent mode now, see Agentic Scanning.

Running a Single Phase

Use vigolium run <phase> or vigolium scan --only <phase> to execute one phase in isolation.

Probe

A host sweep: one request per target, passive fingerprinting and attack-surface scoring, no content discovery and no fuzzing. Built for host lists in the thousands, where run discovery would spend its whole budget on the first handful.
Sweep with JSONL on stdout and TLS certificates:
The aliases probing, httpx, alive, and sweep all work. A probe-only run flips its own defaults - redirect hops recorded, --redirect-mode same-apex, proactive WAF pacing off - see Probe for the full flag surface and the surface_score model.

Discovery

Discovers new endpoints through wordlist-based fuzzing and content probing:
Equivalent to:
Tune discovery with additional flags:

Spidering

Crawls the target using a headless browser to discover pages, forms, and JavaScript-rendered content:
Control the browser engine and parallelism:
The alias spitolas also works:

External Harvest

Pulls endpoints from external intelligence sources (Wayback Machine, certificate transparency logs):

Known Issue Scan

Runs template-based scanning (Nuclei templates) against ingested endpoints:
Filter templates by severity or tags:

Dynamic-Assessment

Runs active and passive vulnerability scanning modules. This is the core scanning phase (formerly named audit).
Select specific modules or tags:

Extension

Runs only custom JavaScript or YAML extensions:

Skipping Phases

Use --skip to disable specific phases while keeping the rest of the pipeline:
Note: --only and --skip cannot be used together.

Phase Aliases

Every phase accepts shorthand aliases - the gerund, the internal engine name, and the vocabulary of the tool it replaces. Canonical names are listed first. Run vigolium strategy --json for the authoritative list - it is generated from the same registry the flags are validated against, so phases[].canonical and phases[].aliases are exactly what --only, --skip, and run <phase> accept.

Chaining Phases Manually

You can chain independent phase runs to build a custom pipeline. Each phase stores its results in the database, so subsequent phases pick up where the previous one left off:

Tuning Per-Phase Performance

Override concurrency and rate limits for individual phases using the config file (vigolium-configs.yaml):
CLI flags (-c, --rate-limit) always take precedence over config values.

Controlling Scope

Scope filtering applies across all phases. Use --scope-origin to control host matching:

Adding Authentication

All phases respect authentication headers. Pass them with -H:
For multi-session testing (e.g., IDOR detection), use session configs: