Capture JWT tokens, authenticated sessions, and admin URLs automatically. Score severity. Export a report triagers actually act on.
Free to use · No credit card · Authorized use only
impactlab.sh handles the evidence layer. You handle the disclosure.
Create a hook, get a script tag. Drop it into your Stored XSS payload. No backend. No external dependencies. One line.
When a real user's browser fires the payload, the hook silently captures JWT presence, cookies, storage keys, and authenticated URLs — all redacted at the edge before storage.
Your session is scored automatically. Export a complete impact report — Markdown or PDF — structured for HackerOne, Bugcrowd, or private programs.
Each data point directly answers: "Can this lead to account takeover?"
Evidence accumulates into a score. Score maps to severity. Severity justifies your report.
Auto-generated in English. Structured for HackerOne and Bugcrowd. Secrets automatically redacted. Business impact pre-written. Remediation included.
Free to start. No credit card. Built for responsible disclosure.
Create your first hookBy using impactlab.sh you agree to our Terms of Authorized Use. For bug bounty and authorized pentesting only.