The part most scanners skip.
Recon is the commodity. What actually finds the bugs, and what you pay for, is authenticated scanning and API authorization testing, confirmed before it is reported, on targets you can still reach behind a WAF.
API authorization testing (BOLA, BFLA, BOPLA)
Crossfyre tests API authorization the way it actually breaks: it replays every endpoint as every identity and diffs the responses to catch BOLA, BFLA, and BOPLA, confirmed before reporting. Self-serve, wired to distributed recon.
Learn more →Authenticated scanning (OAuth, OIDC, SSO)
Crossfyre scans behind the login. It supports static tokens, form logins, and OAuth2 / OIDC / SSO via a headless auth broker that logs in and returns only a resolved token, so your session-gated surface actually gets tested. Secrets stay encrypted.
Learn more →Self-hosted, zero-knowledge OAST
Crossfyre includes an out-of-band interaction server (OAST) you can self-host for confirming blind bugs like SSRF and blind RCE. Interactions are sealed to a per-scan key, so even the server operator only holds ciphertext. Managed pool or bring your own.
Learn more →Reaching authorized targets behind a WAF or CDN
A scan that gets blocked returns nothing. Crossfyre discovers a target’s real origin behind a CDN and, on Reaper, presents a genuine browser handshake, so an authorized scan reaches the in-scope app. Origin discovery is available on every plan; paid egress levers are opt-in.
Learn more →Mobile app testing without a rooted phone or a PC
Crossfyre’s Mobile Tracer captures an Android app’s traffic from the phone itself, no laptop and no root. For certificate-pinned apps it runs a server-assisted repackage that returns patched, installable splits, so full request and response bodies land in the platform. Android only.
Learn more →