Skip to content

Extractors

An extractor is attached to a chain step and pulls a value out of the step’s response into a named variable. That variable is then available to all subsequent steps in the chain via {{variableName}}.

Extractor configuration panel: type dropdown, expression field, variable name

FieldDescription
TypeExtractor type (protocol-specific, see below)
ExpressionWhat to extract (meaning depends on type)
Variable nameName of the variable to store the result in

Extracts the HTTP response status code as a string.

FieldValue
Expression(not used)
Example output"200"

Evaluates a JSONPath expression against the response body.

FieldValue
ExpressionJSONPath string, e.g. $.data.token
Example output"eyJhbGci..."

Returns the entire response body as a string.

FieldValue
Expression(not used)

Returns the value of a specific response header. The lookup is case-insensitive; if the header appears multiple times the first occurrence is returned.

FieldValue
ExpressionHeader name, e.g. Content-Type or X-Request-Id
Example output"application/json"

Returns "true" if the SMTP exchange completed without any assertion failures, "false" otherwise.

FieldValue
Expression(not used)

Returns the server’s response lines for a specific command, joined as a string.

FieldValue
ExpressionThe command string to match (e.g. MAIL FROM:<[email protected]>)

Leave the expression blank to match the server greeting exchange.


Returns the transport outcome of one exchange, so a chain can branch on how it ended and not only on whether the probe as a whole worked. A reset, a timeout and a refused connection are three different findings, and a success flag cannot tell them apart.

FieldValue
ExpressionThe command string, matched the way SMTP_EXCHANGE_LINES matches it, or blank for the greeting
Example output"RST"

Values are OK, EOF, RST, TIMEOUT, MALFORMED_RESPONSE, PARTIAL, CONNECT_REFUSED, CONNECT_TIMEOUT and RESOLVE_FAILED. Blank selects the greeting rather than the last exchange, because the greeting slot is also where a failed connect is recorded.

Returns "true" if all IMAP commands completed successfully.

FieldValue
Expression(not used)

Returns the untagged server lines for a specific IMAP command.

FieldValue
ExpressionThe command string to match (e.g. SEARCH UNSEEN)

Leave the expression blank to match the server greeting.


Returns the transport outcome of one exchange, the IMAP counterpart of SMTP_OUTCOME.

FieldValue
ExpressionThe command string, matched the way IMAP_EXCHANGE_LINES matches it, or blank for the greeting
Example output"TIMEOUT"

Values are OK, EOF, RST, TIMEOUT, MALFORMED_RESPONSE, PARTIAL, CONNECT_REFUSED, CONNECT_TIMEOUT and RESOLVE_FAILED. Blank selects the greeting, which is where a failed connect is recorded.

Returns "true" if the LDAP operation completed without assertion failures.

FieldValue
Expression(not used)

Returns the result code for a specific LDAP operation as a string.

FieldValue
ExpressionA prefix of the operation string (e.g. BIND cn=admin)
Example output"0" (success)

Returns the transport outcome of one operation. A result code cannot stand in for this, because an operation that died at the socket never received one.

FieldValue
ExpressionAn operation prefix, matched the way LDAP_EXCHANGE_RESULT_CODE matches it, or blank for the first exchange
Example output"EOF"

Values are OK, EOF, RST, TIMEOUT, MALFORMED_RESPONSE, PARTIAL, CONNECT_REFUSED, CONNECT_TIMEOUT and RESOLVE_FAILED.

This is the extractor that makes a multi-operation LDAP sequence honest. The probe’s own success is computed from the connect and the assertions, so an operation that dies part way through a sequence still leaves a green probe. Naming that operation here is how a chain sees it.

Returns "true" if all DNS queries completed without any assertion failures, "false" otherwise.

FieldValue
Expression(not used)

Returns the value of the first answer record from a specific query.

FieldValue
ExpressionA prefix of the question string (e.g. A example.com)
Example output"93.184.216.34"

Leave the expression blank to use the first query’s answer. Useful for extracting a resolved IP and passing it to subsequent chain steps.


Returns the response header flags, in the form dig prints them.

FieldValue
ExpressionA prefix of the question string (e.g. A example.com), or blank for the first query
Example output"qr rd ra"

Returns "true" when the answer was authoritative, "false" otherwise. Selects the query the same way DNS_FLAGS does.

FieldValue
ExpressionA prefix of the question string, or blank for the first query
Example output"false"

Whether an answer came from the zone or from a resolver’s cache is a question the record value cannot answer, since both carry the same bytes. Assert on this when a chain cares about delegation.

Returns "true" if the Kerberos operation succeeded, "false" otherwise.

FieldValue
Expression(not used)

Returns the hashcat-ready hash produced by a roasting operation: $krb5asrep$23$… for AS-REP roasting (mode 18200) or $krb5tgs$23$… for Kerberoasting (mode 13100). Empty string for operations that produce no hash (e.g. credential validation).

FieldValue
Expression(not used)
Example output[email protected]:…

Pair with an ITERATE over a username wordlist to roast a whole user list and collect hashes into chain variables.

Returns the KDC error code (0 on success). Useful for username enumeration: 24 (KDC_ERR_PREAUTH_FAILED) means a valid account with a wrong password, while 6 (KDC_ERR_C_PRINCIPAL_UNKNOWN) means the account does not exist.

FieldValue
Expression(not used)
Example output"24"

Returns "true" if every enabled command in the SMB session completed successfully, "false" otherwise.

FieldValue
Expression(not used)

Returns an SMB NT status code (e.g. STATUS_SUCCESS, STATUS_ACCESS_DENIED). Useful for branching a chain on the exact result of a command (access checks, vulnerability probes).

FieldValue
ExpressionA substring of the command label (e.g. TREE_CONNECT); blank = last exchange’s status
Example output"STATUS_ACCESS_DENIED"

Returns the share names from a LIST_SHARES command, newline-separated. Feed it into an ITERATE step (variable-reference source, whitespace-split) to walk every share.

FieldValue
Expression(not used)
Example output"public\nprivate\nIPC$"

Returns the content read by a FILE_READ command, so a file read over SMB can feed a later chain step. UTF-8 text when decodable, otherwise a base64 fallback for binary files.

FieldValue
ExpressionA substring of the file path (e.g. secret.txt); blank = first FILE_READ result
Example output"hunter2"

Returns the decoded MSRPC result lines from commands such as SAMR_ENUM_USERS, SRVSVC_NETSESSIONENUM or WKSSVC_NETWKSTAUSERENUM, joined with newlines. Reads the most recent exchange that produced any, which makes it feed an ITERATE step directly.

FieldValue
Expression(optional) A substring filter applied to each line, case-insensitive
Example output"jdoe\nasmith\nsvc_iis"

Returns the entries from DIR_LIST and DIR_LIST_RECURSIVE exchanges, one per line, as the path and the size separated by a tab. When the command carried patterns, the entries already hold only the matches.

FieldValue
Expression(not used)

Returns "true" when any NEGOTIATE exchange reported that the server requires SMB signing, "false" otherwise.

FieldValue
Expression(not used)

Returns "true" when any SESSION_SETUP exchange came back flagged as a guest session.

FieldValue
Expression(not used)

A server that quietly downgrades a failed logon to guest answers successfully, so a chain asserting that authentication worked needs this to tell the two apart.

Returns the domain SID reported by LSARPC_QUERY_INFO_POLICY.

FieldValue
Expression(not used)
Example output"S-1-5-21-1004336348-1177238915-682003330"

Returns "true" if the connection was established and the statement was accepted by the server, "false" otherwise.

FieldValue
Expression(not used)

Returns the number of rows a query returned.

FieldValue
Expression(not used)
Example output"3"

Returns the number of rows affected by an update/DDL statement (-1 for a query).

FieldValue
Expression(not used)
Example output"1"

Returns a single cell from the result set, the primary chaining primitive. Column names match case-insensitively; a missing cell or SQL NULL returns an empty string.

FieldValue
Expressioncolumn (first row), row.column, or row.colIndex, for example email, 0.email, 2.1
Example output"[email protected]"

Returns the vendor error code from a rejected statement (0 on success). Useful for branching on the exact failure.

FieldValue
Expression(not used)
Example output"1146"

Returns the whole result set as a JSON array (each row an object of column → value).

FieldValue
Expression(not used)
Example output"[{\"id\":\"1\",\"username\":\"jdoe\"}]"

Returns "true" if the operation was accepted by the server, "false" otherwise.

FieldValue
Expression(not used)
Example output"true"

Returns the number of documents returned (Find/Aggregate) or matched (Count).

FieldValue
Expression(not used)
Example output"3"

Reads a field out of the returned documents. Not limited to the first document: a selector reaches any document, and [*] reaches every one.

FieldValue
Expressionfield (first doc), [n].field (doc n), [*].field (all docs, newline-joined), nested via dots (address.city)
Example output"alice"

Returns the MongoDB error code from a rejected operation (0 on success).

FieldValue
Expression(not used)
Example output"26"

Returns the whole result as a JSON array of the returned documents.

FieldValue
Expression(not used)
Example output"[{\"_id\":1,\"name\":\"alice\"}]"

Returns "true" if the statement was accepted by the server, "false" otherwise.

FieldValue
Expression(not used)
Example output"true"

Returns the number of rows returned by a query.

FieldValue
Expression(not used)
Example output"3"

Returns the number of rows affected by an update/DDL statement (-1 for a query).

FieldValue
Expression(not used)
Example output"1"

Reads a single cell out of the result set, the primary chaining primitive.

FieldValue
Expressioncolumn (first row), row.column (row n), or row.colIndex (e.g. email, 0.email, 2.1)
Example output"[email protected]"

Returns the SQLSTATE of a rejected statement (PostgreSQL’s error identity, e.g. 42P01 for an undefined table). Empty on success.

FieldValue
Expression(not used)
Example output"42P01"

Returns the whole result set as a JSON array of row objects.

FieldValue
Expression(not used)
Example output"[{\"id\":1,\"username\":\"alice\"}]"

Returns "true" when the transport was fine and every exchange met its expectation, "false" otherwise.

FieldValue
Expression(not used)

Returns the reply text of one exchange.

FieldValue
ExpressionA command, for example GET or GET user:1, or blank for the last exchange
Example output"hello from virtuprobe"

Reads the lossless rendering rather than the printable one, so a value carrying a line break can still be matched by a pattern carrying one.

Returns the RESP kind of a reply: SIMPLE_STRING, ERROR, INTEGER, BULK_STRING, ARRAY, NULL and so on.

FieldValue
ExpressionA command, or blank for the last exchange
Example output"BULK_STRING"

Worth asserting on its own, because a key that is absent answers NULL while a key holding an empty string answers BULK_STRING, and the reply text is empty either way.

Returns an integer reply as text: DBSIZE, TTL, EXISTS, the count from a DEL.

FieldValue
ExpressionA command, or blank for the last exchange
Example output"9"

Blank when the exchange answered with something that is not an integer, rather than zero. Zero is a real Redis answer, so returning it for “not an integer” would be a wrong answer rather than a missing one.

Returns the elements of an array reply, one per line, which is the shape an ITERATE step consumes.

FieldValue
ExpressionA command, or blank for the last exchange
Example output"first\nsecond\nthird"

A SCAN reply is a two element array of a cursor and the keys, so the keys are unwrapped. Without that, every iteration over a key search would start with the cursor and iterate it as though it were a key.

Returns one field out of an INFO reply.

FieldValue
ExpressionThe field name, for example redis_version or connected_clients. Required
Example output"7.2.4"

INFO answers a bulk string of name:value lines grouped under section headers, so a field lookup is the only practical way to assert on one number out of a hundred.

Returns the server error message of an exchange, blank when it did not answer with an error.

FieldValue
ExpressionA command, or blank for the last exchange
Example output"NOAUTH Authentication required."

Returns "true" when the batch ran and the server did not report an error, "false" otherwise.

FieldValue
Expression(not used)

Returns one column value from a result set.

FieldValue
ExpressionA column name, optionally with a row index, for example total
Example output"42"

Returns how many rows came back. Under the row cap this is the number you received, not the number the table holds, so pair it with MSSQL_TRUNCATED when the difference matters.

Returns how many result sets the batch produced. A procedure that selects twice returns "2".

Returns the rows an INSERT, UPDATE or DELETE touched.

Returns one OUT parameter of a procedure call, by name.

FieldValue
ExpressionThe parameter name

Returns what the server printed, from PRINT or from RAISERROR at severity 10 or below.

An ordinary query leaves this empty, which is correct and is also what an extractor that never ran returns, so do not use an empty result on its own as evidence that a step behaved.

Returns "true" when the row cap was reached. This is the extractor a chain needs in order to require that nothing was cut off, because a row count alone cannot tell the data apart from our limit.

Returns the message number, for example 208 for an invalid object name. That is the number every Microsoft reference is indexed by.

Returns the SQLSTATE. Coarser than the message number, and the one to use in a chain that has to run against more than one database engine.

Returns a value out of a JSON column.

Returns "true" when the transport was fine and every command met its expectation, "false" otherwise.

FieldValue
Expression(not used)

Returns a reply code, for example 226 for a completed transfer.

FieldValue
ExpressionA command, or blank for the last exchange

Returns the reply text, including every line of a multi-line reply such as the banner.

Returns the directory listing, one entry per line.

Newline separated so that an ITERATE step can walk it directly, which is what makes the chain follow what the server actually holds rather than a list of paths written in advance.

Returns the contents of a downloaded file, as text.

Returns the same bytes as hex, for a file that is not text.

Returns how many bytes were transferred.

Freestyle probes run a list of labeled exchanges down one connection, so most of these take an exchange label as the expression. Leaving it blank addresses the last exchange.

Returns "true" if the probe completed, "false" otherwise.

FieldValue
Expression(not used)
Example output"true"

Returns the bytes received in an exchange, as text.

FieldValue
ExpressionExchange label, or blank for the last exchange
Example output"220 mail.example.com ESMTP"

Returns the bytes received, as hex. This is the form a later exchange’s Hex payload accepts directly, so it is how you feed one reply back into the next request.

FieldValue
ExpressionExchange label, or blank for the last exchange
Example output"3220302e310d0a"

Returns bytes at a known position, as hex, for a binary reply with no text form. A slice that runs past the end is clamped rather than refused, because a short reply is itself a finding.

FieldValue
Expressionlabel|offset:length, e.g. header|4:2
Example output"00a3"

Applies a regular expression to the received text and returns the first capture group, or the whole match when the pattern has none. Use it to pull a session id, a version or a status word out of a banner.

FieldValue
Expressionlabel|regex, or a bare regex against the last exchange
Example output"1.4.2"

Returns how many bytes came back.

FieldValue
ExpressionExchange label, or blank for the last exchange
Example output"512"

Returns the transport outcome, so a chain can branch on how an exchange ended rather than only on whether it worked.

FieldValue
ExpressionExchange label, or blank for the last exchange
Example output"RST"

Stores a fixed value into a variable, which is how you pass a hardcoded value or a default through the chain context.

FieldValue
ExpressionThe literal string value to store

Applies a regular expression to the string representation of the step response and returns the first capture group (or the full match if no groups are defined).

FieldValue
ExpressionRegex pattern, e.g. token=([A-Za-z0-9]+)
Example output"abc123"

Most useful when the response is already a plain string, for example on an IMAP step whose exchange lines contain structured text, or in the scripting engine where you can pass any string response. For HTTP responses, combine with HTTP_BODY_RAW in a scripting context if you need regex over the body.