Identify routes and endpoints using scripts written, combine and deduplicate Katana and FFUF outputs into one file (/tmp/all_endpoints.txt)
3
CSRF testing with XSRFProbe: for each endpoint run XSRFProbe (use -c if cookie is provided) with --random-agent --malicious --crawl. XSRFProbe attempts to detect CSRF vulnerabilities and, if successful, generates a PoC and an HTML report