Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

CatEyes

CatSuite CatEyes: how to use and configure page technology detection, the confidence level per detection and the local-database CVE signals to review.

15 min read

CatEyes is CatSuite's fingerprinting module (technology fingerprinting): with one tap it reads the page open in the Browser and identifies frameworks, libraries, servers and services from clues in the HTML, the headers, the loaded resources and runtime objects. Each technology appears with a confidence level and a score, and whenever CatEyes finds the version, it cross-checks that version against a local vulnerability database to highlight CVE signals you should review. This page explains every concept, every detection layer, every button and how to run and interpret CatEyes step by step.

What CatEyes is and what it is for #

CatEyes performs passive reconnaissance of a site's technology stack. Instead of guessing what runs behind a page, it watches concrete evidence — a Server header, a telltale cookie, a CSS class, a JavaScript global object, a /_next/static/ bundle — and adds that evidence up to decide, honestly, how sure it is of each detection.

It is a beginner-level module: you do not have to configure anything. Open the site, tap VERIFICAR (verify) and read the layered result. The careful work is in the reading: understanding why one technology landed as DETECTADO (detected) and another as POSSÍVEL (possible), and treating CVE signals as leads, not verdicts.

Core concepts #

Before reading a report, it helps to understand the terms that appear on the CatEyes screen.

  • Multi-layer fingerprint. The module's core strategy: instead of trusting a single clue, CatEyes gathers signals from several different layers and only commits to a detection when the sum is convincing.
  • Layer. Each source of evidence has a layer: SUPERFÍCIE (surface: headers and cookies), DOM (meta, HTML and ids), RUNTIME (JavaScript global objects and selectors), ASSETS (scripts, CSS and resources), PROBES (light checks of known routes) and PROTOCOLO (network protocol and status).
  • Signal / evidence. A single clue found in a layer, with a description and a number of points. Example: "Server header declared Nginx."
  • Score. The sum of the points from all of a technology's evidence. The higher it is, the stronger the detection.
  • Confidence level. The label derived from the score and the number of layers: DETECTADO (detected), PROVÁVEL (probable) or POSSÍVEL (possible).
  • Technology and category. What was recognized (React, WordPress, Nginx...) and which group it falls into (Frontend, CMS, Backend, Infra, Analytics, Editor, Content, Protocol, Security).
  • Version. When CatEyes can extract a technology's version (from a header, a runtime object, a meta tag or an asset URL), it appears on the card and enables the risk cross-check.
  • Light probe. A controlled request to a known route on the same host (for example /wp-login.php, or a nonexistent route to read the error page), used to reinforce the detection of a CMS, backend and server.
  • Local risk. The cross-check of the technologies that have a version against the local vulnerability database bundled into CatSuite. This is where the CVE signals come from.
  • CVE signal. A record from the local database that matched a technology and its version. It is a lead to review, not proof that the target is vulnerable.

The CatEyes screen: how to open it, panels and sections #

CatEyes lives inside the Browser and always analyzes the page open at that moment. That is why it only works when a site is loaded; with no page, the panel shows "Abra um site primeiro" (open a site first).

How to open CatEyes #

There are three paths, all leading to the same panel:

  • The eye badge in the Browser bar. The eye icon next to the address opens CatEyes and already hints at the risk through its color (see the table below).
  • The Browser options menu. The CatEyes item opens the panel; the item's subtitle summarizes the last result.
  • The Tools tab. In the Browser's tools panel, the CAT EYES tab (subtitle "Análise em camadas", layered analysis) sits next to CONSOLE JS, ARMAZENAMENTO (storage), MONITOR DE REDE (network monitor) and MODIFICADOR DOM (DOM modifier).

The summary card and the chips #

At the top of the panel, a card shows the analyzed URL and a row of chips with the overview of the run:

ChipWhat it shows
FORTES (strong)How many technologies reached the DETECTADO level.
POSSÍVEIS (possible)How many stayed at PROVÁVEL or POSSÍVEL (below detected).
PROBES OKHow many light probes answered without error.
VERSÕES (versions)How many technologies had a version identified.
RISCO (risk)Local-risk summary: AGUARDANDO (waiting), SEM VERSÃO (no version), the top severity with a count, or VERDE (green).
PROTOCOLO (protocol)The navigation nextHopProtocol in uppercase (for example H2, H3), or N/A.

The CatEyes badge in the bar and its colors #

The eye badge in the Browser bar changes color according to the last result, so you can feel the risk without opening the panel:

StateColorMeaning
No analysisNeutral/darkNo analysis has been run yet.
No versionBlueThere were detections, but no confident version, so the local database was not queried.
Has flawsOrange to redThe local database found CVE signals; the color follows the top severity.
CleanGreenThe local database was queried and returned no known flaws.

The analysis sections #

After VERIFICAR, the panel organizes itself into sections, top to bottom:

  • Camadas (layers) — horizontal cards, one per layer, with the signal count and how many technologies touched that layer.
  • Tecnologias (technologies) — the strong results first, each with score, version, aliases and evidence by layer.
  • Risco Local (local risk) — the cross-check of versioned technologies against the local database; this is where the CVE signals appear.
  • Probes Leves (light probes) — the result of each known-route check.
  • Avisos (warnings) — limitations and notes from the run (only shown when there is something to say).

The six detection layers #

The layers are the heart of CatEyes. Each detection adds up evidence from one or more of them, and the Camadas panel shows how many signals and technologies each one gathered.

LayerTitle in the appWhat it observes
SUPERFÍCIECabeçalhos e CookiesResponse headers (Server, X-Powered-By, CF-RAY...), telltale cookies and CSP domains.
DOMDOM, Meta e HTMLMeta tags (including generator and Open Graph), ids, comments and marks in the HTML.
RUNTIMERuntime JavaScriptGlobal objects (window.jQuery, window.Vue, __NEXT_DATA__...) and DOM selectors.
ASSETSAssets e PathsLoaded scripts, stylesheets and resources, with version extraction from the URL.
PROBESProbes LevesReinforcement from known routes and error-page signatures.
PROTOCOLOProtocolo e RedeThe navigation transport protocol and the response status.

Confidence levels and scoring #

CatEyes does not show "yes or no": it shows how much it trusts each detection. The score is the sum of the evidence (repeated signals in the same layer do not count twice), and the level comes from fixed thresholds that also take the number of layers into account.

LevelColorHow it is reached
DETECTADOGreen70 points or more; or 52 points or more with at least 2 distinct layers.
PROVÁVELBlue42 points or more.
POSSÍVELAmber24 points or more.
(hidden)—Below 24 points the technology is not shown.

DETECTADO detections count in the FORTES chip; the others (PROVÁVEL and POSSÍVEL) count in POSSÍVEIS. Within the list, results are ordered first by level and then by score, so whatever is at the top is the most reliable. If nothing clears the 24-point cutoff, the Tecnologias section shows "Sem detecções acima do corte" (no detections above the cutoff).

Technologies CatEyes recognizes #

CatEyes has dedicated detectors, grouped by category. Each one looks for that technology's specific clues in the layers where they usually appear.

CategoryRecognized technologies
InfraCloudflare, Cloudflare Insights, Varnish, F5 BIG-IP
BackendPHP, Apache, Nginx, IIS, ASP.NET, Express.js
CMSWordPress, Elementor, Drupal, Joomla
FrontendReact, Next.js, Vue.js, Nuxt.js, Angular, jQuery, Bootstrap, Tailwind CSS, Lottie
AnalyticsFacebook Pixel, Google Tag Manager, Google Analytics, Stripe
EditorMonaco Editor, Quill, KaTeX
ContentOpen Graph
ProtocolHTTP/3

Each technology card carries the name (with the version when present), a chip with the level and points, the CAT chip with the category, the VERSÃO chip when the version was extracted, the RISCO chip when there are CVE signals, chips with the layers touched and MATCH chips with the aliases used in the search. Just below sit the pieces of evidence, one by one, in the format [LAYER +points] description.

CVE signals and local risk #

The Risco Local section is where a detection becomes a security lead. It only runs when at least one technology exposed a confident version; with no version there is nothing to compare, and the panel shows "Base local ainda não consultada" (local database not queried yet).

When there is a version, CatEyes queries a local vulnerability database shipped with the app (a compressed database, read-only, that never leaves the device). It searches by each technology's aliases and, for every record found, compares the detected version with the fixed version (fixed in):

  • If the detected version is earlier than the fixed version, the signal is marked as version confirmed (the record is compatible with what is on the page).
  • If the detected version is equal to or later than the fixed one, the record is discarded — likely already patched.
  • If the record does not state a fixed version, the signal appears for manual review, with no version confirmation.

Each CVE signal carries the severity and the identifier, the package, the detected version, a summary and the fix line. The severities are normalized into four levels:

SeverityReading
CRÍTICA (critical)Top review priority.
ALTA (high)Priority review.
MÉDIA (medium)Review depending on context.
BAIXA (low)Lower urgency, but worth recording.

When the database is queried and nothing matches, the section shows "Sem falhas conhecidas" (no known flaws) and the risk chip turns VERDE (green).

Options and how to configure #

CatEyes has no settings screen: the analysis runs with one tap and the parameters below are fixed. "Configuring" here means understanding those limits and deciding when and how to run so you get the most out of each page.

OptionValuesDefaultWhat it does
Analysis targetPage open in the BrowserCurrent pageDefines what will be read; CatEyes never leaves the open site.
Verification momentManualOn demand (VERIFICAR)The collection only runs when you tap the button.
Probe scopeSame originFixedThe route checks stay restricted to the current host.
Collection timeout24 seconds24 sAborts the collection if the script takes too long on the page.
Display cutoff24 pointsFixedHides technologies with a score below the cutoff.
Local-risk queryAutomatic when a version existsOnCross-checks the detected versions against the local database.
ExportTXTOn demand (BAIXAR TXT)Generates the full report of the last analysis.

How to adjust in practice: let the page load fully before verifying, so scripts and runtime objects are already available; re-verify after interacting with the page (login, internal navigation) to capture cookies and routes that only appear when authenticated; and run again if the first pass detected nothing — some signals depend on resources that were still loading.

Buttons and actions #

Button / actionWhat it does
VERIFICARRuns the collection on the current page and scores technologies, layers and local risk. Shows "VERIFICANDO..." (verifying) while it works.
BAIXAR TXTExports the last analysis as a text report (cateyes-<host>.txt). Stays disabled until an analysis exists.
Eye badge (bar)Opens CatEyes and signals the risk through color; pulses at critical or high severity.
CatEyes item (menu)Opens the panel from the Browser options menu.
CAT EYES tab (tools)Opens CatEyes inside the Browser's tools panel.

When a verification finishes, CatEyes confirms with the message "CatEyes atualizou as assinaturas da página." (CatEyes updated the page signatures). If the collection fails, "Falha ao verificar a página: ..." (failed to verify the page) appears with the reason. On export, the confirmation is "Relatório TXT salvo." (TXT report saved), or with the destination when available.

Step by step #

Run CatEyes on a page #

  1. In the Browser, open the authorized target and wait for the page to load fully.
  2. Tap the eye badge in the bar, or open the CAT EYES tab in the tools.
  3. Tap VERIFICAR.
  4. Wait for the collection (the button shows "VERIFICANDO...").
  5. Read the summary card (FORTES, POSSÍVEIS, PROBES OK, VERSÕES, RISCO, PROTOCOLO) and then the sections below.

Interpret the detections and the confidence #

  1. Start with the Tecnologias section: the DETECTADO (green) items at the top are the most reliable.
  2. On each card, check the score and the evidence by layer — they explain why that technology was recognized.
  3. Use the Camadas panel to see where the confidence came from: several layers pointing at the same place is a strong signal.
  4. Treat PROVÁVEL and POSSÍVEL items as hypotheses; confirm with a new verification after the page has loaded everything.

Review CVE signals responsibly #

  1. Open the Risco Local section. If it shows "Base local ainda não consultada", it is because no confident version was detected.
  2. For each signal, note the technology, the detected version, the identifier and the fix line.
  3. Confirm the target's real version by another route before concluding anything — the signal is a lead.
  4. Weigh the context: a CVE may not apply to that server's specific configuration.

Export the TXT report #

  1. With an analysis on screen, tap BAIXAR TXT.
  2. CatEyes generates cateyes-<host>.txt with summary, technologies, local risk, layers, headers, cookies, probes and warnings.
  3. Keep the report alongside your authorized-test evidence.

Examples #

Header of the TXT report (summary section):

Report summaryText
CAT EYES
URL: https://target.com/
Origem: https://target.com
Titulo: Authorized target
Status: 200
Lang: en
Protocolo: h2
Banco local: consultado
Severidade maxima: ALTA
Tecnologias com versao: 3
Falhas conhecidas: 2

A detected technology, as it appears in the report:

Technology in the reportText
- WordPress 6.4 | DETECTADO | 123 pontos
  Categoria: CMS
  Aliases de busca: wordpress, wordpresscore
  Camadas: DOM, Probes
  * [DOM +68] Meta generator declarou WordPress.
  * [Probes +34] O endpoint /wp-json/ respondeu com status 200.

A CVE signal in the local-risk section:

CVE signalText
- CVE-0000-00000 | ALTA | jquery
  Resumo: Short description of the known flaw.
  Fixed in: 3.5.0
  Alias: jquery | Versao detectada: 3.4.1

The result of a light probe:

Light probeText
- WordPress login (HEAD /wp-login.php) -> 200
  URL final: https://target.com/wp-login.php

Common problems and frequently asked questions #

"Abra um site primeiro" (open a site first). — CatEyes needs a loaded page. Search the web or type a URL in the Browser before opening the module.

"Nada analisado ainda" (nothing analyzed yet). — You opened the panel but have not run the collection. Tap VERIFICAR.

"Sem detecções acima do corte" (no detections above the cutoff). — The page did not expose enough signals this round. Wait for loading to finish and verify again; very lean or protected pages may simply not reveal the stack.

"Base local ainda não consultada" (local database not queried yet). — No technology exposed a confident version, so there was nothing to cross-check. This is common and expected on many sites.

The RISCO chip shows SEM VERSÃO (no version). — There were detections, but no version. The CVE cross-check depends on an identified version.

"Falha ao verificar a página: ..." (failed to verify the page). — The collection did not complete (the 24 s timeout, a page block or a script error). Reload the page and try again.

The numbers change between verifications. — That is normal: resources, cookies and runtime objects vary with what has already loaded. Verify with the page fully ready.

CatEyes flags a CVE — is the target vulnerable? — Not necessarily. The signal is a lead based on the detected version and the local database. Confirm the real version and the context. See also Error reference.

Good practices and responsible use #

  • Analyze authorized targets only; see Security.
  • Let the page load fully and, when it makes sense, re-verify after login or internal navigation.
  • Read the score and the evidence, not just the technology name — they show how much to trust.
  • Treat every CVE signal as a lead: confirm the version and context before concluding.
  • Export the TXT report to record the state of the analysis alongside your evidence.

Next step #