# CatEyes

> CatSuite CatEyes: how to use and configure page technology detection, the confidence level per detection and the local-database CVE signals to review.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/modules/cateyes
- Section: Modules
- Updated: 2026-10-06
- Other language (pt-BR): https://netcattest.com/catsuite/docs/modulos/cateyes

**CatEyes** is CatSuite's *fingerprinting* module (technology fingerprinting): with one tap it reads the page open in the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser) and identifies **frameworks, libraries, servers and services** from clues in the HTML, the headers, the loaded resources and *runtime* objects. Each technology appears with a **confidence level** and a **score**, and whenever CatEyes finds the **version**, it cross-checks that version against a **local vulnerability database** to highlight **CVE signals** you should review. This page explains every concept, every detection layer, every button and how to run and interpret CatEyes step by step.

## What CatEyes is and what it is for

CatEyes performs passive reconnaissance of a site's technology stack. Instead of guessing what runs behind a page, it watches concrete evidence — a `Server` header, a telltale cookie, a CSS class, a JavaScript global object, a `/_next/static/` bundle — and adds that evidence up to decide, honestly, how sure it is of each detection.

It is a **beginner-level** module: you do not have to configure anything. Open the site, tap **VERIFICAR** (verify) and read the layered result. The careful work is in the reading: understanding why one technology landed as **DETECTADO** (detected) and another as **POSSÍVEL** (possible), and treating CVE signals as leads, not verdicts.

> [!WARNING]
> CatEyes queries the open page itself and makes a few light route checks on the same host. Use it only against targets you are **authorized** to analyze. See the responsible-use rules in [Security](https://netcattest.com/catsuite/en/docs/security).

## Core concepts

Before reading a report, it helps to understand the terms that appear on the CatEyes screen.

- **Multi-layer fingerprint.** The module's core strategy: instead of trusting a single clue, CatEyes gathers signals from several different **layers** and only commits to a detection when the sum is convincing.
- **Layer.** Each source of evidence has a layer: **SUPERFÍCIE** (surface: headers and cookies), **DOM** (meta, HTML and ids), **RUNTIME** (JavaScript global objects and selectors), **ASSETS** (scripts, CSS and resources), **PROBES** (light checks of known routes) and **PROTOCOLO** (network protocol and status).
- **Signal / evidence.** A single clue found in a layer, with a description and a number of points. Example: "Server header declared Nginx."
- **Score.** The sum of the points from all of a technology's evidence. The higher it is, the stronger the detection.
- **Confidence level.** The label derived from the score and the number of layers: **DETECTADO** (detected), **PROVÁVEL** (probable) or **POSSÍVEL** (possible).
- **Technology and category.** What was recognized (React, WordPress, Nginx...) and which group it falls into (Frontend, CMS, Backend, Infra, Analytics, Editor, Content, Protocol, Security).
- **Version.** When CatEyes can extract a technology's version (from a header, a runtime object, a meta tag or an asset URL), it appears on the card and enables the risk cross-check.
- **Light probe.** A controlled request to a known route on the same host (for example `/wp-login.php`, or a nonexistent route to read the error page), used to reinforce the detection of a CMS, backend and server.
- **Local risk.** The cross-check of the technologies **that have a version** against the local vulnerability database bundled into CatSuite. This is where the CVE signals come from.
- **CVE signal.** A record from the local database that matched a technology and its version. It is a **lead to review**, not proof that the target is vulnerable.

## The CatEyes screen: how to open it, panels and sections

CatEyes lives inside the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser) and always analyzes the **page open at that moment**. That is why it only works when a site is loaded; with no page, the panel shows "Abra um site primeiro" (open a site first).

### How to open CatEyes

There are three paths, all leading to the same panel:

- **The eye badge in the Browser bar.** The eye icon next to the address opens CatEyes and already hints at the risk through its color (see the table below).
- **The Browser options menu.** The **CatEyes** item opens the panel; the item's subtitle summarizes the last result.
- **The Tools tab.** In the Browser's tools panel, the **CAT EYES** tab (subtitle "Análise em camadas", layered analysis) sits next to **CONSOLE JS**, **ARMAZENAMENTO** (storage), **MONITOR DE REDE** (network monitor) and **MODIFICADOR DOM** (DOM modifier).

### The summary card and the chips

At the top of the panel, a card shows the analyzed URL and a row of *chips* with the overview of the run:

| Chip | What it shows |
| --- | --- |
| **FORTES** (strong) | How many technologies reached the **DETECTADO** level. |
| **POSSÍVEIS** (possible) | How many stayed at **PROVÁVEL** or **POSSÍVEL** (below detected). |
| **PROBES OK** | How many light *probes* answered without error. |
| **VERSÕES** (versions) | How many technologies had a version identified. |
| **RISCO** (risk) | Local-risk summary: `AGUARDANDO` (waiting), `SEM VERSÃO` (no version), the top severity with a count, or `VERDE` (green). |
| **PROTOCOLO** (protocol) | The navigation `nextHopProtocol` in uppercase (for example `H2`, `H3`), or `N/A`. |

### The CatEyes badge in the bar and its colors

The eye badge in the Browser bar changes color according to the last result, so you can feel the risk without opening the panel:

| State | Color | Meaning |
| --- | --- | --- |
| No analysis | Neutral/dark | No analysis has been run yet. |
| No version | Blue | There were detections, but no confident version, so the local database was not queried. |
| Has flaws | Orange to red | The local database found CVE signals; the color follows the top severity. |
| Clean | Green | The local database was queried and returned no known flaws. |

> [!NOTE]
> When the top severity is **CRÍTICA** (critical) or **ALTA** (high), the badge pulses to draw attention. This is still a signal to review, not a closed diagnosis.

### The analysis sections

After **VERIFICAR**, the panel organizes itself into sections, top to bottom:

- **Camadas** (layers) — horizontal cards, one per layer, with the signal count and how many technologies touched that layer.
- **Tecnologias** (technologies) — the strong results first, each with score, version, aliases and evidence by layer.
- **Risco Local** (local risk) — the cross-check of versioned technologies against the local database; this is where the CVE signals appear.
- **Probes Leves** (light probes) — the result of each known-route check.
- **Avisos** (warnings) — limitations and notes from the run (only shown when there is something to say).

## The six detection layers

The layers are the heart of CatEyes. Each detection adds up evidence from one or more of them, and the **Camadas** panel shows how many signals and technologies each one gathered.

| Layer | Title in the app | What it observes |
| --- | --- | --- |
| **SUPERFÍCIE** | Cabeçalhos e Cookies | Response headers (`Server`, `X-Powered-By`, `CF-RAY`...), telltale cookies and CSP domains. |
| **DOM** | DOM, Meta e HTML | Meta tags (including `generator` and Open Graph), ids, comments and marks in the HTML. |
| **RUNTIME** | Runtime JavaScript | Global objects (`window.jQuery`, `window.Vue`, `__NEXT_DATA__`...) and DOM selectors. |
| **ASSETS** | Assets e Paths | Loaded scripts, stylesheets and resources, with version extraction from the URL. |
| **PROBES** | Probes Leves | Reinforcement from known routes and error-page signatures. |
| **PROTOCOLO** | Protocolo e Rede | The navigation transport protocol and the response status. |

> [!TIP]
> The more layers point at the same technology, the higher the confidence. A detection that shows up in **SUPERFÍCIE**, **RUNTIME** and **ASSETS** at once is far more solid than one that came from a single asset.

## Confidence levels and scoring

CatEyes does not show "yes or no": it shows **how much** it trusts each detection. The score is the sum of the evidence (repeated signals in the same layer do not count twice), and the level comes from fixed thresholds that also take the number of layers into account.

| Level | Color | How it is reached |
| --- | --- | --- |
| **DETECTADO** | Green | 70 points or more; or 52 points or more with at least 2 distinct layers. |
| **PROVÁVEL** | Blue | 42 points or more. |
| **POSSÍVEL** | Amber | 24 points or more. |
| (hidden) | — | Below 24 points the technology is not shown. |

**DETECTADO** detections count in the **FORTES** chip; the others (PROVÁVEL and POSSÍVEL) count in **POSSÍVEIS**. Within the list, results are ordered first by level and then by score, so whatever is at the top is the most reliable. If nothing clears the 24-point cutoff, the **Tecnologias** section shows "Sem detecções acima do corte" (no detections above the cutoff).

## Technologies CatEyes recognizes

CatEyes has dedicated detectors, grouped by category. Each one looks for that technology's specific clues in the layers where they usually appear.

| Category | Recognized technologies |
| --- | --- |
| **Infra** | Cloudflare, Cloudflare Insights, Varnish, F5 BIG-IP |
| **Backend** | PHP, Apache, Nginx, IIS, ASP.NET, Express.js |
| **CMS** | WordPress, Elementor, Drupal, Joomla |
| **Frontend** | React, Next.js, Vue.js, Nuxt.js, Angular, jQuery, Bootstrap, Tailwind CSS, Lottie |
| **Analytics** | Facebook Pixel, Google Tag Manager, Google Analytics, Stripe |
| **Editor** | Monaco Editor, Quill, KaTeX |
| **Content** | Open Graph |
| **Protocol** | HTTP/3 |

Each technology card carries the name (with the version when present), a chip with the level and points, the **CAT** chip with the category, the **VERSÃO** chip when the version was extracted, the **RISCO** chip when there are CVE signals, chips with the layers touched and **MATCH** chips with the aliases used in the search. Just below sit the pieces of evidence, one by one, in the format `[LAYER +points] description`.

## CVE signals and local risk

The **Risco Local** section is where a detection becomes a security lead. It only runs when at least one technology exposed a **confident version**; with no version there is nothing to compare, and the panel shows "Base local ainda não consultada" (local database not queried yet).

When there is a version, CatEyes queries a **local vulnerability database** shipped with the app (a compressed database, read-only, that never leaves the device). It searches by each technology's aliases and, for every record found, compares the **detected version** with the **fixed version** (`fixed in`):

- If the detected version is **earlier** than the fixed version, the signal is marked as **version confirmed** (the record is compatible with what is on the page).
- If the detected version is **equal to or later** than the fixed one, the record is **discarded** — likely already patched.
- If the record **does not state** a fixed version, the signal appears for manual review, with no version confirmation.

Each CVE signal carries the severity and the identifier, the package, the detected version, a summary and the fix line. The severities are normalized into four levels:

| Severity | Reading |
| --- | --- |
| **CRÍTICA** (critical) | Top review priority. |
| **ALTA** (high) | Priority review. |
| **MÉDIA** (medium) | Review depending on context. |
| **BAIXA** (low) | Lower urgency, but worth recording. |

When the database is queried and nothing matches, the section shows "Sem falhas conhecidas" (no known flaws) and the risk chip turns **VERDE** (green).

> [!IMPORTANT]
> A CVE signal is a **lead to review**, not proof of a vulnerability. Version detection can be wrong, and a CVE may not apply to the target's specific configuration. Always confirm the real version and the context before any conclusion.

## Options and how to configure

CatEyes has no settings screen: the analysis runs with one tap and the parameters below are **fixed**. "Configuring" here means understanding those limits and deciding **when and how** to run so you get the most out of each page.

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| **Analysis target** | Page open in the Browser | Current page | Defines what will be read; CatEyes never leaves the open site. |
| **Verification moment** | Manual | On demand (**VERIFICAR**) | The collection only runs when you tap the button. |
| **Probe scope** | Same origin | Fixed | The route checks stay restricted to the current host. |
| **Collection timeout** | 24 seconds | 24 s | Aborts the collection if the script takes too long on the page. |
| **Display cutoff** | 24 points | Fixed | Hides technologies with a score below the cutoff. |
| **Local-risk query** | Automatic when a version exists | On | Cross-checks the detected versions against the local database. |
| **Export** | TXT | On demand (**BAIXAR TXT**) | Generates the full report of the last analysis. |

How to adjust in practice: let the **page load fully** before verifying, so scripts and runtime objects are already available; **re-verify** after interacting with the page (login, internal navigation) to capture cookies and routes that only appear when authenticated; and run again if the first pass detected nothing — some signals depend on resources that were still loading.

## Buttons and actions

| Button / action | What it does |
| --- | --- |
| **VERIFICAR** | Runs the collection on the current page and scores technologies, layers and local risk. Shows "VERIFICANDO..." (verifying) while it works. |
| **BAIXAR TXT** | Exports the last analysis as a text report (`cateyes-<host>.txt`). Stays disabled until an analysis exists. |
| **Eye badge (bar)** | Opens CatEyes and signals the risk through color; pulses at critical or high severity. |
| **CatEyes item (menu)** | Opens the panel from the Browser options menu. |
| **CAT EYES tab (tools)** | Opens CatEyes inside the Browser's tools panel. |

When a verification finishes, CatEyes confirms with the message "CatEyes atualizou as assinaturas da página." (CatEyes updated the page signatures). If the collection fails, "Falha ao verificar a página: ..." (failed to verify the page) appears with the reason. On export, the confirmation is "Relatório TXT salvo." (TXT report saved), or with the destination when available.

## Step by step

### Run CatEyes on a page

1. In the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser), open the **authorized** target and wait for the page to load fully.
2. Tap the **eye badge** in the bar, or open the **CAT EYES** tab in the tools.
3. Tap **VERIFICAR**.
4. Wait for the collection (the button shows "VERIFICANDO...").
5. Read the summary card (**FORTES**, **POSSÍVEIS**, **PROBES OK**, **VERSÕES**, **RISCO**, **PROTOCOLO**) and then the sections below.

### Interpret the detections and the confidence

1. Start with the **Tecnologias** section: the **DETECTADO** (green) items at the top are the most reliable.
2. On each card, check the score and the **evidence by layer** — they explain why that technology was recognized.
3. Use the **Camadas** panel to see where the confidence came from: several layers pointing at the same place is a strong signal.
4. Treat **PROVÁVEL** and **POSSÍVEL** items as hypotheses; confirm with a new verification after the page has loaded everything.

### Review CVE signals responsibly

1. Open the **Risco Local** section. If it shows "Base local ainda não consultada", it is because no confident version was detected.
2. For each signal, note the technology, the **detected version**, the identifier and the **fix** line.
3. Confirm the target's real version by another route before concluding anything — the signal is a lead.
4. Weigh the context: a CVE may not apply to that server's specific configuration.

### Export the TXT report

1. With an analysis on screen, tap **BAIXAR TXT**.
2. CatEyes generates `cateyes-<host>.txt` with summary, technologies, local risk, layers, headers, cookies, probes and warnings.
3. Keep the report alongside your authorized-test evidence.

## Examples

Header of the TXT report (summary section):

```text
CAT EYES
URL: https://target.com/
Origem: https://target.com
Titulo: Authorized target
Status: 200
Lang: en
Protocolo: h2
Banco local: consultado
Severidade maxima: ALTA
Tecnologias com versao: 3
Falhas conhecidas: 2
```

A detected technology, as it appears in the report:

```text
- WordPress 6.4 | DETECTADO | 123 pontos
  Categoria: CMS
  Aliases de busca: wordpress, wordpresscore
  Camadas: DOM, Probes
  * [DOM +68] Meta generator declarou WordPress.
  * [Probes +34] O endpoint /wp-json/ respondeu com status 200.
```

A CVE signal in the local-risk section:

```text
- CVE-0000-00000 | ALTA | jquery
  Resumo: Short description of the known flaw.
  Fixed in: 3.5.0
  Alias: jquery | Versao detectada: 3.4.1
```

The result of a light probe:

```text
- WordPress login (HEAD /wp-login.php) -> 200
  URL final: https://target.com/wp-login.php
```

## Common problems and frequently asked questions

**"Abra um site primeiro" (open a site first).** — CatEyes needs a loaded page. Search the web or type a URL in the Browser before opening the module.

**"Nada analisado ainda" (nothing analyzed yet).** — You opened the panel but have not run the collection. Tap **VERIFICAR**.

**"Sem detecções acima do corte" (no detections above the cutoff).** — The page did not expose enough signals this round. Wait for loading to finish and verify again; very lean or protected pages may simply not reveal the stack.

**"Base local ainda não consultada" (local database not queried yet).** — No technology exposed a confident version, so there was nothing to cross-check. This is common and expected on many sites.

**The RISCO chip shows `SEM VERSÃO` (no version).** — There were detections, but no version. The CVE cross-check depends on an identified version.

**"Falha ao verificar a página: ..." (failed to verify the page).** — The collection did not complete (the 24 s timeout, a page block or a script error). Reload the page and try again.

**The numbers change between verifications.** — That is normal: resources, cookies and runtime objects vary with what has already loaded. Verify with the page fully ready.

**CatEyes flags a CVE — is the target vulnerable?** — Not necessarily. The signal is a lead based on the detected version and the local database. Confirm the real version and the context. See also [Error reference](https://netcattest.com/catsuite/en/docs/reference/errors).

## Good practices and responsible use

- Analyze **authorized targets only**; see [Security](https://netcattest.com/catsuite/en/docs/security).
- Let the page **load fully** and, when it makes sense, **re-verify** after login or internal navigation.
- Read the **score and the evidence**, not just the technology name — they show how much to trust.
- Treat every **CVE signal as a lead**: confirm the version and context before concluding.
- Export the **TXT report** to record the state of the analysis alongside your evidence.

## Next step

- [Browser](https://netcattest.com/catsuite/en/docs/modules/browser)
- [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer)
- [SSL/TLS](https://netcattest.com/catsuite/en/docs/modules/ssl-tls)
- [Interceptor](https://netcattest.com/catsuite/en/docs/modules/interceptor)
- [Modules overview](https://netcattest.com/catsuite/en/docs/modules)
