Item logo image for Cobalt Scoping Assistant

Cobalt Scoping Assistant

ExtensionWorkflow & Planning15 users
Item media 1 (screenshot) for Cobalt Scoping Assistant

Overview

A lightweight tool to record web application usage for penetration test scoping

The Cobalt Scoping Assistant helps Cobalt customers quickly scope web application penetration tests by recording a live browsing session and automatically extracting the information needed to define test coverage. How it works: Start a recording, browse the target application as you normally would, then stop and export. The extension captures everything in the background without interrupting your workflow — and recording continues seamlessly across new tabs. What gets captured: - Unique dynamic pages visited (pages that issue mutating HTTP requests (POST, PUT, PATCH, DELETE)). - API endpoints and routes (detected from network requests). - All internal links found on the pages the user visits. - Technology stack fingerprints inferred from HTTP headers, cookies, and URL patterns (e.g. Rails, Django, WordPress, GraphQL, PHP, and many more). Domain filtering: Focus your recording on specific domains so third-party resources, CDNs, and analytics noise are excluded from your export. Built-in presets automatically filter out common static asset providers (Google APIs, Cloudflare, jsDelivr, etc.). Privacy-first: All data is processed and stored locally in your browser. Nothing is sent to any external server. The exported JSON file must be manually provided to Cobalt by you. Export format: Results are exported as a structured JSON file containing visited dynamic pages, discovered API routes, and inferred technologies — ready to feed directly into your scoping workflow.

Details

  • Version
    1.0.0
  • Updated
    April 25, 2026
  • Offered by
    Cobalt Scanner
  • Size
    148KiB
  • Languages
    English
  • Developer
    Cobalt Labs Inc
    575 Market St San Francisco, CA 94105-2854 US
    Email
    scanner@cobalt.io
    Phone
    +1 847-780-6531
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
  • D-U-N-S
    080522872

Privacy

Manage extensions and learn how they're being used in your organization

Cobalt Scoping Assistant has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Cobalt Scoping Assistant handles the following:

Web history
User activity
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps