The Vex Language

Vex is a scripting language for security workflows. Call modules, work with their results, and report checks or findings from the same program.

input endpoint: url

response = http.get(endpoint, timeout=5s)
expect response.status == 200, "Endpoint did not return 200"
out(response.status)

Use braces for blocks, name = value for bindings, and # for comments. Types are usually inferred; declare them on inputs and function parameters where needed.

Use vex_help in your environment for each call’s parameters and return fields. Check a program before running it, and use only targets you are authorized to test.

Improve team velocity with
better security and privacy.