The Vex Language
Vex is a scripting language for security workflows. Call modules, work with their results, and report checks or findings from the same program.
input endpoint: url
response = http.get(endpoint, timeout=5s)
expect response.status == 200, "Endpoint did not return 200"
out(response.status) Use braces for blocks, name = value for bindings, and # for comments. Types are usually inferred; declare them on inputs and function parameters where needed.
- Syntax: bindings, calls, functions, and blocks.
- Types: values, collections, records, and typed inputs.
- Strings: interpolation, raw strings, and bytes.
- Pipes: pass results through a chain of calls.
- Control flow: branches, loops, and bounded concurrency.
- Inputs and credentials: run parameters and named secrets.
- Error handling: recover from an operation that fails.
- Expect and findings: record checks and report issues.
Use vex_help in your environment for each call’s parameters and return fields. Check a program before running it, and use only targets you are authorized to test.