Guides

Practical, task-focused walkthroughs for running Dapper against real applications. The reference section documents every flag and field in isolation; these guides put them together end to end — choosing a target and pointing Dapper at your source, logging into authenticated apps (including SSO and 2FA), watching a run as it executes, reading the evidence-backed report it produces, and wiring the whole thing into CI/CD so a pentest happens on every deploy.

Each page is self-contained and starts from a working command you can copy. If you’re new, read Running a pentest first — it covers the lifecycle the other guides drill into. If you’re integrating Dapper into a pipeline, jump straight to CI/CD integration.

Dapper is a defensive security tool. Only run it against systems you own or have explicit written permission to test, and prefer a staging environment with test accounts — runs execute real exploits and can create, modify, or delete data. See Disclaimers.


Table of contents