Installation Guide

The information in this document applies to version 7.2 of Syhunt Hybrid.

Introduction

Syhunt Hybrid 7 is a 64-bit multi-platform application security scanner that runs on Windows, MacOS and Linux, such as Ubuntu Desktop/Server, Debian and Fedora with near zero effort. Syhunt Hybrid allows to perform web and mobile application security testing (DAST and SAST) and integrate with a variety of systems for continuous integration and scanning.

Comparison Between Syhunt Versions

 Hybrid for WindowsHybrid for Linux/MacOS
Web UI Differencesopenresty for both HTTPS/HTTPNGINX for HTTPS, openresty as back-end
Deep AJAX Crawler Uses Chromium engine Uses Firefox engine
Augmented Dynamic Analysis (DAST + OAST)
API Analysis (AAST + OAST)
Web Application Source Code Analysis (SAST)
Mobile Application Source Code Analysis (MAST)
Forensic Analysis (FAST) (only via CLI) (only via CLI)
AI-Powered Capabilities Patched Code Examples
AI Confidence Score
Patched Code Examples
AI Confidence Score
Advanced Authentication Options Recorder, Selenium Recorder, Selenium
Integrations Shell (PowerShell)
Issue Trackers (GitHub, GitLab, JIRA...)
CI/CD Tools (GitLab, GitHub, BitBucket & Jenkins)
Supported WAFs for Virtual Patching
Scan Azure DevOps / TFS project URLs (non-GIT)
Shell (Bash)
Issue Trackers (GitHub, GitLab, JIRA...)
CI/CD Tools (GitLab, GitHub, BitBucket & Jenkins)
Supported WAFs for Virtual Patching
Scan Azure DevOps / TFS project URLs (non-GIT)
Scan Scheduler
OSes/Distributions CompatibilityOfficially:
Windows 11
Windows 10
Windows Server 2016 to 2015
Officially:
MacOS Sequoia 15.4.1 or higher (on Apple Silicon)
Ubuntu Server/Desktop 18.10 and later
Debian 9 and later
Fedora 32 and later
Unofficially (Successfully Tested):
See the Linux distro list
macOS Monterey
AvailabilityAvailable Now (Native Win64 Binaries)Check Availability of Native Binaries for your distro
Available Now (Wine-Powered Installation)

Installing Syhunt on Windows

If you are a registered customer: Please follow the initial steps in our welcome guide to download, install and start using the full version of Syhunt Hybrid. If you are a community (non-registered) user, you can use Syhunt Community.

  1. (Optional) Download and install GIT for Windows (if you have not done so yet) if you plan to scan GIT repositories with Syhunt
  2. Download the Syhunt Hybrid setup (syhunt-hybrid-7.2.0.31.exe)
  3. After downloading the exe file, double-click its icon to launch it.
  4. You should read carefully the EULA presented to you on installation before accepting it.
  5. It's an easy next-next-finish installation process. When you click Finish, Syhunt will be launched and is ready for use - you should immediately see the Launcher screen.
  6. Finally, if you need, enable the Syhunt web user interface.

What's next? Read our quick start and integration guides.

Installing Syhunt on macOS

Syhunt Hybrid 7.2 is compatible with macOS Sequoia and earlier versions of macOS. This is the Carbon version, which uses Wine for installation and runs on both Apple Silicon (via Rosetta) and Intel-based Macs. Alternatively, if you prefer to use virtualization, Syhunt Hybrid 7.1.6 can run on ARM64 Linux, such as Ubuntu, Debian or Kali Linux, within macOS using Parallels Desktop with a Pro license - the Standard license is not compatible.

Please follow the installation guide for macOS.

Installing Syhunt on Linux

Syhunt Hybrid ˣ⁶⁴ for Linux (Full Version)

If you are a registered customer: Please follow the initial steps in our welcome guide to download, install and start using full version Syhunt Hybrid. If you are a community (non-registered) user, you can use Syhunt Community.

Syhunt Hybrid for Linux is now available for download. This is the Carbon version (Wine-Powered installation of Syhunt), compatible with most 64-bit Linux desktop and servers.

Follow the Syhunt installation guide for the Linux distribution you use.

DistributionGuide Difficulty Level
Kali LinuxVery Easy
Parrot OSVery Easy
FedoraVery Easy
MX LinuxVery Easy
Ubuntu Desktop/ServerEasy
Oracle LinuxEasy
Alma LinuxEasy
Rocky LinuxEasy
Amazon Linux 2Easy
Amazon Linux 2023Easy
CentOS (Everything/Minimal)Easy
DebianEasy
openSUSEEasy
KDE NeonEasy
DeepinEasy
ManjaroEasy
Red Hat Enterprise (RHEL)Easy
Arch LinuxMedium
Linux Mint20: Easy, 19 or later: Medium
Elementary OS5.1: Easy, 5.0: Incompatible
SolusIncompatible (Unstable)

Installing the Syhunt Sandcat browser extension

Since version 7.2, Syhunt Hybrid comes with a browser extension that can be installed in Edge, Chrome, Brave or any Chromium-based web browser. This browser extension has been designed to allow manual login and browser-assisted testing. The name Sandcat is a tribute to the Sandcat Browser, included with 7.1 and previous versions of Syhunt, the built-in browser that allowed manual login to be performed in a similar way.

  1. Open your web browser and go to menu -> Extensions -> Manage Extensions.
  2. Enable developer mode (at the top right side of the screen).
  3. Click the Load Unpacked button and select the folder where the Sandcat Extension is available:
    1. On Windows: C:\Program Files\Syhunt Hybrid\Extensions\SandcatExtension
    2. On Linux: /home/[user]/syhunt-hybrid/carbon/sandcat
    3. On macOS: /Applications/Syhunt Hybrid/carbon/sandcat
  4. After that, you will see the Syhunt Sandcat extension in the list of extensions.
    1. After that, visit the web UI home again and you should see the message: Extension detected and ready. This means everything is OK.

If your web UI is accessible through an IP, domain or subdomain (other than localhost), configure the URL in the extensions preferences:

  1. Click the Details button of the extension, then Extension options.
  2. Check the option Use custom Syhunt UI origin,
  3. Adjust the protocol (http or https).
  4. Enter the host (careful not to add protocol to the host, like http:// or https://)
  5. Enter the port used by the web UI.
  6. Click the Save button.
  7. After that, visit the web UI home again and you should see the message: Extension detected and ready. This means everything is OK.

System Requirements

Syhunt Hybrid can be installed on 64-bit versions of Windows, MacOS (on Apple Silicon) or Linux, but it is able to analyze applications designed for any target platform, including Android, Apple iOS and macOS, BSD, Linux, Windows, Solaris and Unix, independently of the platform it is executed from.

  1. 4GB of available RAM (8GB recommended) *
  2. 2GB of free disk space**
  3. Internet Connection (recommended for code scans and dynamic scans and some features)
  4. One of the following compatible 64-bit operating systems:
    1. Windows 10 or 11, or Windows Server 2016 to 2025 (x64 or ARM64).
    2. MacOS Sequoia 15.4.1 or higher (on Apple Silicon)
    3. Any of the following supported Linux distributions:
      1. Kali 2024.3 or higher
      2. Ubuntu Server or Desktop 18 or higher
      3. Debian 9 or higher
    4. Any unofficially supported OS***, like a Linux distribution such as the ones listed below.
  5. (Optional) GIT on Linux/macOS or GIT for Windows (optional for GIT repository scans)
  6. Java or Java Headless installed on Linux/macOS
  7. If native binary is not available for your specific OS type or distribution yet, Wine64 Stable is required to be installed.
  8. (Optional) API key (OpenAI or DeepSeek) or local AI model to enable AI-powered features. For more details, see System Requirements for Local Model

* This does not include additional RAM that may be required to perform concurrent scans.

** This does not include the space required to save scan session data, which varies depending on the website or source code being analyzed and the scan frequency.

*** Unofficially supported OS: means that while the product has been successfully tested and the installation process has been documented, Syhunt does not provide technical support or assistance for issues related to the product's performance on that particular OS. If you choose to use the product with an OS that is not officially supported, you may encounter compatibility issues, errors, or bugs. Therefore, it is always recommended to use a supported OS to ensure optimal performance and compatibility with the product.

Compatible Linux Distributions

Officially Supported:
Ubuntu Server/Desktop 18.10 and later
Debian 9 and later
Unofficially (Successfully Tested):
Fedora 32 and later
CentOS 7.7 and later (Minimal or Everything)
Kali Linux 2019 and later
Parrot OS 4.1, 4.7 and later
Linux Mint 19.2 and later
OpenSUSE Leap 15.1 and later
Fedora 32
MX Linux 19.1 and later
KDE Neon 2020.03 and later
Deepin 15.9
Manjaro 19
Arch Linux 2019 and later
Unsupported:
Elementary OS 5.1 (Successfully Tested), 5.0 (Unsupported)
CentOS 6.1 (Successfully Tested)
Solus 4.1 (Unstable)

Internet Connection Requirements

The machine on which Syhunt is installed must be allowed to open HTTP(S) requests to the following Internet addresses:

DomainPortsFeature
Specific target domain(s)80, 443*The domain hosting the web application or codebase you want to scan
Any or specific asset domain(s)80, 443Optional, if you want externally hosted JavaScript files and assets to be analyzed during DAST or SAST (Recommended)
syhunt.fra1.cdn.digitaloceanspaces.com443Required (Assets for installation and auto-updating)
www.syhunt.net80, 443Required (Assets for HTML/PDF generation, update notification, auto-updating, and more)
signal.syhunt.net80, 443Required during DAST for performing OAST (Important)
api.openai.com443Optional for AI-powered features
fonts.googleapis.com80, 443Required (Assets for HTML/PDF generation - Fonts)
www.google.com443Required (Assets for HTML/PDF generation - Google's JSAPI)
www.gstatic.com443Required (Assets for HTML/PDF generation - Google's JSAPI)

* If your target is using a non-standard port (eg, 8080), or you want to connect to a GIT address using SSH, or other protocols, you need to allow these ports as well.

If you use a personal firewall, you'll just have to let the firewall know that Syhunt is authorized to make connections to the Internet.

Finishing the Installation

  1. Download the Syhunt Hybrid setup using a web browser like Chrome or Firefox, wget or curl command.
  2. Run the Syhunt setup application (On Windows and Linux distros the setup will run if you just open the file after giving it the appropriate permission):
    • Hybrid: java -jar syhunt-hybrid-7.2.0.31.jar
    • If you are on headless Linux: java -jar syhunt-hybrid-7.2.0.31.jar -console
    • Community: java -jar syhunt-community-7.0.10.3.jar
  3. Alternatively, on Linux, if you have binfmt-support installed (sudo apt install binfmt-support, to install it), give the jar file executable permission (chmod a+rx setupfilename.jar or using the file properties of the jar file) and execute it directly:
    • Hybrid: ./syhunt-hybrid-7.2.0.31.jar
    • If you are on headless Linux: ./syhunt-hybrid-7.2.0.31.jar -console
    • Community: ./syhunt-community-7.0.10.3.jar
  4. Read carefully the EULA presented to you on installation before accepting it. It's an easy next-next-finish installation process. When you click Finish, Syhunt tools are ready for use.
    1. On Linux: Syhunt will (by default) be installed in /home/[user]/syhunt-hybrid or /home/[user]/syhunt-community
    2. On MacOS: Syhunt will (by default) be installed in /Applications/Syhunt Hybrid/ or /Applications/Syhunt Community/
  5. Finally, enable the Syhunt web user interface.

Console mode

Alternatively, if the Syhunt setup is running in console mode:

  1. Give 1 to accept after reading EULA (if you agree with its terms) or 2 to reject it (if you reject the terms, you cannot install and use Syhunt)
  2. Press enter to install using the default installation path
  3. Enter 1 to continue the installation
  4. Enter Y (Yes) to install Syhunt Core
  5. Enter 1 to continue. After that you should see a message saying: console installation done.

What's next? Read our quick start and integration guides.

Updating Syhunt

You can download and install the updates directly from the Syhunt website. If you have Syhunt Hybrid version 6.8.4 or higher, Syhunt will also notify you about new releases both in its Launcher interface and reports.

On Linux or macOS, you can use the command scanupdate to check for updates. If updates are available, Syhunt will ask if you want to download and install them. If you call scanupdate auto, Syhunt will check for updates and automatically install them when the command is executed without asking for user confirmation.

There is no need to uninstall Syhunt before installing a new version, unless you are updating Syhunt Community CLI under Windows.

Uninstalling Syhunt

On Windows operating systems, Syhunt creates a uninstall shortcut in the Start Menu under the Syhunt Community or Syhunt Hybrid folder, and an uninstall entry in the Program and Features area of the Windows Control Panel which allow to uninstall Syhunt completely.

On Linux or macOS operating systems, go to the directory where you installed Syhunt and execute the command:

java -jar Uninstall.jar

Contact