RH2-1 / PROJECTSBack to archive ↗

Security research toolkit / 01

RH2
ENUM

A focused Python framework for authentication analysis—built to compare normal and candidate responses, surface meaningful differences, and turn a vague signal into explainable evidence.

Python 3.10+RequestsRich CLIv1.0.0
Abstract amber and black RH2 Enum response-analysis system diagram
RH2 / ENUMSYS-0001
Response difference engine

The idea

Find the difference that matters.

Authentication behavior rarely announces itself with one perfect response. A target may reveal a subtle status change, a different message length, a timing delta, or one inserted character. RH2 Enum turns those small differences into a repeatable comparison workflow.

The tool learns a baseline, injects one candidate at a time into a controlled request template, compares the result, and reports the evidence behind the difference. That emphasis on explanation is the point: the output should help a researcher decide what to verify next.

Under the hood

Six working parts.

Parse → baseline → compare → explain → verify

  1. 01

    Request parser

    Turns a captured request into a reusable target while preserving method, headers, body, and placeholders.

  2. 02

    Baseline engine

    Learns normal response fingerprints before comparing candidate inputs against the target's own behavior.

  3. 03

    Response analysis

    Measures status, length, words, lines, headers, timing, similarity, and precise character differences.

  4. 04

    Timing layer

    Uses repeated samples, outlier filtering, adaptive thresholds, and delta reporting for timing-based signals.

  5. 05

    Thread engine

    Runs bounded concurrent candidate checks while keeping the output structured and readable.

  6. 06

    Evidence output

    Explains why a candidate differs instead of returning an opaque yes/no result.

Workflow

Evidence over noise.

01

Load a controlled request

Keep the method, headers, body, and placeholder explicit so the test can be reproduced.

02

Learn normal behavior

Collect baseline responses and calculate the target's normal fingerprint and timing range.

03

Compare candidates

Run bounded candidate checks and inspect status, length, similarity, precise differences, and timing.

04

Read the reason

A candidate is useful only when the output explains why it differed and what should be verified next.

Open source project

Read the implementation.

The public repository contains the modular Python source, CLI components, analyzers, comparison layers, and project metadata.

Open GitHub ↗