Security research toolkit / 01
RH2
ENUM
A focused Python framework for authentication analysis—built to compare normal and candidate responses, surface meaningful differences, and turn a vague signal into explainable evidence.

The idea
Find the difference that matters.
Authentication behavior rarely announces itself with one perfect response. A target may reveal a subtle status change, a different message length, a timing delta, or one inserted character. RH2 Enum turns those small differences into a repeatable comparison workflow.
The tool learns a baseline, injects one candidate at a time into a controlled request template, compares the result, and reports the evidence behind the difference. That emphasis on explanation is the point: the output should help a researcher decide what to verify next.
Under the hood
Six working parts.
Parse → baseline → compare → explain → verify
- 01
Request parser
Turns a captured request into a reusable target while preserving method, headers, body, and placeholders.
- 02
Baseline engine
Learns normal response fingerprints before comparing candidate inputs against the target's own behavior.
- 03
Response analysis
Measures status, length, words, lines, headers, timing, similarity, and precise character differences.
- 04
Timing layer
Uses repeated samples, outlier filtering, adaptive thresholds, and delta reporting for timing-based signals.
- 05
Thread engine
Runs bounded concurrent candidate checks while keeping the output structured and readable.
- 06
Evidence output
Explains why a candidate differs instead of returning an opaque yes/no result.
Workflow
Evidence over noise.
Load a controlled request
Keep the method, headers, body, and placeholder explicit so the test can be reproduced.
Learn normal behavior
Collect baseline responses and calculate the target's normal fingerprint and timing range.
Compare candidates
Run bounded candidate checks and inspect status, length, similarity, precise differences, and timing.
Read the reason
A candidate is useful only when the output explains why it differed and what should be verified next.
Open source project
Read the implementation.
The public repository contains the modular Python source, CLI components, analyzers, comparison layers, and project metadata.