---
url: https://docs.ogmabox.com/app/automate.md
description: Run repeatable request campaigns with Ogma Automate.
---

# Automate

Automate sends one request template many times with controlled payload variation, letting you enumerate parameters, fuzz inputs, or test access controls at scale.

## Create a Session

1. Open a request in **HTTP History** or **Replay**.
2. Right-click the request and choose **Send to Automate**, or use the toolbar button.
3. The request opens as the session template. All further configuration applies to this template.

## Payload Positions

Payload positions mark where payloads are inserted. Ogma replaces each marker with a payload value per request.

* Highlight text in the request editor and click **Mark** to add a position marker.
* Remove a marker by clicking the marker handle and selecting **Remove**.
* Multiple positions are supported. Their behavior depends on the attack mode.

## Attack Modes

| Mode | Behavior |
|------|----------|
| Sniper | One position at a time. Iterates each payload through each position in turn. Total requests equal payload count times position count. |
| Battering Ram | Uses the same payload value in all positions simultaneously. |
| Pitchfork | Multiple positions iterated in parallel. Pairs the first payload from list A with the first from list B, and so on. Stops when the shortest list is exhausted. |
| Cluster Bomb | Every combination across all positions. Request count equals the product of all list lengths. Use with small lists. |
| Sequential | Extracts a configured value from each response and injects it into the next request. Configure the extractor, target position, and iteration limit before starting. |

## Payload Sources

| Source | Description |
|--------|-------------|
| Wordlist | Load a newline-delimited file or paste values directly. |
| Numbers | Generate a numeric range with a configurable start, end, and step. |
| Null | Replaces the position with an empty string for the configured number of iterations; it does not retain the original marked text. |
| Custom list | Enter values inline without a file. |

## Matchers

Matchers annotate result rows that meet a condition. They do not filter rows; they add a boolean column per matcher.

* Add a matcher by clicking **+ Matcher**.
* Describe the condition in plain language using **AI Assist**, or configure it manually.

| Matcher type | Matches when |
|--------------|--------------|
| Status | Response code equals or differs from a given value. |
| Size | Response body length falls within a specified range. |
| Body content | Response body contains or matches a string or regex. |

## Stop Conditions

A stop condition halts the run when a matcher fires.

* Configure a **Stop condition** using response status or size, a comparison operator, and a value.
* A matching result pauses the run; requests already in flight may still complete.

This is useful when you need only the first successful result, such as a valid credential or a bypassed check.

## Extractors

Extractors pull a value from each response and store it as a named column.

* Use extractors to capture CSRF tokens, session IDs, or nonces for chained requests.
* Describe the extraction target using **AI Assist**, or configure Body Regex, Body Grep, or Response Header extraction manually.
* Extracted values appear as columns in the results table.
* For sequential mode, configure the extractor used for chaining explicitly; a result sent to another session does not automatically establish token extraction for that session.

## Results Table

Each completed request produces one row.

| Column | Description |
|--------|-------------|
| # | Request sequence number. |
| Status | HTTP response code. |
| Size | Response body length in bytes. |
| Time | Round-trip time in milliseconds. |
| Payload | The payload value(s) used for this request. |
| Matcher columns | One boolean column per configured matcher. |
| Extractor columns | One extracted value column per configured extractor. |

Click any row to open the full request and response in the inspector panel.

## Filtering Results

Type a HTTPQL expression in the **Filter** bar above the results table to narrow displayed rows. Example:

```text
result.status.eq:200 AND result.len.gt:500
```

Automate queries use the `result.*` namespace. For an extracted column, use its `result.extract.<name>` field. HTTP History's `req.*` and `resp.*` fields are not interchangeable with Automate result filters.

## AI Assist

The **AI Assist** button appears next to matcher and extractor configuration fields. Describe what you want to detect or extract in plain language. Ogma generates the configuration. Review the result before saving.

## Send a Result Elsewhere

Right-click any result row to:

* **Send to Replay** - open the specific request and response in Replay for manual follow-up.
* **Send to new Automate session** - use the result row's request as the template for a new session.
* **Copy as curl** - copy the request as a curl command.

## Related Pages

* [Replay](./replay.md)
* [Environment](./environment.md)
* [Exports](./exports.md)
