BurnBox Architecture & API Reference
Developer and analyst guide to the BurnBox secure web research workspace, SSRF perimeter controls, and REST APIs.
1. The 6-Stage Web Research Lifecycle
BurnBox standardizes web investigations into an auditable six-stage pipeline:
Discover and input target URLs, configure crawl depth (1–3), and set domain scoping constraints.
Run pre-flight DNS SSRF validation and dispatch crawl tasks to decoupled Scrapy Cloud workers.
Harvest page body content, HTTP response codes, response headers, and outbound link graphs.
Inspect evidence, export clean JSON datasets, or run exploratory analytics via Deepnote notebooks.
Attach structured notes, risk tags, and timeline markers to research findings in project workspaces.
Collaborate securely across roles with tenant-scoped permissions and immutable audit logs.
2. SSRF Shield & Perimeter Verification
Before any crawl job is dispatched, the BurnBox control plane executes a multi-layer SSRF filter:
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopbacks (127.0.0.0/8, ::1), and carrier-grade NAT (100.64.0.0/10).169.254.169.254) on AWS, GCP, Azure, and DigitalOcean.3. REST API Endpoints
/api/investigations/api/investigations/api/investigations/:id/api/projects/api/projects/api/audit-logs/api/analytics/api/analytics/api/webhooks/pageclip