The payload was typed, not spoken. Get it in writing.
Security video is where transcription fails hardest. The presenter says "and we just fire this off" while the payload sits in the terminal; the header that matters is in the Burp pane; the vulnerable function is on screen for six seconds. An audio transcript of a conference talk keeps the narration and loses the research.
SightScript reads the screen alongside the audio, so a talk or a walkthrough comes back as a writeup you can search months later: the chain in order, every command and request captured character for character, and the detection and mitigation the speaker gave.
Free to try — no account, no card.
One talk in. A writeup and a reference out.
Technical writeup
Shaped like a good vulnerability report: target and preconditions, root cause, the chain with commands inline, impact, and detection and mitigation — readable by someone who never watched the video.
Attack chain
The progression in order — recon, foothold, escalation, impact — each stage timestamped where the video places it, carrying the exact command or request when one was shown, including the failed attempts that led to the working payload.
Artifacts
The reference table you actually search later: CVEs, endpoints, hosts, ports, paths, hashes, versions and tools, each recorded exactly as it appeared on screen.
Detection & mitigation
The defensive half most summaries drop: what to log, what to alert on, what to patch, and what to do when patching isn't an option.
Visual notes
The complete on-screen record — HTTP requests and responses, vulnerable code, config files, error pages. Anything typed is kept verbatim with its encoding intact; long tool output is kept down to the lines that carry the finding.
Transcript & chapters
The full talk with timestamps and speaker labels, plus a timestamped outline so you can jump back to the exact minute a technique was shown.
A wrong identifier is worse than a missing one
Generic AI summaries invent CVE numbers and "correct" the flags you actually need. This one is built to transcribe, not to recall.
Payloads survive intact
URL-encoding, base64, escapes and odd whitespace are preserved exactly — a re-encoded payload is a dead payload.
No invented identifiers
A CVE, version or hash is recorded only when it was read in full from the screen. If the video never named one, you get the vulnerability described in words instead of a plausible-looking number.
Only the impact demonstrated
What the demo actually reached, kept separate from what the presenter claimed — no quiet upgrade from file read to remote code execution.
How it works
Paste the talk
A conference talk, a bug bounty walkthrough, a CTF solve, a tool demo — anything with a terminal or a proxy on screen.
It reads the screen
Terminal, Burp pane, code, slides — together with what was said about them.
Keep the writeup
Read it in tabs, export to Markdown, Word or PDF, or — with a free account — share it as a read-only link with your team.
Questions, answered
Will it make up a CVE number?
It's specifically built not to. Identifiers are all-or-nothing: a CVE, version or hash is only recorded when it was read in full from the screen or heard unambiguously. If the video never names one, you get a description of the vulnerability rather than a guess — because for this audience a wrong identifier is far worse than a missing one.
Does it work on defensive talks and tool demos?
Yes. The writeup adapts to what the video actually is, and a video with no attack in it simply returns no attack chain rather than dressing up an install walkthrough as an intrusion. The artifacts table still collects the identifiers — rule names, log fields, event IDs, versions.
How long can the video be?
Up to 20 minutes without an account and 45 minutes with a free account. Pro ($9.99/month) covers 90 minutes, which fits a full conference session, and can combine up to 5 videos into one document — up to 90 minutes of video in total.
Can I process a private recording?
Pro supports direct file upload, so an internal demo or a recorded engagement debrief doesn't need to be on YouTube. The file goes from your browser straight to a one-time transit store at an unguessable URL, which is deleted the moment the file is handed to the model; the model's own copy expires within 48 hours. Only the documents are kept, in your library.
Try it on your last video
Paste a link, pick your output, and see what it caught on screen.
Start freeMore ways to use SightScript