Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
kiterunner — High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists, and concurrent host scanning. | Kitploit
Tools/GitHubGitHub/assetnote/kiterunner
ReconnaissanceWeb Vulnerability ScannersDynamic Code Analysis (DAST)Web Application ExploitationAPI Security TestingInformation GatheringWeb SecurityAPI SecurityTop in API Security #1Top in API Security Testing #1
3.2k340375 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Top in Dynamic Code Analysis (DAST) #14
Top in Web Application Exploitation #15
Top in Web Security #14
Top in Web Vulnerability Scanners #14
GitHubassetnote/kiterunner

kiterunner

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists, and concurrent host scanning.

View Repository

Kiterunner

GoDoc GitHub release Go Report Card

Introduction

For the longest of times, content discovery has been focused on finding files and folders. While this approach is effective for legacy web servers that host static files or respond with 3xx’s upon a partial path, it is no longer effective for modern web applications, specifically APIs.

Over time, we have seen a lot of time invested in making content discovery tools faster so that larger wordlists can be used, however the art of content discovery has not been innovated upon.

Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications.

Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values.

When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered.

By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters and values for each request it sends.

Swagger files were collected from a number of datasources, including an internet wide scan for the 40+ most common swagger paths. Other datasources included GitHub via BigQuery, and APIs.guru.

Contents

  • Kiterunner
  • Introduction
  • Installation
    • Downloading a release
    • Building from source
    • Installing via AUR
  • Usage
    • Quick Start
    • CLI Help
    • Input/Host Formatting
    • API Scanning
    • Vanilla Bruteforcing
    • Dirsearch Bruteforcing
  • Technical Features
    • Depth Scanning
    • Using Assetnote Wordlists
      • Head Syntax
    • Concurrency Settings/Going Fast
    • Converting between file formats
    • Replaying requests
  • Technical Implementation
    • Intermediate Data Type (PRoutes)
    • Kite File Format

Installation

Downloading a release

You can download a pre-built copy from https://github.com/assetnote/kiterunner/releases.

Building from source

# build the binary
make build

# symlink your binary
ln -s $(pwd)/dist/kr /usr/local/bin/kr

# compile the wordlist
# kr kb compile <input.json> <output.kite>
kr kb compile routes.json routes.kite

# scan away
kr scan hosts.txt -w routes.kite -x 20 -j 100 --ignore-length=1053

The JSON datasets can be found below:

  • routes-large.json (118MB compressed, 2.6GB decompressed)
  • routes-small.json (14MB compressed, 228MB decompressed)

Alternatively, it is possible to download the compile .kite files from the links below:

  • routes-large.kite (40MB compressed, 183M decompressed)
  • routes-small.kite (2MB compressed, 35MB decompressed)

AUR

Users using a Arch based distro can download the pre-built binary from AUR You can use a "Aur Helper" like yay to install kiterunner

yay -S kiterunner-bin

Usage

Quick Start

kr [scan|brute] <input> [flags]
  • <input> can be a file, a domain, or URI. we'll figure it out for you. See Input/Host Formatting for more details
# Just have a list of hosts and no wordlist
kr scan hosts.txt -A=apiroutes-210328:20000 -x 5 -j 100 --fail-status-codes 400,401,404,403,501,502,426,411

# You have your own wordlist but you want assetnote wordlists too
kr scan target.com -w routes.kite -A=apiroutes-210328:20000 -x 20 -j 1 --fail-status-codes 400,401,404,403,501,502,426,411

# Bruteforce like normal but with the first 20000 words
kr brute https://target.com/subapp/ -A=aspx-210328:20000 -x 20 -j 1

# Use a dirsearch style wordlist with %EXT%
kr brute https://target.com/subapp/ -w dirsearch.txt -x 20 -j 1 -exml,asp,aspx,ashx -D

CLI Help

Usage:
  kite scan [flags]
Download Tool