
Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
If this project helps your work, support ongoing maintenance and new features.
ETH Donation Wallet
0x11282eE5726B3370c8B480e321b3B2aA13686582
Scan the QR code or copy the wallet address above.
Async, modular API security scanner for API baseline testing and regression detection.
Combines discovery with targeted checks (CORS/CSP/GraphQL/OpenAPI/JWT/API Security) using adaptive concurrency and CI-ready outputs (NDJSON/SARIF).
Use cases: offense for red-team/API pentest discovery and exploit validation, and defense for CI/CD regression gating, continuous API hardening, and early misconfiguration detection.
Scanning at scale? See Triage Mode — scan 5000 targets in 20 minutes with core security checks, then use Enrich Mode to add threat intelligence context (ports, CVEs, ASN, domain age) to findings.
ApiHunterapihunterapi_scannerapihunter (default for cargo run)Set these in the GitHub repository settings for discoverability:
Async API security scanner for CORS/CSP/GraphQL/JWT/OpenAPI and active API posture checks.https://github.com/Teycir/ApiHunterrust, security, api-security, scanner, graphql, cors, csp, jwt, openapi, sarif, ndjsonflowchart LR
A[CLI apihunter] --> B[main.rs]
D[Input Sources] --> E[Pre-filter + Discovery]
B --> C[HttpClient + Config]
E --> F[runner.rs]
C --> F
F --> G1[Passive scanners]
F --> G2[Active scanners]
I[template-tool] --> H[CVE templates]
H --> G2
G1 --> J[Findings]
G2 --> J
J --> K[Reporter]
K --> L[Auto Reports]
K --> M[CI/CD Controls]
ApiHunter uses several stealth techniques to avoid detection by WAF (Web Application Firewall) and bot protection systems:
What it does: Randomly cycles through 100+ real browser User-Agent strings from a file (assets/user_agents.txt)
Why it works: Bots typically use the same User-Agent (like curl/7.68.0). By pretending to be Chrome, Firefox, Safari, etc., you blend in with legitimate traffic
Simple analogy: Like wearing different disguises instead of always wearing the same uniform
What it does: Adds random delays between requests (controlled by --delay-ms) with jitter (small random variations)
Why it works: Bots send requests at perfect intervals (exactly 100ms apart). Humans are unpredictable. Random timing makes traffic look organic
Simple analogy: Walking with irregular steps instead of marching like a robot
What it does: Tracks delay separately for each domain, not globally
Why it works: Prevents burst patterns where you hit one host 50 times instantly. Each host sees polite, spaced-out requests
Simple analogy: Taking turns in different conversations instead of shouting at one person repeatedly