Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/teycir/apihunter
ReconnaissanceVulnerability ScannersDynamic Analysis (Sandboxing)Web Application ExploitationInformation GatheringWeb SecurityPenetration TestingDevSecOpsAPI Security
GitHubteycir/apihunter

ApiHunter

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

View RepositoryWebsite
192172 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Support Development

If this project helps your work, support ongoing maintenance and new features.

ETH Donation Wallet
0x11282eE5726B3370c8B480e321b3B2aA13686582

Ethereum donation QR code

Scan the QR code or copy the wallet address above.

🎯 ApiHunter

Typing SVG

Rust Security API Async CI License


📺 Video Demo

ApiHunter Demo Video
Click to watch the full demo on YouTube

🖥️ Desktop App Snapshots

ApiHunter Desktop — Overview panel with version chip, health check, and Full Scan target input

ApiHunter Desktop — Full Scan controls: Quick Passive / Deep Active presets, collapsible Safety, Runtime Limits, and Scanner Toggles sections

ApiHunter Desktop — Results analytics dashboard: severity heatmap, worst-target card, scan efficiency, summary, findings breakdown, and top checks

ApiHunter Desktop — Results lower panel: target ranking, scanner coverage, check severity breakdown, per-target summary, and one-click export buttons


📑 Table of Contents

  • Video Demo
  • Desktop App Snapshots
  • Why ApiHunter?
  • Scanner Modules
  • Features
  • Comparison with Other Tools
  • Quick Start
  • Architecture
  • Template Tooling
  • Scan Scripts
  • Testing Strategy
  • Documentation
  • Roadmap
  • Installation
  • CLI Reference
  • Exit Codes
  • Security & Legal Guardrails
  • Related Projects
  • About
  • FAQ
  • License

Async, modular API security scanner for API baseline testing and regression detection.
Combines discovery with targeted checks (CORS/CSP/GraphQL/OpenAPI/JWT/API Security) using adaptive concurrency and CI-ready outputs (NDJSON/SARIF).

Use cases: offense for red-team/API pentest discovery and exploit validation, and defense for CI/CD regression gating, continuous API hardening, and early misconfiguration detection.

Scanning at scale? See Triage Mode — scan 5000 targets in 20 minutes with core security checks, then use Enrich Mode to add threat intelligence context (ports, CVEs, ASN, domain age) to findings.

Naming

  • Project/repository: ApiHunter
  • Cargo package: apihunter
  • Library crate: api_scanner
  • CLI binary: apihunter (default for cargo run)

GitHub Metadata (Recommended)

Set these in the GitHub repository settings for discoverability:

  • Description: Async API security scanner for CORS/CSP/GraphQL/JWT/OpenAPI and active API posture checks.
  • Website: https://github.com/Teycir/ApiHunter
  • Topics: rust, security, api-security, scanner, graphql, cors, csp, jwt, openapi, sarif, ndjson

Repository Flow

flowchart LR
    A[CLI apihunter] --> B[main.rs]
    D[Input Sources] --> E[Pre-filter + Discovery]
    B --> C[HttpClient + Config]
    E --> F[runner.rs]
    C --> F

    F --> G1[Passive scanners]
    F --> G2[Active scanners]

    I[template-tool] --> H[CVE templates]
    H --> G2

    G1 --> J[Findings]
    G2 --> J
    J --> K[Reporter]
    K --> L[Auto Reports]
    K --> M[CI/CD Controls]

Why ApiHunter?

Core Advantages

  • API-First Architecture: Purpose-built for REST/GraphQL APIs, not adapted from web app scanners
  • Intelligent False Positive Reduction:
    • SPA catch-all detection with canary probing
    • Context-aware secret validation (frontend vs backend)
    • Body content validation and referer checking
    • Response fingerprinting to skip duplicate findings
  • Production-Safe by Design:
    • Adaptive concurrency (AIMD) that backs off on errors
    • Per-host rate limiting with configurable delays
    • Politeness controls (retries, timeouts, WAF evasion)
    • Dry-run mode for active checks
  • Stealth & Evasion:
    • Runtime User-Agent rotation from curated pool (assets/user_agents.txt)
    • Randomized request delays with jitter
    • Per-host delay enforcement (avoids burst patterns)
    • Retry logic with exponential backoff
    • Custom header injection for blending with legitimate traffic
    • Adaptive timing based on server responses
    • No hardcoded scanner fingerprints in default mode

Stealth Techniques Deep Dive

ApiHunter uses several stealth techniques to avoid detection by WAF (Web Application Firewall) and bot protection systems:

1. User-Agent Rotation

What it does: Randomly cycles through 100+ real browser User-Agent strings from a file (assets/user_agents.txt)

Why it works: Bots typically use the same User-Agent (like curl/7.68.0). By pretending to be Chrome, Firefox, Safari, etc., you blend in with legitimate traffic

Simple analogy: Like wearing different disguises instead of always wearing the same uniform

2. Random Timing & Jitter

What it does: Adds random delays between requests (controlled by --delay-ms) with jitter (small random variations)

Why it works: Bots send requests at perfect intervals (exactly 100ms apart). Humans are unpredictable. Random timing makes traffic look organic

Simple analogy: Walking with irregular steps instead of marching like a robot

3. Per-Host Delay Enforcement

What it does: Tracks delay separately for each domain, not globally

Why it works: Prevents burst patterns where you hit one host 50 times instantly. Each host sees polite, spaced-out requests

Simple analogy: Taking turns in different conversations instead of shouting at one person repeatedly

Download Tool