Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ApiHunter — Rust製の非同期APIセキュリティスキャナー。CORS、CSP、GraphQL、JWT、OpenAPI、およびアクティブなAPIセキュリティ態勢チェック用。 | Kitploit
ツール/GitHubGitHub/teycir/apihunter
偵察脆弱性スキャナー動的分析 (サンドボックス)ウェブアプリケーション悪用情報収集ウェブセキュリティペネトレーションテストDevSecOpsAPIセキュリティ
GitHubteycir/apihunter

ApiHunter

Rust製の非同期APIセキュリティスキャナー。CORS、CSP、GraphQL、JWT、OpenAPI、およびアクティブなAPIセキュリティ態勢チェック用。

192172ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見るウェブサイト

開発のサポート

このプロジェクトがあなたの作業に役立つなら、継続的なメンテナンスと新機能の開発をサポートしてください。

ETH 寄付ウォレット
0x11282eE5726B3370c8B480e321b3B2aA13686582

Ethereum 寄付 QR コード

上記のQRコードをスキャンするか、ウォレットアドレスをコピーしてください。

🎯 ApiHunter

タイピング SVG

Rust セキュリティ API 非同期 CI ライセンス


📺 ビデオデモ

ApiHunter デモビデオ
クリックしてYouTubeでフルデモを視聴してください

🖥️ デスクトップアプリのスクリーンショット

ApiHunter デスクトップ — バージョンチップ、ヘルスチェック、Full Scan ターゲット入力を備えた概要パネル

ApiHunter デスクトップ — Full Scan コントロール: Quick Passive / Deep Active プリセット、折りたたみ可能な Safety、Runtime Limits、Scanner Toggles セクション

ApiHunter デスクトップ — 結果分析ダッシュボード: 重大度ヒートマップ、ワーストターゲットカード、スキャン効率、サマリー、検出結果の内訳、トップチェック

ApiHunter デスクトップ — 結果下部パネル: ターゲットランキング、スキャナーカバレッジ、チェック重大度の内訳、ターゲット別サマリー、ワンクリックエクスポートボタン


📑 目次

  • ビデオデモ
  • デスクトップアプリのスクリーンショット
  • ApiHunter を使う理由?
  • スキャナーモジュール
  • 特徴
  • 他のツールとの比較
  • クイックスタート
  • アーキテクチャ
  • テンプレートツール
  • スキャンスクリプト
  • テスト戦略
  • ドキュメント
  • ロードマップ
  • インストール
  • CLI リファレンス
  • 終了コード
  • セキュリティと法的ガードレール
  • 関連プロジェクト
  • 概要
  • FAQ
  • ライセンス

API のベースラインテストと回帰検出のための、非同期・モジュール式 API セキュリティスキャナー。
適応型並行処理と CI 対応出力(NDJSON/SARIF)を用いて、探索とターゲットを絞ったチェック(CORS/CSP/GraphQL/OpenAPI/JWT/API Security)を組み合わせます。

ユースケース: 攻撃側ではレッドチーム/API ペネトレーションテストの探索とエクスプロイト検証、防御側では CI/CD 回帰ゲート、継続的な API ハードニング、早期の設定ミス検出。

大規模スキャンをお考えですか? Triage Mode を参照 — コアセキュリティチェックで 20 分間に 5000 ターゲットをスキャンし、その後 Enrich Mode を使用して脅威インテリジェンスのコンテキスト(ポート、CVE、ASN、ドメインの経過期間)を検出結果に追加できます。

命名

  • プロジェクト/リポジトリ: ApiHunter
  • Cargo パッケージ: apihunter
  • ライブラリクレート: api_scanner
  • CLI バイナリ: apihunter(cargo run のデフォルト)

GitHub メタデータ(推奨)

見つけやすくするために、GitHub リポジトリの設定でこれらを設定してください:

  • 説明: CORS/CSP/GraphQL/JWT/OpenAPI とアクティブな API 姿勢チェックのための非同期 API セキュリティスキャナー。
  • ウェブサイト: https://github.com/Teycir/ApiHunter
  • トピックス: rust, security, api-security, scanner, graphql, cors, csp, jwt, openapi, sarif, ndjson

リポジトリのフロー```mermaid

flowchart LR A[CLI apihunter] --> B[main.rs] D[Input Sources] --> E[Pre-filter + Discovery] B --> C[HttpClient + Config] E --> F[runner.rs] C --> F

F --> G1[Passive scanners]
F --> G2[Active scanners]

I[template-tool] --> H[CVE templates]
H --> G2

G1 --> J[Findings]
G2 --> J
J --> K[Reporter]
K --> L[Auto Reports]
K --> M[CI/CD Controls]
## Why ApiHunter?

### Core Advantages

- **API-First Architecture**: Purpose-built for REST/GraphQL APIs, not adapted from web app scanners
- **Intelligent False Positive Reduction**: 
  - SPA catch-all detection with canary probing
  - Context-aware secret validation (frontend vs backend)
  - Body content validation and referer checking
  - Response fingerprinting to skip duplicate findings
- **Production-Safe by Design**:
  - Adaptive concurrency (AIMD) that backs off on errors
  - Per-host rate limiting with configurable delays
  - Politeness controls (retries, timeouts, WAF evasion)
  - Dry-run mode for active checks
- **Stealth & Evasion**:
  - Runtime User-Agent rotation from curated pool (assets/user_agents.txt)
  - Randomized request delays with jitter
  - Per-host delay enforcement (avoids burst patterns)
  - Retry logic with exponential backoff
  - Custom header injection for blending with legitimate traffic
  - Adaptive timing based on server responses
  - No hardcoded scanner fingerprints in default mode

### Stealth Techniques Deep Dive

ApiHunter uses several stealth techniques to avoid detection by WAF (Web Application Firewall) and bot protection systems:

#### 1. User-Agent Rotation
**What it does:** Randomly cycles through 100+ real browser User-Agent strings from a file (`assets/user_agents.txt`)

**Why it works:** Bots typically use the same User-Agent (like `curl/7.68.0`). By pretending to be Chrome, Firefox, Safari, etc., you blend in with legitimate traffic

**Simple analogy:** Like wearing different disguises instead of always wearing the same uniform

#### 2. Random Timing & Jitter
**What it does:** Adds random delays between requests (controlled by `--delay-ms`) with jitter (small random variations)

**Why it works:** Bots send requests at perfect intervals (exactly 100ms apart). Humans are unpredictable. Random timing makes traffic look organic

**Simple analogy:** Walking with irregular steps instead of marching like a robot

#### 3. Per-Host Delay Enforcement
**What it does:** Tracks delay separately for each domain, not globally

**Why it works:** Prevents burst patterns where you hit one host 50 times instantly. Each host sees polite, spaced-out requests

**Simple analogy:** Taking turns in different conversations instead of shouting at one person repeatedly

#### 4. Adaptive Concurrency (AIMD)
**What it does:** Automatically slows down when getting 429 (rate limit) or 503 (server busy) errors, speeds up when successful

**Why it works:** Backs off when caught, mimics how browsers retry. WAFs see "this client respects our limits"

**Simple analogy:** Slowing down when traffic is congested, speeding up on open roads

#### 5. Retry with Exponential Backoff
**What it does:** When a request fails, waits 1s, then 2s, then 4s before retrying

**Why it works:** Legitimate clients retry gracefully. Bots often hammer immediately or give up

**Simple analogy:** Knocking on a door, waiting longer each time instead of banging continuously

#### 6. No Scanner Fingerprints
**What it does:** Doesn't send headers like `X-Scanner: ApiHunter` or predictable patterns
ツールをダウンロード