
Rust製の非同期APIセキュリティスキャナー。CORS、CSP、GraphQL、JWT、OpenAPI、およびアクティブなAPIセキュリティ態勢チェック用。
このプロジェクトがあなたの作業に役立つなら、継続的なメンテナンスと新機能の開発をサポートしてください。
ETH 寄付ウォレット
0x11282eE5726B3370c8B480e321b3B2aA13686582
上記のQRコードをスキャンするか、ウォレットアドレスをコピーしてください。
API のベースラインテストと回帰検出のための、非同期・モジュール式 API セキュリティスキャナー。
適応型並行処理と CI 対応出力(NDJSON/SARIF)を用いて、探索とターゲットを絞ったチェック(CORS/CSP/GraphQL/OpenAPI/JWT/API Security)を組み合わせます。
ユースケース: 攻撃側ではレッドチーム/API ペネトレーションテストの探索とエクスプロイト検証、防御側では CI/CD 回帰ゲート、継続的な API ハードニング、早期の設定ミス検出。
大規模スキャンをお考えですか? Triage Mode を参照 — コアセキュリティチェックで 20 分間に 5000 ターゲットをスキャンし、その後 Enrich Mode を使用して脅威インテリジェンスのコンテキスト(ポート、CVE、ASN、ドメインの経過期間)を検出結果に追加できます。
ApiHunterapihunterapi_scannerapihunter(cargo run のデフォルト)見つけやすくするために、GitHub リポジトリの設定でこれらを設定してください:
CORS/CSP/GraphQL/JWT/OpenAPI とアクティブな API 姿勢チェックのための非同期 API セキュリティスキャナー。https://github.com/Teycir/ApiHunterrust, security, api-security, scanner, graphql, cors, csp, jwt, openapi, sarif, ndjsonflowchart LR A[CLI apihunter] --> B[main.rs] D[Input Sources] --> E[Pre-filter + Discovery] B --> C[HttpClient + Config] E --> F[runner.rs] C --> F
F --> G1[Passive scanners]
F --> G2[Active scanners]
I[template-tool] --> H[CVE templates]
H --> G2
G1 --> J[Findings]
G2 --> J
J --> K[Reporter]
K --> L[Auto Reports]
K --> M[CI/CD Controls]
## Why ApiHunter?
### Core Advantages
- **API-First Architecture**: Purpose-built for REST/GraphQL APIs, not adapted from web app scanners
- **Intelligent False Positive Reduction**:
- SPA catch-all detection with canary probing
- Context-aware secret validation (frontend vs backend)
- Body content validation and referer checking
- Response fingerprinting to skip duplicate findings
- **Production-Safe by Design**:
- Adaptive concurrency (AIMD) that backs off on errors
- Per-host rate limiting with configurable delays
- Politeness controls (retries, timeouts, WAF evasion)
- Dry-run mode for active checks
- **Stealth & Evasion**:
- Runtime User-Agent rotation from curated pool (assets/user_agents.txt)
- Randomized request delays with jitter
- Per-host delay enforcement (avoids burst patterns)
- Retry logic with exponential backoff
- Custom header injection for blending with legitimate traffic
- Adaptive timing based on server responses
- No hardcoded scanner fingerprints in default mode
### Stealth Techniques Deep Dive
ApiHunter uses several stealth techniques to avoid detection by WAF (Web Application Firewall) and bot protection systems:
#### 1. User-Agent Rotation
**What it does:** Randomly cycles through 100+ real browser User-Agent strings from a file (`assets/user_agents.txt`)
**Why it works:** Bots typically use the same User-Agent (like `curl/7.68.0`). By pretending to be Chrome, Firefox, Safari, etc., you blend in with legitimate traffic
**Simple analogy:** Like wearing different disguises instead of always wearing the same uniform
#### 2. Random Timing & Jitter
**What it does:** Adds random delays between requests (controlled by `--delay-ms`) with jitter (small random variations)
**Why it works:** Bots send requests at perfect intervals (exactly 100ms apart). Humans are unpredictable. Random timing makes traffic look organic
**Simple analogy:** Walking with irregular steps instead of marching like a robot
#### 3. Per-Host Delay Enforcement
**What it does:** Tracks delay separately for each domain, not globally
**Why it works:** Prevents burst patterns where you hit one host 50 times instantly. Each host sees polite, spaced-out requests
**Simple analogy:** Taking turns in different conversations instead of shouting at one person repeatedly
#### 4. Adaptive Concurrency (AIMD)
**What it does:** Automatically slows down when getting 429 (rate limit) or 503 (server busy) errors, speeds up when successful
**Why it works:** Backs off when caught, mimics how browsers retry. WAFs see "this client respects our limits"
**Simple analogy:** Slowing down when traffic is congested, speeding up on open roads
#### 5. Retry with Exponential Backoff
**What it does:** When a request fails, waits 1s, then 2s, then 4s before retrying
**Why it works:** Legitimate clients retry gracefully. Bots often hammer immediately or give up
**Simple analogy:** Knocking on a door, waiting longer each time instead of banging continuously
#### 6. No Scanner Fingerprints
**What it does:** Doesn't send headers like `X-Scanner: ApiHunter` or predictable patterns