Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
akto — 开源的 API 安全平台,用于持续的 API 发现、漏洞测试和运行时威胁检测。与 CI/CD 流水线集成,覆盖 OWASP Top 10,内置 1000+ 项测试。 | Kitploit
工具/GitHubGitHub/akto-api-security/akto
漏洞扫描器API安全测试Web安全DevSecOpsAPI 安全
GitHubakto-api-security/akto

akto

开源的 API 安全平台,用于持续的 API 发现、漏洞测试和运行时威胁检测。与 CI/CD 流水线集成,覆盖 OWASP Top 10,内置 1000+ 项测试。

查看仓库
1.5k287696小时49分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
网站
分享
<a href="https://artifacthub.io/packages/search?repo=akto" _target="blank">
  <img src="https://img.shields.io/endpoint?url=https://artifacthub.io/badge/repository/akto"/>
</a>  


<a href="https://www.akto.io/blog/akto-takes-center-stage-at-black-hat-2023-in-las-vegas" _target="blank">
  <img src="https://img.shields.io/badge/Black_Hat_Arsenal-USA_2023-blue?style=square"/>
</a>  


<a href="https://www.akto.io/blog/akto-presentation-at-defcon-2023-in-las-vegas" _target="blank">
  <img src="https://img.shields.io/badge/Defcon-USA_2023-blue?style=square"/>
</a>  

<br/> 
<a href="https://github.com/akto-api-security/akto/commits/master" _target="blank">
  <img src="https://img.shields.io/github/commit-activity/m/akto-api-security/akto?label=commits&amp;logo=github"/>
</a>  

<a href="https://github.com/akto-api-security/akto/releases" _target="blank">
  <img src="https://img.shields.io/github/release-date/akto-api-security/akto?label=latest%20release&amp;logo=docker"/>
</a>

<a href="https://discord.gg/Wpc6xVME4s" _target="blank">
  <img src="https://img.shields.io/discord/1070706429402562733?logo=Discord"/>
</a>

<a href="https://hub.docker.com/r/aktosecurity/akto-api-security-dashboard/tags?page=1&name=local" _target="blank">
  <img src="https://img.shields.io/docker/image-size/aktosecurity/akto-api-security-dashboard?logo=docker"/>
</a>

<a href="https://github.com/akto-api-security/akto/issues?q=label%3Ahackfest" _target="blank">
  <img src="https://img.shields.io/github/issues/akto-api-security/akto/hackfest?logo=github"/>
</a>

<!--a href="https://hub.docker.com/r/aktosecurity/akto-api-security-dashboard" _target="blank">
  <img src="https://img.shields.io/docker/pulls/aktosecurity/akto-api-security-dashboard?logo=docker"/>
</a-->


<a href="https://hub.docker.com/r/aktosecurity/akto-api-security-dashboard" _target="blank">
  <img src="https://img.shields.io/badge/Docker_pulls-10K+-blue?logo=docker"/>
</a>


# Akto.io API 安全

## 贡献者
<a href="https://github.com/akto-api-security/akto/graphs/contributors">
  <img src="https://contrib.rocks/image?repo=akto-api-security/akto" />
</a>


# 什么是 Akto?

[工作原理](https://docs.akto.io/#how-it-works) • [快速开始](https://docs.akto.io/#how-to-get-started) • [API 资产清单](https://docs.akto.io/api-inventory/api-collections) • [API 测试](https://docs.akto.io/testing/run-test) • [添加测试](https://docs.akto.io/testing/test-library) • [加入 Discord 社区](https://discord.com/invite/Wpc6xVME4s) •

Akto 是一个即时、开源的 API 安全平台,只需 60 秒即可上手。安全团队使用 Akto 持续维护 API 资产清单、测试 API 漏洞并发现运行时问题。Akto 覆盖了所有 OWASP Top 10 和 HackerOne Top 10 类别,包括 BOLA、身份验证、SSRF、XSS、安全配置等。Akto 强大的测试引擎通过读取流量数据来理解 API 流量模式,从而运行各种业务逻辑测试,减少误报。Akto 可以集成多种流量来源——burpsuite、AWS、postman、GCP、网关等。以下是本季度的[公开路线图](https://github.com/orgs/akto-api-security/projects/8)。

Akto 通过以下三件事帮助安全和工程团队保护其 API:

1. [API 资产清单](https://docs.akto.io/api-inventory/api-collections)
2. [在 CI/CD 中运行业务逻辑测试](https://docs.akto.io/testing/run-test)
3. [发现运行时漏洞](https://docs.akto.io/api-inventory/sensitive-data)

https://user-images.githubusercontent.com/91306853/216407351-d18c396b-5cd0-4cbc-a350-10a76b1d67b3.mp4

## 它是如何工作的?

步骤 1:创建资产清单

<figure><img src="https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg" alt=""><figcaption></figcaption></figure>

步骤 2:运行测试

<figure><img src="https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg" alt=""><figcaption></figcaption></figure>

## 如何开始?

### 使用 docker-compose(适用于任何安装了 Docker 的机器)
运行以下命令来安装 Akto。你需要安装 curl 和 Docker 才能运行容器。
1. 使用此命令克隆 Akto 仓库 `git clone https://github.com/akto-api-security/akto.git`
2. 进入克隆的目录 `cd akto` 
3. 运行 `docker-compose up -d`
<details>
  <summary><h4>如果你要在自己的云环境(AWS/GCP/Heroku)中进行设置,请阅读本节</h4></summary>

请确保以下事项,以遵循良好的安全实践:
1. 仅开放端口 9090 的入站安全规则,并将源 CIDR 限制为 VPC CIDR 或你的 IP。 
2. 使用私有子网中的 EC2—— 
    
    a. 这样,任何人都无法向你的机器发起入站请求。 
    
    b. 确保此私有子网可以访问互联网,以便出站调用能够成功!
    
    c. 你可能需要设置隧道以便通过 VPN 访问实例,使用 `ssh -i pemfile ec2-user@vpn-public-instance -L 9090:private-instance:9090`
    
    d. 在浏览器中访问 `http://private-instance:9090`

3. 使用公共子网中的 EC2——请勿这样做!如果你仍想这样做,可以跳过 2.b 和 2.c。直接通过 `http://ip:9090` 访问你的实例即可

如果你能为你的应用程序提供镜像流量(零性能影响),Akto 在云部署中会非常强大。你还能够在 CI/CD 中安排测试,并在仪表板上邀请更多团队成员。为此,你应该安装[此处](https://stairway.akto.io)提供的 Akto 企业版。在[此处](https://www.akto.io/pricing)了解更多信息

</details>  

## API 安全测试教程

| 标题 | 链接 |
| ------------- | ------------- |
| 介绍 | https://www.youtube.com/watch?v=oFt4OVmfE2s |
| **教程 1:** SSRF 端口扫描(OWASP API7:2023) | https://www.youtube.com/watch?v=WjNNh6asAD0 |

## 开发与贡献

<details>
  <summary><h3>使用 VSCode Devcontainers 快速搭建</h3></summary>

### 前提条件:

1. [安装 VSCode](https://code.visualstudio.com/)
2. [安装 VSCode Dev Containers 扩展](https://marketplace.visualstudio.com/items?itemName=ms-vscode-remote.remote-containers)  
3. **Windows:** Windows 10 专业版/企业版上的 [Docker Desktop](https://www.docker.com/products/docker-desktop) 2.0+。Windows 10 家庭版(2004+)需要 Docker Desktop 2.3+ 和 [WSL 2 后端](https://aka.ms/vscode-remote/containers/docker-wsl2)。 
4. **macOS:** [Docker Desktop](https://www.docker.com/products/docker-desktop) 2.0+。
5. **Linux:** [Docker CE/EE](https://docs.docker.com/install/#supported-platforms) 18.06+ 和 [Docker Compose](https://docs.docker.com/compose/install) 1.21+。

**注意**:如果使用 Docker Desktop,建议将内存分配更改为 8 GB 以获得更好的性能  
  
### 步骤:

#### 克隆仓库并在 vscode 中打开

1. 打开终端
2. `mkdir ~/akto_code`
3. `cd ~/akto_code`
4. `git clone https://github.com/akto-api-security/akto`
5. 在 VScode 中打开:`code akto`

#### 启动 Dev Container

1. 转到“查看”>“命令面板”,然后输入:Dev Containers: Reopen in Container
<img src="https://assets.kitploit.com/production/public/readmes/6063/55316a486d156017f3282896483e4ec8fa41a3f3a65bb3f8987ca169e55451ac.png"></img>
2. 等待 Dev Container 完成设置。
3. 在浏览器中打开 **localhost:9090** 以查看 Akto 仪表板

</details>


<details>
  <summary><h3> 手动安装说明</h3> </summary>

### 前提条件
OpenJDK 8、node(v18.7.0+ [链接](https://nodejs.org/download/release/v18.7.0/))、npm(v8.15.0+)、maven(v3.6.3 [链接](https://dlcdn.apache.org/maven/maven-3/3.6.3/binaries/))、MongoDB(v5.0.3+ [链接](https://www.mongodb.com/docs/manual/administration/install-community/))


#### 克隆仓库
1. `mkdir ~/akto_code`
2. `cd akto_code`
3. `git clone https://github.com/akto-api-security/akto`

#### 设置数据库

1. `打开一个新的终端标签页`
2. `cd ~`
3. `mkdir ~/akto_mongo_data`
4. `<path_to_mongo_folder>/bin/mongod --dbpath ~/akto_mongo_data`

#### 设置前端

1. `打开一个新的终端标签页`
2. `cd ~/akto_code/akto`
3. `cd apps/dashboard/web/polaris_web`
4. `npm install`
5. `npm run hot`

#### 设置仪表板

1. `打开一个新的终端标签页`
2. `cd ~/akto_code/akto`
3. `export AKTO_MONGO_CONN="mongodb://localhost:27017"`
4. `export DASHBOARD_MODE="local_deploy"`
5. `mvn clean install`
6. `mvn --projects :dashboard --also-make jetty:run -Djetty.port=9090`

#### 设置测试

1. `打开一个新的终端标签页`
2. `cd ~/akto_code/akto`
3. `cd apps/testing`
4. `export AKTO_MONGO_CONN="mongodb://localhost:27017"`
5. `mvn compile; mvn exec:java -Dexec.mainClass="com.akto.testing.Main"`

  </details>  
  
#### 使用 Testing CLI 工具

运行以下命令以运行测试 CLI 工具

```bash
docker run -v ./:/out  \ # needed to generate test report on host machine
    -e TEST_IDS='JWT_NONE_ALGO REMOVE_TOKENS' \ # space separated test ids
    -e AKTO_DASHBOARD_URL='<AKTO_DASHBOARD_URL>' \ 
    -e AKTO_API_KEY='<AKTO_API_KEY>' \ 
    -e API_COLLECTION_ID='123' \ # api collection id on which you want to run tests
    -e TEST_APIS='https://demo.com/api/books https://demo.com/api/cars' \ # space separated apis from the api collection on which you want to run tests. If not present, all apis in the collection will be tested. [optional]
    -e OVERRIDE_APP_URL='https://dummy.com' \ # If you want to test on a separate host. [optional] 
    aktosecurity/akto-api-testing-cli
```

### 动手试试

1. 在你喜欢的浏览器中打开 `localhost:9090`
2. 首次登录时需要注册,之后就可以直接登录了

<details>  
  <summary><h3>调试</h3></summary>
1. 要调试前端,请从[此处](https://devtools.vuejs.org/guide/installation.html)安装 Vue.js Chrome 扩展。
2. 要调试后端,请在运行 Web 服务器之前执行以下操作—— 
  a. 设置 MAVEN_OPTS 变量以在 Java 进程中启用调试
        
        export MAVEN_OPTS="-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=8081, -Dcom.sun.management.jmxremote=true -Dcom.sun.management.jmxremote.port=9010 -Dcom.sun.management.jmxremote.rmi.port=9010 -Dcom.sun.management.jmxremote.local.only=false -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
        
  b. 在 Visual Studio Code 中,单击任意行号以设置断点。
    
  c.  从“运行和调试”模式附加 Java 调试器。如果是第一次操作,请单击“Create launch.json file”,然后选择“Add configuration”。选择“Java: Attach process by ID”并保存文件。 <br/>
     <img width="426" alt="img1" src="https://assets.kitploit.com/production/public/readmes/6063/8066e85fcd60acda23d905ff2a64969cb39d640cff06738418d0f4d4d864b990.png"><br/>
  d. 将会显示正在运行的 Java 进程列表。选择 Web 服务器进程以附加调试器

</details>  
<a href="https://hits.sh/github.com/akto-api-security/hits.svg?label=Hits%20since%2020%2F5&color=FFFFFF&labelColor=FFFFFF"><img alt="Hits" src="https://hits.sh/github.com/akto-api-security/hits.svg?label=Hits%20since%2020/5&amp;color=FFFFFF&amp;labelColor=FFFFFF"/></a> 
  
## 贡献

我们欢迎您对本项目的贡献。请阅读我们的 [CONTRIBUTING.md](https://github.com/akto-api-security/akto/blob/master/CONTRIBUTING.md) 以了解如何参与。

## 许可证

本项目采用 [MIT 许可证](https://github.com/akto-api-security/akto/blob/master/LICENSE.md) 授权。
下载工具