AppCheck API Scanner Logo

AppCheck API Scanner

API vulnerability scanner with support for REST, SOAP, and GraphQL APIs

Application Security
Commercial
Visit website
Claim and verify your listing
0

AppCheck API Scanner Description

AppCheck API Scanner is a dynamic application security testing tool designed to identify vulnerabilities in APIs. The scanner supports multiple API types including REST (JSON), SOAP (WSDL), and GraphQL, providing comprehensive security coverage across different API architectures. The tool performs endpoint discovery through SPA crawling and GraphQL introspection, automatically generating fixture data from Swagger and GraphQL schemas. It includes advanced authentication support, maintaining active sessions and handling various authentication mechanisms such as TOTP and OAuth. The scanner implements request signing capabilities, including HMAC support and AWS v4 request signing, with chainable rules for complex custom signature requirements. It conducts contextual probing of individual API methods and performs payload-based testing to confirm real vulnerabilities. The platform identifies authorization flaws, permission issues such as IDOR (Insecure Direct Object References), and provides comprehensive OWASP vulnerability coverage including injection attacks, XSS, and remote code execution. It supports multi-domain scanning, covering both backend APIs and frontend single-page applications within the same scan. AppCheck provides detailed diagnostic output for manual review and offers remediation guidance based on best practices from OWASP, MITRE, and in-house experts. The scanner can be integrated into the application lifecycle from development through production environments.

AppCheck API Scanner FAQ

Common questions about AppCheck API Scanner including features, pricing, alternatives, and user reviews.

AppCheck API Scanner is API vulnerability scanner with support for REST, SOAP, and GraphQL APIs developed by AppCheck. It is a Application Security solution designed to help security teams with API Security, Authentication, DAST.

Have more questions? Browse our categories or search for specific tools.

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

7
TestSavant AI Security Assurance Platform Logo

AI security assurance platform for red-teaming, guardrails & compliance

5
OSINTLeak Real-time OSINT Leak Intelligence Logo

Real-time OSINT monitoring for leaked credentials, data, and infrastructure

5
Mandos Brief Logo

Weekly cybersecurity newsletter covering security incidents, AI, and leadership

5
View Popular Tools →