Imperva API Security is an API protection solution that provides continuous monitoring and security for APIs across cloud, on-premises, and hybrid environments. The tool performs automated discovery and classification of public, private, and shadow APIs to maintain a comprehensive API inventory. It includes capabilities for identifying design flaws and vulnerabilities associated with OWASP API Security Top 10. Key functionalities include: - Continuous API discovery and risk assessment - Detection of business logic vulnerabilities like Broken Object Level Authorization (BOLA) - Integration with WAF and bot protection systems - Support for both agent-based and agentless deployment options - API traffic inspection across encrypted applications and microservices - Classification of APIs based on sensitivity and data types - Integration capabilities with API gateways and management platforms The solution can be deployed as: - Cloud-managed through Imperva Cloud WAF - Self-managed via local management console - API Security Add-on for existing Imperva WAF users It provides monitoring for both north-south and east-west API traffic, enabling organizations to maintain visibility and security across their entire API infrastructure.
FEATURES
ALTERNATIVES
BunkerWeb is a next-generation and open-source Web Application Firewall (WAF) with seamless integration and user-friendly customization options.
A web application firewall solution that monitors, filters, and protects web applications from malicious traffic and common web-based attacks.
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
An application security platform that provides runtime threat modeling, vulnerability management, and automated remediation workflows with a focus on identifying exploitable vulnerabilities in production environments.
An Application Security Posture Management platform that provides visibility, security controls, and automated workflows across the software development lifecycle from code to cloud.
A tool for identifying potential security vulnerabilities in web applications
A security feature to prevent unexpected manipulation of fetched resources.
Scan files for viruses and malware with language-agnostic REST API
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

PTJunior
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.