Kiterunner Logo

Kiterunner

0
Free
Visit Website

For the longest of times, content discovery has been focused on finding files and folders. While this approach is effective for legacy web servers that host static files or respond with 3xx’s upon a partial path, it is no longer effective for modern web applications, specifically APIs. Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications. Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values. When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered. By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters.

FEATURES

ALTERNATIVES

ConDroid performs concolic execution of Android apps to observe 'interesting' behavior in dynamic analysis.

An Application Security Posture Management platform that provides visibility, security controls, and automated workflows across the software development lifecycle from code to cloud.

A tool to conduct preliminary security checks in code, infrastructure, or IAM configurations using various open-source tools.

A collection of mobile security resources with tools, white papers, ebooks, and webinars.

A fast and minimal JS endpoint extractor

Guidelines for secure coding in Java SE to avoid bugs that could weaken security and open holes in Java's security features.

Yaramod is a library for parsing YARA rules into AST and building new YARA rulesets with C++ programming interface.

An ASPM platform that provides software supply chain security through risk assessment, prioritization, and protection mechanisms.