An automated tool for API Reconnaissance and Vulnerability Assessment. Designed for SOC analysts and penetration testers to quickly identify PII leaks, BOLA vulnerabilities, and security misconfigurations.
No complex setup required.
- Download this repository (Code -> Download ZIP).
- Double-click
one_click_start.bat.- This will automatically install Python dependencies (
requirements.txt) and launch the dashboard.
- This will automatically install Python dependencies (
(Requires Python 3.10+ installed on your system)
- Recursion Engine: Find hidden endpoints other scanners miss.
- PII Detection: Auto-flags Emails, SSNs, Credit Cards, and API Keys.
- Analyst Reports: Generates "Plain English" reports ready for Jira/Teams.
- Active Verification: Built-in playbooks for validating BOLA and SSRF.
- Windows 10/11
- Python 3.10 or newer
Open a Pull Request! We love community tools.
MIT