View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0009719 | Kali Linux | New Tool Requests | public | 2026-05-29 20:31 | 2026-05-29 20:37 |
| Reporter | glichx | Assigned To | |||
| Priority | normal | Severity | minor | Reproducibility | have not tried |
| Status | new | Resolution | open | ||
| Summary | 0009719: [New Tool Request] apicg - High-performance asynchronous API Attack Surface Mapper | ||||
| Description | Tool Information
Descriptionapicg is a high-performance, asynchronous API attack surface mapping utility designed for penetration testers and bug bounty hunters. It combines passive JavaScript/Specification analysis with highly concurrent active endpoint fuzzing. Unlike older tools that pull massive amounts of third-party noise (such as Google Analytics, Tag Manager, and tracking pixel routes), apicg uses an active in-scope validation system to strip away tracking junk dynamically, leaving security teams with a clean, actionable blueprint of the actual target API routes. Features
Target Category in Kali Menu03-web-applications -> Web Application Analysis Technical JustificationModern web applications are heavily reliant on APIs, which traditionally requires testers to manually crawl bundles or use heavy intercepting proxies. apicg bridges this gap natively inside a lightweight CLI tool. It follows standard Python packaging rules (setup.py entry points) and can easily be packaged into a native Debian (.deb) binary for distribution within the Kali ecosystem. | ||||
| Attached Files | |||||