REST & GraphQLModern API architectures
AuthenticationOAuth, JWT, API keys
Data ValidationInput/output security
Rate LimitingDoS protection
[ live terminal ]
From a 401 to a finding, in one run.
feron-agent — api.example.com
API Endpoint AnalysisSample report
- Total Endpoints
- 47
- Authenticated
- 32
- Public
- 15
- Vulnerable
- 12
[ what the agent does ]
Four passes over every API, end to end.
01Discovery & Documentation
Identifies all endpoints, parameters and auth mechanisms.
02Authentication & Authorization
Tests token handling and access controls.
03Data Validation & Business Logic
Hunts injection and logic flaws.
04Security Controls Assessment
Rate limiting, encryption, logging.
[ sample finding ]
What lands in your queue.
High
Endpoint GET /api/v1/users/{userId}
Broken Object Level Authorization
The API endpoint allows users to access other users' data by manipulating the userId parameter without proper authorization checks.
[ recommendation ]
Implement proper authorization checks to ensure users can only access their own data or data they have explicit permission to access.
[ coverage: owasp api top 10 ]
The full OWASP API Top 10, and the logic beyond it.
- Broken Object Level Authorization
- Broken Authentication
- Excessive Data Exposure
- Lack of Resources & Rate Limiting
- Broken Function Level Authorization
- Mass Assignment
- Security Misconfiguration
- Injection
- Improper Assets Management
- Insufficient Logging & Monitoring
- Business Logic Flaws
- Insecure Direct Object References
[ api types ]
Whatever your services speak.
REST APIs
- HTTP methods testing
- JSON/XML validation
- Resource-based security
- CORS policies
GraphQL APIs
- Query complexity analysis
- Schema introspection
- Authorization testing
- Batching attacks
SOAP Web Services
- WSDL analysis
- XML injection testing
- WS-Security validation
- SOAP fault handling
Microservices
- Service mesh security
- Inter-service auth
- API gateway testing
- Container security
[ early access ]
Point an agent at your API.