Skip to main content

vamp-api-probe

Python 3.9+ Platform License AGPL-3.0 VampSecure Labs

Overview

vamp-api-probe is a DAST (Dynamic Application Security Testing) scanner for modern REST APIs, aligned with the OWASP API Security Top 10 2023. It probes live API endpoints for broken object-level authorization (BOLA), broken function-level authorization (BFLA), mass assignment vulnerabilities, absent rate limiting, authentication weaknesses, exposed administrative endpoints, security header misconfigurations, and legacy version exposure. It can operate against a bare base URL with automatic endpoint discovery or drive its test suite from an OpenAPI/Swagger specification for complete endpoint coverage.

Features

  • API1 — BOLA (Broken Object Level Authorization): enumerates numeric path parameters (±1, ±10, ±100, and common IDs), compares authenticated vs unauthenticated responses to detect cross-user data leakage (CRITICAL/HIGH)
  • API2 — BFLA (Broken Function Level Authorization): probes every endpoint without Authorization header and tests privileged HTTP methods (DELETE, PUT, PATCH) for missing access control (CRITICAL/HIGH)
  • API3 — Mass Assignment: injects admin-escalation fields (isAdmin, role, is_superuser, verified, balance, credits) in POST/PUT/PATCH bodies and checks whether the API accepts them (CRITICAL)
  • API4 — Rate Limiting: fires a configurable burst of requests against the same endpoint and flags absence of HTTP 429 responses (HIGH)
  • API5 — Broken Authentication: tests manipulated JWT tokens (single-character mutation) and expired JWT detection to identify missing token validation (CRITICAL)
  • API6 — Sensitive Business Flows: detects administrative and debug endpoints (/admin, /internal, /debug, /actuator, /metrics, /env, /_debug) accessible without authentication (HIGH)
  • API8 — Security Misconfiguration: audits response headers (X-Content-Type-Options, X-Frame-Options, Strict-Transport-Security, Content-Security-Policy) and checks for stack trace exposure via malformed input (MEDIUM)
  • API9 — Improper Inventory Management: probes legacy API versions (e.g. /v1/ when target is /v2/) for unretired endpoints (MEDIUM)
  • OpenAPI/Swagger spec ingestion (YAML or JSON) for automatic endpoint and schema discovery
  • Fallback endpoint discovery against common REST paths when no spec is provided
  • Bearer token support for authenticated test passes
  • Configurable per-request timeout and rate-limit burst size
  • Export to Console (Rich), JSON, and HTML (dark-theme)
  • VSL unified client report (HTML + optional PDF via fpdf2)

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0
  • aiohttp >= 3.8.0
  • pyyaml >= 6.0
  • Optional: fpdf2 >= 2.7 for --report-pdf

Installation

pip install vamp-api-probe
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-api-probe
git clone https://github.com/Vampsecure-Labs/vamp-api-probe.git
cd vamp-api-probe
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

vamp-api-probe scan --help
usage: vamp-api-probe scan --url URL
                            [--spec OPENAPI_FILE]
                            [--token BEARER_TOKEN]
                            [--no-auth-tests]
                            [--timeout SECONDS]
                            [--rate-limit-burst N]
                            [--json FILE] [--html FILE]
                            [--client CLIENT] [--engagement ENGAGEMENT]
                            [--auditor AUDITOR] [--report-scope SCOPE]
                            [--report-html FILE] [--report-pdf FILE]

vamp-api-probe — REST API DAST Scanner (VampSecure Labs)

Examples

# Scan a public API with automatic endpoint discovery
vamp-api-probe scan --url https://api.ejemplo.com/v1

# Scan with an OpenAPI spec for full endpoint coverage
vamp-api-probe scan --url https://api.ejemplo.com/v1 --spec openapi.yaml

# Authenticated scan with a Bearer token
vamp-api-probe scan --url https://api.ejemplo.com/v1 --token eyJhbGciOiJIUzI1NiJ9...

# Skip tests that require a second user account
vamp-api-probe scan --url https://api.ejemplo.com/v1 --no-auth-tests

# Custom timeout and rate-limit burst
vamp-api-probe scan --url https://api.ejemplo.com/v1 --timeout 15 --rate-limit-burst 30

# Export findings to JSON and dark-theme HTML
vamp-api-probe scan --url https://api.ejemplo.com/v1 --json results.json --html report.html

# Generate client-ready engagement report (HTML + PDF)
vamp-api-probe scan --url https://api.ejemplo.com/v1 \
    --client "Acme Corp" --engagement "API Security Assessment Q4 2026" \
    --auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf

CLI Reference

Flag Default Description
--url URL (required) Base URL of the API under test
--spec FILE — OpenAPI/Swagger YAML or JSON spec for endpoint discovery
--token TOKEN — Bearer token for authenticated requests
--no-auth-tests off Skip tests that require a second-user context
--timeout N 10 Per-request timeout in seconds
--rate-limit-burst N 20 Number of rapid requests for rate-limit test
--json FILE — Export results to JSON
--html FILE — Export dark-theme HTML report
--client TEXT — Client name for VSL engagement report
--engagement TEXT — Engagement title for VSL engagement report
--auditor TEXT — Auditor name for VSL engagement report
--report-scope TEXT — Scope description for VSL engagement report
--report-html FILE — Export unified VSL client report (HTML)
--report-pdf FILE — Export unified VSL client report (PDF, requires fpdf2)

Output Formats

Format Flag Description
Console (default) Rich progress and findings table with OWASP API Top 10 mapping
JSON --json FILE Machine-readable full result set
HTML --html FILE Dark-theme standalone report
Client HTML --report-html FILE Unified VampSecure Labs engagement report
Client PDF --report-pdf FILE PDF version of the VSL client report

OWASP API Top 10 Coverage

ID Category Severity
API1:2023 Broken Object Level Authorization (BOLA) CRITICAL / HIGH
API2:2023 Broken Function Level Authorization (BFLA) CRITICAL / HIGH
API3:2023 Broken Object Property Level Authorization / Mass Assignment CRITICAL
API4:2023 Unrestricted Resource Consumption (Rate Limiting) HIGH
API5:2023 Broken Function Level Authorization / Broken Authentication CRITICAL
API6:2023 Unrestricted Access to Sensitive Business Flows HIGH
API8:2023 Security Misconfiguration MEDIUM
API9:2023 Improper Inventory Management MEDIUM

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 CRITICAL or HIGH findings detected Pipeline fails — review required
2 Connection or configuration error Pipeline fails — check target

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-api-probe is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-api-probe 1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-api-probe 1.0
File Size Uploaded
vamp_api_probe-1.0.tar.gz 30.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-api-probe 1.0
File Interpreter ABI Platform
vamp_api_probe-1.0-py3-none-any.whl Python 3 none any Details

Total release size: 62.8 kB

Release files / vamp_api_probe-1.0.tar.gz

Download URL vamp_api_probe-1.0.tar.gz
Size 30.6 kB
Tags Source
SHA-256 checksum
How to use checksums
73d7f3a9f13e8fd3393068c870e81bede1ea7f39d80d2265683c0b9585853dcc
BLAKE2b-256 checksum
How to use checksums
ed9ba7b07928877ed163845dc90a4787639677305e6a29c7a988d7141ad0cee4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_api_probe-1.0-py3-none-any.whl

Download URL vamp_api_probe-1.0-py3-none-any.whl
Size 32.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e69d209fe628a6fea3dfc83f2989120f13c02fd562df5e3394ce08572f85331b
BLAKE2b-256 checksum
How to use checksums
52eaac2bb1a6bbccca5f91be74d4e3abeb477ac5389476c006cab9512b6c8bd0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page