Nicolas Southern
Nicolas Southern
← Back to Cyber

Cyber Tool

API Griffer

A Python API fuzzing tool with a live demo target for finding hidden REST-style routes, testing HTTP methods, and writing structured findings. Authorized testing only.

Overview

API Griffer focuses on repeatable route discovery for REST-style APIs. It combines generated path candidates, multiple HTTP methods, noise filtering, and structured output so testing sessions can move from broad discovery to focused review.

Highlights

Python CLI for API endpoint fuzzing and method-aware route discovery.

Custom headers, query strings, request bodies, proxying, concurrency, and structured findings.

A deployable sample service so the workflow feels like a real API.

Built for authorized testing and OSWE-style white-box work.

Workflow

Route Discovery

Build candidate paths from wordlists, test nested routes, and compare how endpoints respond across HTTP methods.

Reviewable Findings

Capture results in a structured format so interesting responses can be reviewed, repeated, and shared during authorized testing.

Demo Target

The companion sample service gives the tool a realistic target for demos, lab work, and regression checks.

Tech Stack

Python
Requests
Next.js
React
TypeScript
Vitest
Docker
GitHub Actions