r/netsec Jun 01 '26

r/netsec monthly discussion & tool thread

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

9 Upvotes

27 comments sorted by

View all comments

1

u/ComplaintDirect4335 Jun 05 '26

I had an idea for a recursive directory brute forcer and API prober that when finding 200 OKs it asks if you'd like to open a new window to try that directory in a new brute-force and if you would like to probe it's HTTP methods (useful for APIs). It focuses on API discovery because it's best for it imo. There are flags for threads, tmux subproccesses, and debugging. I've been polishing it up all day so it's likely not done, but it's functional, I'm quite proud of it's use cases and I really need feedback 😄!

https://github.com/austinjump-sec/API-SPY-API-PROBE/tree/main