Security tool · discovery

kiterunner

Context-aware content discovery built for APIs. Uses real request templates (from 67k+ Swagger specs) instead of dumb path lists, catching routes that need specific methods/headers.

apicontent-discoveryroutesassetnote
Stable IDtool:kiterunnerLast updatedLast verifiedLegacy review pendingProvenanceSource-linked

Where kiterunner fits

Context-aware content discovery built for APIs. Uses real request templates (from 67k+ Swagger specs) instead of dumb path lists, catching routes that need specific methods/headers.

Detection-first use

Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.

Installation references

Install with releaseAuthorization required
wget https://github.com/assetnote/kiterunner/releases/latest/download/kiterunner_linux_amd64.tar.gz && tar -xzf kiterunner_linux_amd64.tar.gz
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Command templates

Scan with routesAuthorization required

Populate placeholders only with assets that are explicitly in scope.

kr scan {url} -w {routes} -x {threads}
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Continue the workflow

Attribution and verification

Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.