|
24 | 24 |
|
25 | 25 | </div> |
26 | 26 |
|
27 | | -**GraphQLNomad** is a powerful all-in-one command-line tool designed for security researchers, penetration testers, bug bounty hunters, and developers. It automates the entire GraphQL reconnaissance workflow - from discovering hidden endpoints to fingerprinting the underlying engine and exploring schemas through an intuitive interactive shell. |
| 27 | +**GraphQLNomad** is a powerful all-in-one command-line tool designed for security researchers, penetration testers, bug bounty hunters, and developers. |
| 28 | + |
| 29 | +It automates the entire GraphQL reconnaissance workflow - from discovering hidden endpoints to fingerprinting the underlying engine and exploring schemas through an intuitive interactive shell. |
28 | 30 |
|
29 | 31 | ## ✨ Key Features |
30 | 32 |
|
|
36 | 38 | ### 🔬 Engine Fingerprinting |
37 | 39 | * **Technology Identification**: Automatically identifies the underlying GraphQL engine and its technology stack |
38 | 40 | * **Supported Engines**: |
39 | | - - **Apollo Server** (Node.js, JavaScript) |
40 | | - - **Graphene** (Python, Django, Flask) |
41 | | - - **Hot Chocolate** (.NET, C#) |
42 | | - - **Hasura** (Go, Haskell) |
| 41 | + - **Apollo Server** (Node.js, JavaScript) |
| 42 | + - **Graphene** (Python, Django, Flask) |
| 43 | + - **Hot Chocolate** (.NET, C#) |
| 44 | + - **Hasura** (Go, Haskell) |
43 | 45 | * **Behavioral Analysis**: Uses multiple fingerprinting techniques including error signatures, headers, and response patterns |
44 | 46 |
|
45 | 47 | ### 📊 Schema Introspection |
@@ -263,6 +265,7 @@ Example wordlist format: |
263 | 265 | View all GraphQL engines that can be fingerprinted: |
264 | 266 |
|
265 | 267 | ```bash |
| 268 | +# Note: A URL is required but can be any placeholder when using --list-engines |
266 | 269 | graphqlnomad --list-engines https://example.com |
267 | 270 | ``` |
268 | 271 |
|
|
0 commit comments