metlo v1.0.1 releases: open-source API security platform
Metlo
Metlo is an open-source API security platform
- Create an Inventory of all your API Endpoints.
- Proactively test your APIs before they go into production.
- Detect API attacks in real-time.
Features
- Endpoint Discovery – Metlo scans network traffic and creates an inventory of every single endpoint in your API.
- Sensitive Data Scanning – Each endpoint is scanned for PII data and given a risk score.
- Vulnerability Discovery – Get Alerts for issues like unauthenticated endpoints returning sensitive data, No HSTS headers, PII data in URL params, Open API Spec Diffs and more
- API Security Testing – Build security tests directly in Metlo with a simple HTTP Request editor and javascript assertions.
- CI/CD Integration – Integrate with your CI/CD to find issues in development and staging.
- Attack Detection – Our ML Algorithms build a model for baseline API behavior. Any deviation from this baseline is surfaced to your security team as soon as possible. (Coming Soon)
- Attack Context – Metlo’s UI gives you full context around any attack to help quickly fix the vulnerability. (Coming Soon)
Why Metlo?
Most businesses have adopted public facing APIs to power their websites and apps. This has dramatically increased the attack surface for your business. There’s been a 200% increase in API security breaches in just the last year with the APIs of companies like Uber, Meta, Experian and Just Dial leaking millions of records. It’s obvious that tools are needed to help security teams make APIs more secure but there’s no great solution on the market.
Some solutions require you to go through sales calls to even try the product while others have you to send all your API traffic to their own cloud. Metlo is the first Open Source API security platform that you can self host, and get started for free right away!
Changelog v1.0.1
-
[Go] Don’t try to reconnect to metlo agent (#522)
Install & Use
Copyright (c) 2022 S2 Labs Inc.