Meet Vespasian. It Sees What Static Analysis Can’t.
ID: d02f52b4-adeb-5c21-b5fc-d58fd6ddfe3e
STIX ID: report--d02f52b4-adeb-5c21-b5fc-d58fd6ddfe3e
Feed Name: Security Boulevard
Vespasian is an open-source tool from Praetorian that captures HTTP traffic (via a headless browser or imported proxy captures) to automatically discover and generate API specifications (OpenAPI for REST, GraphQL SDL, and WSDL for SOAP). The post describes Vespasian's two-stage capture-and-generate pipeline, classification heuristics for REST/GraphQL/SOAP, probing and normalization behaviors, integration with Burp Suite and Hadrian for end-to-end testing, usage examples, and FAQs; it is an informational product announcement for offensive security tooling, not a report of an incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
