Submit your favorite resources for free.

Submit
LogoHackDB
icon of graphw00f

graphw00f

Graphw00f is a GraphQL server engine fingerprinting tool. It identifies backend technologies and security defenses by analyzing unique endpoint responses.

Introduction

graphw00f is a GraphQL fingerprinting tool designed for security professionals. It identifies GraphQL server engines by sending benign and malformed queries, analyzing unique responses to distinguish implementations. Key features include:

  • Engine Detection: Identifies various GraphQL engines like Graphene, Apollo, and WPGraphQL.
  • Threat Matrix Integration: Uses the GraphQL Threat Matrix to provide insights into security features and CVEs.
  • Customizable Headers: Supports custom headers and cookies for specific endpoints.
  • Detection & Fingerprinting Modes: Detects GraphQL endpoints and fingerprints the engine in one go.

Use cases include:

  • Identifying the technology stack behind a GraphQL endpoint.
  • Assessing the security posture of GraphQL implementations.
  • Guiding security engineers in understanding potential vulnerabilities.

Information

  • Publisher
  • Websitegithub.com
  • Created date04/11/2025
  • Published date04/11/2025

Categories

Tags

215+ Subscribers
Newsletter

Join 215+ Professionals

Receive our monthly newsletter featuring the latest additions to the directory.

No spam. Unsubscribe anytime.