📋 Description
THUGSAPI is a comprehensive, enterprise-grade web reconnaissance and security analysis framework designed by SYLHETYHACKVENGER (THE-ERROR808) for professional penetration testers, security researchers, and bug bounty hunters. This powerful tool employs a multi-phase approach to thoroughly analyze web applications, APIs, and infrastructure components, providing deep insights into potential security weaknesses and attack surfaces.
The tool combines passive intelligence gathering with active scanning techniques to deliver a complete security assessment of any web target. From DNS enumeration and subdomain discovery to advanced GraphQL introspection and JWT token analysis, THUGSAPI covers the entire spectrum of web reconnaissance. Its sophisticated evasion mechanisms help bypass WAF protections, rate limiting, and other defensive measures, ensuring thorough coverage even against well-protected targets.
THUGSAPI's architecture is built on a modular, phase-based system that systematically progresses from preparation through reconnaissance, discovery, and deep analysis. Each phase employs specialized techniques and checks, including SSL/TLS validation, WAF detection, subdomain takeover vulnerability identification, CORS misconfiguration analysis, and cache header inspection. The tool automatically handles dependency management, generates detailed JSON reports, and provides real-time logging with color-coded output for enhanced readability.
The framework incorporates advanced security research methodologies and implements cutting-edge reconnaissance techniques. Its ability to detect subdomain takeovers across 17+ platforms, perform GraphQL introspection, decode JWT tokens, and identify CORS misconfigurations makes it an invaluable asset for modern security assessments. The tool's evasion layer ensures successful testing even against heavily protected environments, while its comprehensive reporting capabilities provide actionable intelligence for remediation efforts.
🚀 Key Features
· Multi-Phase Analysis: Systematic approach with 4 distinct phases · WAF Evasion: Advanced techniques to bypass Web Application Firewalls · Subdomain Takeover Detection: Identifies vulnerable subdomains across 17+ platforms · GraphQL Introspection: Extracts full GraphQL schemas · JWT Analysis: Automatic JWT token extraction and decoding · CORS Security Analysis: Detects misconfigurations · WebSocket Discovery: Identifies WebSocket endpoints · Secret Discovery: Finds API keys, tokens, and credentials (18+ types) · DNS & WHOIS Enumeration: Comprehensive domain intelligence · Technology Fingerprinting: Detects frameworks, CMS, and libraries (25+) · Rate Limiting Detection: Identifies throttling mechanisms · Automatic Dependency Management: Self-installing requirements · JSON Reporting: Comprehensive output in structured format
🛡️ Capabilities Dashboard
Category Feature Status Description Phase 0: Preparation URL Validation ✅ Validates URL format and scheme DNS Resolution ✅ Resolves A, AAAA, MX, NS, TXT records SSL/TLS Verification ✅ Validates certificates and protocols WAF Detection ✅ Identifies 10+ WAF solutions Rate Limiting Test ✅ Detects throttling mechanisms Proxy Configuration ✅ Supports HTTP/HTTPS/SOCKS5 proxies Session Management ✅ Configures retries and timeouts User-Agent Rotation ✅ 15+ modern browser user agents Phase 1: Reconnaissance DNS Enumeration ✅ Gathers all DNS record types WHOIS Lookup ✅ Retrieves domain registration info Subdomain Discovery ✅ Enumerates 40+ common subdomains Subdomain Takeover ✅ Detects 17+ takeover patterns Technology Detection ✅ Identifies 25+ frameworks and CMS Security Headers ✅ Analyzes 9+ security headers SSL Certificate ✅ Extracts certificate details Port Scanning ✅ Checks 20+ common ports Third-Party Detection ✅ Identifies CDN, analytics, payments Phase 2: Discovery Directory Bruteforce ✅ Tests 40+ common directories File Discovery ✅ Finds 30+ sensitive files API Endpoint Discovery ✅ Identifies 40+ API endpoints Parameter Discovery ✅ Tests 30+ common parameters Hidden Paths ✅ Finds .git, .env, .aws paths Admin Panel Detection ✅ Identifies 24+ admin interfaces Backup File Discovery ✅ Finds 17+ backup file patterns GraphQL Introspection ✅ Extracts complete schema WebSocket Discovery ✅ Identifies WebSocket endpoints CORS Analysis ✅ Detects misconfigurations Phase 3: Deep Analysis HTML Structure ✅ Extracts page metadata JavaScript Extraction ✅ Identifies all JS files CSS Extraction ✅ Finds stylesheets Comment Extraction ✅ Extracts HTML comments Secret Discovery ✅ Finds 18+ types of secrets Form Analysis ✅ Extracts form structures Cookie Analysis ✅ Analyzes cookie attributes Metadata Extraction ✅ Extracts meta tags JWT Decoding ✅ Decodes JWT without verification Cache Analysis ✅ Analyzes cache headers
📊 Digital Architectural Simulator
╔═══════════════════════════════════════════════════════════════════════════════╗
║ THUGSAPI ARCHITECTURAL FLOW ║
║ By SYLHETYHACKVENGER (THE-ERROR808) ║
╠═══════════════════════════════════════════════════════════════════════════════╣
║ ║
║ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ ┌────────────┐ ║
║ │ PHASE 0 │ │ PHASE 1 │ │ PHASE 2 │ │ PHASE 3 │ ║
║ │ PREPARATION │───▶│RECONNAISSANCE│───▶│ DISCOVERY │───▶│DEEP ANAL. │ ║
║ └──────────────┘ └──────────────┘ └──────────────┘ └────────────┘ ║
║ │ │ │ │ ║
║ ▼ ▼ ▼ ▼ ║
║ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ ┌────────────┐ ║
║ │• URL Validate│ │• DNS Records │ │• Directories │ │• HTML Parse│ ║
║ │• DNS Resolve │ │• WHOIS Info │ │• Files │ │• JS Extract│ ║
║ │• SSL Verify │ │• Subdomains │ │• API Endpoints│ │• CSS Ext. │ ║
║ │• WAF Detect │ │• Technologies│ │• Parameters │ │• Comments │ ║
║ │• Rate Limit │ │• Headers │ │• Hidden Paths│ │• Secrets │ ║
║ │• User Agents │ │• SSL Details │ │• Admin Panels│ │• Forms │ ║
║ │• Proxies │ │• Ports │ │• Backups │ │• Cookies │ ║
║ │• Session │ │• Server │ │• GraphQL │ │• Metadata │ ║
║ │ │ │• Third-Party │ │• WebSocket │ │• JWT │ ║
║ │ │ │ │ │• CORS │ │• Cache │ ║
║ └──────────────┘ └──────────────┘ └──────────────┘ └────────────┘ ║
║ ║
║ ┌─────────────────────────────────────────────────────────────────────────┐ ║
║ │ OUTPUT GENERATION LAYER │ ║
║ ├─────────────────────────────────────────────────────────────────────────┤ ║
║ │ • JSON Report (Complete structured data) │ ║
║ │ • HTML Page (Target response) │ ║
║ │ • Summary Report (Human-readable) │ ║
║ │ • Log File (Detailed execution log) │ ║
║ │ • Console Output (Real-time color-coded) │ ║
║ └─────────────────────────────────────────────────────────────────────────┘ ║
║ ║
║ ┌─────────────────────────────────────────────────────────────────────────┐ ║
║ │ EVASION & STEALTH LAYER │ ║
║ ├─────────────────────────────────────────────────────────────────────────┤ ║
║ │ • Random User-Agent Rotation • Dynamic Proxy Switching │ ║
║ │ • Request Delay Throttling • WAF Signature Bypass │ ║
║ │ • IP Rotation (X-Forwarded-For) • Rate Limit Evasion │ ║
║ │ • Custom Header Injection • TLS Fingerprint Spoofing │ ║
║ └─────────────────────────────────────────────────────────────────────────┘ ║
║ ║
║ ┌─────────────────────────────────────────────────────────────────────────┐ ║
║ │ ADVANCED SECURITY MODULES │ ║
║ ├─────────────────────────────────────────────────────────────────────────┤ ║
║ │ • SSL/TLS Certificate Validation • Security Headers Analysis │ ║
║ │ • Subdomain Takeover Detection • CORS Misconfiguration Detection │ ║
║ │ • Secret/Key Discovery • JWT Token Decoding │ ║
║ │ • Cache Policy Analysis • GraphQL Schema Extraction │ ║
║ │ • WebSocket Security Analysis • Rate Limit Detection │ ║
║ └─────────────────────────────────────────────────────────────────────────┘ ║
║ ║
║ ┌─────────────────────────────────────────────────────────────────────────┐ ║
║ │ DATA PROCESSING PIPELINE │ ║
║ ├─────────────────────────────────────────────────────────────────────────┤ ║
║ │ • Input Validation ──▶ • Request Processing ──▶ • Response │ ║
║ │ • Data Extraction ──▶ • Analysis Engine ──▶ • Reporting │ ║
║ └─────────────────────────────────────────────────────────────────────────┘ ║
║ ║
╚═══════════════════════════════════════════════════════════════════════════════╝
📁 Project Structure
THUGSAPI/
├── thugsapi.py # Main tool script (by SYLHETYHACKVENGER)
├── thugsapi_results/ # Results directory
│ ├── [target]_[timestamp]_complete.json
│ ├── [target]_[timestamp]_page.html
│ ├── [target]_[timestamp]_summary.txt
│ └── [target]_[timestamp]_logs.json
├── requirements.txt # Dependencies
└── README.md # Documentation
🔧 Installation
Quick Install
# Clone or download the script
python3 thugsapi.py
# Dependencies auto-install on first runManual Install
pip install -r requirements.txtDependencies
· requests - HTTP client · beautifulsoup4 - HTML parsing · dnspython - DNS resolution · websocket-client - WebSocket testing · pyjwt - JWT token decoding · colorama - Colored output · python-whois - WHOIS queries · aiohttp - Async HTTP support
🎯 Usage Examples
Basic Scan
python3 thugsapi.py https://example.comWith Domain Only
python3 thugsapi.py example.comQuick Scan
# The tool will prompt for URL if not provided
python3 thugsapi.pyResults Location
All results are saved in the thugsapi_results/ directory with timestamped filenames.
📈 Output Examples
Console Output
[14:32:15.234] PHASE 0: PREPARATION - Clearing All Obstacles
[14:32:15.235] [1/9] Validating URL...
[14:32:15.236] ✓ URL validated: https://example.com
[14:32:15.237] [2/9] Resolving DNS...
[14:32:15.421] ✓ DNS resolved: 93.184.216.34
[14:32:15.422] [3/9] Testing Network Connectivity...
[14:32:15.623] ✓ Network reachable (latency: 42.5ms)
[14:32:15.624] [4/9] Checking SSL/TLS...
[14:32:15.890] ✓ SSL valid: TLSv1.3
[14:32:15.891] [5/9] Detecting WAF/IDS/IPS...
[14:32:16.102] ✓ No WAF detected
[14:32:16.103] [6/9] Testing Rate Limiting (Exact)...
[14:32:16.304] ✓ No rate limiting detected
Summary Output
═══════════════════════════════════════════════════════════════════════════════
🎯 EXECUTION COMPLETE
Duration: 0:02:15.634
───────────────────────────────────────────────────────────────────────────────
📊 DISCOVERED:
• API Endpoints: 7
• Secrets Found: 3
• JWT Tokens: 1
• Subdomains: 12
• Directories: 45
• Admin Panels: 2
• WebSocket Endpoints: 1
• GraphQL Endpoints: 1
───────────────────────────────────────────────────────────────────────────────
✅ ALL BUGS FIXED | ALL FEATURES ADDED
📁 Results saved in 'thugsapi_results' directory
═══════════════════════════════════════════════════════════════════════════════
🛠️ Advanced Features
WAF Evasion
· Detects Cloudflare, AWS WAF, Akamai, Imperva, F5, ModSecurity, Sucuri, Barracuda, WordFence, and CloudFront · Implements specific bypass techniques per WAF type
Subdomain Takeover Detection
· Checks for 17+ takeover patterns · Detects AWS S3, GitHub Pages, Heroku, Cloudflare, Netlify, Vercel, Azure, Google Cloud, WordPress, Shopify, Tumblr, Ghost, Pantheon, Acquia, Fastly, Akamai, and Cloudfront
Secret Discovery (18+ Types)
· API Keys, JWT Tokens, AWS Credentials, Google API Keys, OAuth Tokens, Passwords, Secrets, Private Keys, Slack Tokens, GitHub Tokens, Stripe Keys, PayPal Secrets, Twilio Keys, SendGrid Keys, and more
GraphQL Analysis
· Performs full schema introspection · Extracts query, mutation, and subscription types · Identifies all available fields and types
CORS Analysis
· Detects wildcard origin configurations · Identifies allowed methods and headers · Analyzes credential sharing policies
IMPORTANT: This tool is intended for authorized security testing and educational purposes only.
· ✅ DO: Use only on systems you own or have explicit written permission to test · ✅ DO: Follow responsible disclosure practices · ✅ DO: Respect all applicable laws and regulations · ❌ DON'T: Use for unauthorized access or malicious purposes · ❌ DON'T: Scan systems without proper authorization · ❌ DON'T: Ignore rate limiting or cause denial of service
🔒 Security Best Practices
- Always obtain written permission before testing any system
- Use responsibly and follow the rules of engagement
- Respect rate limits to avoid disrupting services
- Keep results confidential and secure
- Disclose vulnerabilities responsibly
- Stay within scope of authorized testing
📝 License
This tool is provided "AS IS" without any warranties. Use at your own risk. The author is not responsible for any misuse or damage caused by this tool.
🤝 Contributing
Contributions, bug reports, and feature requests are welcome! Please ensure your code follows the existing style and includes appropriate documentation.
📞 Contact & Support
· Author: SYLHETYHACKVENGER (THE-ERROR808) · GitHub: sylhetyhackvenger · For issues, questions, or suggestions: Open an issue on the repository
THUGSAPI - Empowering Security Professionals with Advanced Reconnaissance
Built with ❤️ by SYLHETYHACKVENGER (THE-ERROR808) Security Research & Development
📊 Quick Reference Card
Aspect Details Tool Name THUGSAPI Author SYLHETYHACKVENGER (THE-ERROR808) GitHub sylhetyhackvenger Type Advanced Web Reconnaissance & Security Analysis Language Python 3.8+ Phases 4 (Preparation, Reconnaissance, Discovery, Deep Analysis) Features 50+ Security Checks Output Formats JSON, HTML, TXT, Console Auto-Dependencies Yes Proxy Support HTTP, HTTPS, SOCKS5 WAF Evasion Yes (10+ WAFs) Subdomain Takeover Yes (17+ Platforms) GraphQL Support Yes (Full Introspection) JWT Decoding Yes CORS Analysis Yes WebSocket Discovery Yes Secret Discovery 18+ Types Security Headers 9+ Checks Technology Detection 25+ Frameworks
© 2026 SYLHETYHACKVENGER (THE-ERROR808). All rights reserved.
