Based on the provided content, here are some key points about Hadrian:
-
Purpose: Hadrian is an open-source tool developed by Praetorian for testing API authorization vulnerabilities across REST, GraphQL, and gRPC APIs.
-
Key Features:
- Requires API specifications (OpenAPI, GraphQL schema, or proto file) and valid auth tokens.
- Can test adaptive rate limiting with reactive backoff on 429/503 responses to avoid getting blocked during assessments.
- Supports sending findings to a local Ollama instance for LLM-powered analysis, which helps in sorting true positives from edge cases quickly.
-
Installation:
bash1go install github.com/praetorian-inc/hadrian/cmd/hadrian@latest -
Usage Examples:
- Testing REST APIs with an API specification and valid auth tokens.
- Using
--dry-runto preview what Hadrian would test without sending actual requests. - Sending results for analysis using a local Ollama instance.
-
Integration with Other Tools:
- Part of the Praetorian Offensive Toolkit, which includes tools like Nerva (service fingerprinting), Aurelian (cloud
Read the full article at Blog - Praetorian
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



