Skip to content

v0.2.5

Latest

Choose a tag to compare

@github-actions github-actions released this 28 Sep 19:44
· 4 commits to main since this release

Highlights

  • Expand injection coverage with blind boolean LDAP and XPath checks, Velocity/Smarty/Razor SSTI probes, string-transform template evaluation, dynamic MSSQL timing payloads, Windows PowerShell/cmd variants, and stronger SQL boolean/arithmetic oracles.
  • Add heuristic IDOR testing for single-profile scans while preserving strict multi-role BOLA ownership and anonymous-control proofs.
  • Add route authorization-bypass coverage for encoded slashes, case normalization, method overrides, and safe-read fallback for non-GET endpoints.
  • Extend SSRF coverage with IPv6, IPv4-mapped IPv6, hexadecimal/octal, zero-address, gopher and dict payloads.
  • Add directory-listing discovery, broader cloud-takeover fingerprints, and cache parameter-cloaking verification.

Discovery and replay

  • Preserve browser-captured XHR request templates ahead of synthetic forms, including original methods, bodies, headers, cookies, CSRF context and duplicate parameters.
  • Add XML, multipart, raw GraphQL, WebSocket JSON, observed-header, cookie and positional path-identifier mutation surfaces.
  • Discover common content roots and inferred parent directories from observed static assets, with structural Apache, nginx, Python and IIS directory-index detection.
  • Auto-admit exact passive CDN dependencies learned from successful in-scope HTML/CSP without expanding active scan scope or forwarding credentials.
  • Infer authorization role profiles from distinct configured authentication profiles and publish browser/OAST/identity/workflow/runtime readiness.

Verification and false-positive control

  • Introduce SQL boolean-pair and numeric arithmetic-oracle proof types with alternating replay, clean controls and padding-aware semantic comparison.
  • Publish per-target request, response, authentication/rate/gateway block, timeout, transport, proof-role and suppression diagnostics.
  • Require current proof-policy evidence before a candidate can become a finding; unproven candidates fail closed and remain visible in coverage diagnostics.
  • Distinguish browser-confirmed reflected XSS from true DOM-based XSS in terminal labels and stored evidence.
  • Add end-to-end OAST self-testing, exact scan-scoped correlation and hidden health callbacks.
  • Expand TLS, CSP, deserialization, LLM, sensitive-data and CVE validation while keeping evidence typed and replayable.

Reporting and operation

  • Stream HTML, JSON, CSV, Markdown and SARIF findings with context cancellation instead of building large reports entirely in memory.
  • Generate a bounded fast-partial report after Ctrl+C and allow a second interrupt to cancel reporting immediately.
  • Preserve full Burp-style request/response evidence, add coverage diagnostics, and embed scanner version, commit and build date.
  • Add machine-readable assurance profiles and a fail-closed complete-corpus release gate for module/capability omissions.
  • Embed release build provenance and publish signed GitHub attestations in addition to SHA-256 checksums.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./....
  • Strict observed-corpus benchmark quality retains 1.0 precision and an F1 score above 0.96.
  • Regression coverage includes the six Burp Bounty SQLi surfaces, reflected-vs-DOM XSS classification, browser request replay, directory listing, OAST correlation, report streaming and interrupt behavior.

Install with Go

go install github.com/akha-security/akca/engine/cmd/akca@v0.2.5

After the module proxy refreshes, @latest resolves to v0.2.5 as well:

go install github.com/akha-security/akca/engine/cmd/akca@latest

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Release binaries include GitHub build-provenance attestations and can be verified with gh attestation verify <binary> -R akha-security/akca.

Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.4...v0.2.5