Traffic-based attack detection
Metlo passively listens to API traffic to build a model of how the API behaves, then uses that model to flag malicious requests and bad actors.
Metlo is an open source API security product that discovers API inventory from traffic and helps detect and block malicious requests. It also supports custom tests, OpenAPI spec generation, and integrations across common runtimes and infrastructure.
Metlo is an API security product that uses observed API traffic to help teams discover their API surface and detect malicious activity. The homepage positions it as open source API security software for setting up in less than 15 minutes.
The product combines discovery, testing, and protection workflows. It can inventory endpoints, hosts, and sensitive data, identify unauthenticated endpoints, run custom tests, and block malicious requests in real time using detections built from request patterns.
The site also describes a deployment model built around connectors and agents, with support for common stacks such as Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, Docker, Express, Koa, and Fastify. The homepage states that discovery metadata is sent to Metlo’s cloud while the agent performs discovery locally.
Metlo passively listens to API traffic to build a model of how the API behaves, then uses that model to flag malicious requests and bad actors.
The product calls out built-in detections for SQLi, XSS, SSRF, RCE, login brute force, account takeover, and more, with support for custom detections.
Metlo distinguishes detection at the IP, session, and user level, which helps identify attacks that move beyond a single request or address.
It creates an inventory of endpoints, hosts, and sensitive data from observed traffic, including unauthenticated endpoints and data fields.
Discovery runs in the agent, with only metadata sent to Metlo’s cloud, and the product can send webhooks when new endpoints or data fields are found.
Metlo supports custom tests for finding different kinds of vulnerabilities and can autogenerate OpenAPI specs from discovered API activity.
Use Metlo to map your API surface from live traffic, including hosts, endpoints, sensitive data, and unauthenticated routes, so teams can understand what is actually exposed.
Use the built-in detections to watch for common attack patterns such as SQLi, XSS, SSRF, RCE, brute force, and account takeover, then block or review malicious requests.
Use custom tests to probe for different kinds of vulnerabilities during API security checks and development workflows.
Use the connectors and runtime support to add Metlo to existing services and infrastructure that run on Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, or Docker.
Use the discovered API activity and metadata to generate OpenAPI specs or send alerts when new endpoints and data fields are identified.
Metlo discovers API endpoints, hosts, sensitive data, and unauthenticated endpoints from API traffic, and it can also detect and block malicious requests and bad actors.
The homepage says Metlo can be set up in less than 15 minutes and integrates with Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, Docker, and common frameworks such as Express, Koa, and Fastify.
Metlo includes built-in detections such as SQLi, XSS, SSRF, RCE, login brute force, and account takeover, and it also supports custom detections and custom tests.
The pricing page at `/pricing` is not available, so the site text does not confirm current pricing or plan structure.