VYPR
researchPublished Sep 30, 2026· 1 source

OWASP Noir: New Open-Source Tool Maps Application Endpoints for Enhanced Security

OWASP Noir, a new open-source static analysis tool, aims to uncover hidden and undocumented API endpoints within application source code, improving security visibility.

The OWASP Foundation has released Noir, a novel open-source static analysis tool designed to meticulously scan application source code and catalog all exposed endpoints. This tool goes beyond traditional methods by identifying not only documented routes but also 'shadow APIs'—endpoints present in the code but absent from any official documentation. By inventorying paths, HTTP methods, parameters, headers, and cookies, and crucially linking each to its origin file and line number, Noir provides developers and security professionals with a comprehensive map of an application's attack surface.

Noir's approach offers a significant advantage over dynamic analysis tools like ZAP and Burp Suite. While dynamic scanners probe running applications by crawling, they can only discover routes that are reachable through the crawler's path. Endpoints that are never encountered during a crawl, even if they are functional and potentially vulnerable, remain hidden. Noir, by analyzing the source code directly, can uncover these undocumented or deprecated routes, ensuring that no potential entry point is overlooked.

One of Noir's key strengths is its broad language and framework support. It boasts the ability to analyze code across 29 different programming languages and 205 frameworks from a single, plugin-free binary. The tool automatically detects the language, framework, and routing conventions used within an application. For instances where static rules might miss custom routing or less common frameworks, Noir offers an integration with large language models (LLMs) via providers like OpenAI and Ollama. This allows for the analysis of code through an LLM, though routes identified this way are flagged for manual verification.

Beyond endpoint discovery, Noir incorporates passive scanning rules to identify sensitive information like hardcoded keys, tokens, and credentials directly within the codebase. Furthermore, it employs a tagging system that labels endpoints with properties such as 'jwt', 'payment', 'admin', and 'file_upload'. This categorization allows security reviewers to prioritize their analysis, focusing on critical areas like payment processing or administrative functions before examining less sensitive routes.

The tool is designed with multiple user types in mind. Human reviewers receive a clear list of attacker-reachable entrypoints. AI code auditing agents can leverage the same data, with an additional flag (--ai-context) providing surrounding code context, including guards, sinks, and signals, to aid in single-handler analysis. Noir also supports integration with dynamic analysis tools, outputting route information in formats compatible with ZAP, Burp Suite, Caido, and Gori, either as proxy targets or OpenAPI imports.

Noir's output flexibility is another notable feature, supporting 22 different formats including JSON, SARIF, OpenAPI, Postman, and cURL. This wide range of export options ensures compatibility with various security workflows and CI/CD pipelines. The tool is readily available on GitHub and can be integrated into continuous integration processes as a GitHub Action, enabling automated security checks early in the development lifecycle.

By providing a deep, code-level insight into an application's exposed interfaces, OWASP Noir empowers development teams and security professionals to proactively identify and address potential vulnerabilities. Its ability to find undocumented or forgotten endpoints, coupled with its broad compatibility and LLM integration, makes it a valuable addition to the open-source security toolkit, particularly in complex and rapidly evolving software development environments.

Synthesized by Vypr AI