OWASP has released Noir, a new open-source static analysis tool designed to inventory application endpoints. Unlike dynamic application security testing (DAST) tools, which interact with a running application, Noir analyzes source code directly to identify all exposed paths, HTTP methods, parameters, headers, and cookies, linking each to its originating file and line number. This approach allows Noir to discover "shadow APIs"—endpoints present in the code but not documented—as well as deprecated routes and undocumented handlers that might be missed by DAST tools if their crawlers do not reach them.
Noir is designed to be highly versatile, supporting 29 programming languages and 205 frameworks from a single binary without requiring plugins or per-language configurations. It automatically detects the language, framework, and routing conventions. For frameworks or custom routing schemes that its static rules might miss, Noir can leverage large language models (LLMs) via providers like OpenAI or Ollama to analyze the code. However, routes identified through LLM analysis are recommended for manual verification.
Beyond endpoint discovery, Noir also incorporates passive scanning rules to detect hardcoded keys, tokens, and credentials, assigning severity grades to these findings. Seventeen distinct "taggers" label endpoints with properties such as "jwt," "payment," "admin," and "file_upload," enabling reviewers to prioritize critical handlers.
The tool generates its inventory for three primary audiences. Human reviewers receive a comprehensive list of attacker-reachable entry points. AI code auditors, specifically LLM-based review agents, can consume the same list, with an `ai-context` flag providing surrounding code elements like guards, sinks, validators, and signals for single-handler analysis. DAST tools, including ZAP, Burp Suite, Caido, and Gori, can import Noir's output as a proxy target or an OpenAPI definition.
Noir supports 22 output formats, including JSON, SARIF, OpenAPI, Postman, and cURL. It is also available as a GitHub Action, facilitating integration into continuous integration (CI) pipelines. The tool is freely accessible on GitHub.






