OWASP Noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

About OWASP Noir

About

Noir bridges the gap between SAST and DAST by analyzing source code to generate accurate, authenticated endpoint inventories. It detects what others miss: shadow APIs, deprecated endpoints, and hidden routes. By bypassing outdated documentation and proxies, Noir uses your source code to deliver a comprehensive, actionable attack surface inventory. This single source of truth empowers White-box security teams and Pentesters and integrates directly with DAST solutions, eliminating testing blind spots across your DevSecOps pipeline.

Project Resources

Project Leaders

HAHWUL

Project Lead

Hwan Lee

EmailX

KSG

Project Lead

Seonggi Kim

EmailGitHub

Project Information

Incubator Project
Classification
Incubator
Language
Crystal
License
MIT
Latest Version
v1.3.1
GitHub Stars
1429
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP Noir