Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT News › Developer

OWASP Noir: Open-Source Static Analysis Tool

Help Net Security, Wednesday, September 30th, 2026

OWASP Noir scans source code to inventory every exposed endpoint, including undocumented shadow APIs.

Help Net Security profiles OWASP Noir, an open-source static analysis tool that reads source code and lists the endpoints an application exposes, including paths, methods, parameters, headers and cookies tied to file and line, surfacing shadow APIs, deprecated routes and undocumented handlers that DAST crawlers miss.

A single binary supports 29 languages and 205 frameworks, can fall back to an LLM for unusual routing, flags hardcoded secrets and tags endpoints such as admin or payment.

Its output serves human reviewers, AI code auditors and DAST tools like ZAP and Burp Suite.

more →  ·  More from Developer →