OWASP Noir Open‑Source Static Analysis Tool Maps Hidden Endpoints, Secrets, and Shadow APIs Across 29 Languages
What Happened – OWASP released Noir, a free static‑analysis binary that parses source code to enumerate every exposed HTTP endpoint, its methods, parameters, headers and cookies. It surfaces undocumented “shadow” APIs, deprecated routes, and hard‑coded credentials, and can hand off ambiguous routes to an LLM for supplemental analysis. Results are exported in 22 formats (JSON, SARIF, OpenAPI, Postman, cURL, etc.) and the tool ships as a GitHub Action for CI pipelines.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs need an authoritative, up‑to‑date inventory of application attack surfaces; Noir provides that inventory automatically, reducing reliance on manual documentation.
- By flagging hard‑coded secrets and exposing undocumented endpoints, the tool supplies concrete evidence that secure‑development controls are being exercised and can be audited.
- Integration into CI pipelines creates a defensible audit trail of each code change’s impact on the endpoint landscape, supporting ongoing control monitoring.
Who Is Affected – Organizations that develop or consume web‑based applications, especially in technology, SaaS, financial services, and any sector that exposes APIs to external partners or customers.
Recommended Actions
- Add the Noir GitHub Action to your CI/CD pipeline to generate an endpoint inventory on every build.
- Map the generated inventory to your secure‑development control objectives (e.g., “maintain an up‑to‑date API catalogue”) and retain the SARIF/JSON reports as audit evidence.
- Review any flagged hard‑coded keys or shadow routes and remediate before release.
Source: Help Net Security
Technical Notes
- Static analysis covers 29 programming languages and 205 frameworks from a single binary; no per‑language plugins required.
- Optional LLM integration (OpenAI, Ollama, etc.) can enrich routing detection for custom frameworks, but results should be manually validated.
- Passive scanning rules assign severity tags (e.g., jwt, payment, admin) to help prioritize review.
Source: same as above