OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from.
Tools like ZAP and Burp Suite, known as DAST tools, poke at a running apps from the outside and find many of its routes by crawling.
When the static rules miss a framework, or an app uses one-off custom routing, Noir can hand the code to an LLM through OpenAI, Ollama, or similar providers.
DAST tools including ZAP, Burp Suite, Caido, and Gori receive the routes as a proxy target or an OpenAPI import.
Must read:Subscribe to the Help Net Security ad-free monthly newslett…