Analyzes source code to uncover the complete attack surface — hidden endpoints, shadow APIs, undocumented routes, and security blind spots that manual review misses.
Crystal, Ruby, Python, Go, Java, Kotlin, JS/TS, PHP, C#, and more. One tool for your entire stack.
LLM integration detects endpoints even in unsupported frameworks. Nothing escapes.
CI/CD native. GitHub Actions, JSON/YAML/SARIF output. Plug into ZAP, Burp, Caido.
Discovered endpoints feed directly into dynamic testing tools. Static analysis meets dynamic scanning for full coverage.
JSONYAMLOpenAPISARIFcURLHTMLMermaidOAS
Open Source
OWASP Noir is built by the community. Contribute, report issues, or just star the repo.