OWASP Noir: open-source static analysis tool
OWASP has released Noir, a free static analysis tool that inventories the endpoints an application exposes — paths, HTTP methods, parameters, headers and cookies, each tied to its file and line. It covers 29 languages and 205 frameworks from a single binary, surfaces shadow and deprecated APIs, and can fall back to an LLM via OpenAI or Ollama for custom routing.
- Covers 29 languages and 205 frameworks from one binary, no plugins
- Finds shadow APIs, deprecated routes and undocumented handlers
- 17 taggers label endpoints such as jwt, payment, admin and file_upload
- Exports in 22 formats including JSON, SARIF, OpenAPI and Postman
Read next
Software