Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
-
Updated
Sep 5, 2026 - Crystal
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.
Automatically discover APIs behind NGINX / NGINX Plus from access logs — shadow API detection, live API inventory, and ML anomaly detection. Self-hosted, Docker-ready.
Know every endpoint and whether you meant to expose it. Static, deterministic, local. Part of Stelnyx.
NOEMVEX-WEB-ARCHITECT v4.1: Advanced stealth web reconnaissance and API auditing suite. Bypasses WAFs via Exponential Backoff. Automatically decompiles minified JavaScript to extract hardcoded secrets, maps Shadow API routes, and performs active GDPR/PII data leak hunting with Zero-False-Positive JWT validation.
A fast, passive API attack surface discovery tool that detects undocumented (Shadow) APIs by reconciling web server access logs against OpenAPI/Swagger specifications and flags OWASP Top 10 vulnerabilities.
To associate your repository with the shadow-api topic, visit your repo's landing page and select "manage topics."