Performing Api Inventory And Discovery
Overview
Cybersecurity skill for performing api inventory and discovery. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing api inventory and discovery"
"Performs API inventory and discovery to identify all API endpoints in an organiz"
Mapping the complete API attack surface of an organization before a security assessment
Identifying shadow APIs deployed by development teams without security review
Discovering deprecated or zombie API versions that remain accessible but unmaintained
Finding undocumented API endpoints exposed through mobile applications, SPAs, or microservices
Building an API inventory for compliance requirements (PCI-DSS, SOC2, GDPR)
Do not use without written authorization. API discovery involves scanning network infrastructure and analyzing traffic.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization specifying the target domains and network ranges
- Passive traffic capture capability (network tap, proxy, or cloud traffic mirroring)
- Active scanning tools: Amass, subfinder, httpx, and nuclei
- JavaScript analysis tools: LinkFinder, JS-Miner, or custom parsers
- Access to cloud console (AWS, Azure, GCP) for API gateway inventory
- Burp Suite Professional for passive API endpoint discovery
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for api inventory and discovery operations.
- Prepare Environment — Set up tools, access, and data sources required for api inventory and discovery.
- Execute Core Workflow — Perform the api inventory and discovery operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-api-inventory-and-discovery3description: Use when performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Use when working with performing api inventory and discovery.4license: Apache-2.05---67# Performing Api Inventory And Discovery89## Overview1011Cybersecurity skill for performing api inventory and discovery. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing api inventory and discovery"16- "Performs API inventory and discovery to identify all API endpoints in an organiz"171819- Mapping the complete API attack surface of an organization before a security assessment20- Identifying shadow APIs deployed by development teams without security review21- Discovering deprecated or zombie API versions that remain accessible but unmaintained22- Finding undocumented API endpoints exposed through mobile applications, SPAs, or microservices23- Building an API inventory for compliance requirements (PCI-DSS, SOC2, GDPR)2425**Do not use** without written authorization. API discovery involves scanning network infrastructure and analyzing traffic.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Written authorization specifying the target domains and network ranges38- Passive traffic capture capability (network tap, proxy, or cloud traffic mirroring)39- Active scanning tools: Amass, subfinder, httpx, and nuclei40- JavaScript analysis tools: LinkFinder, JS-Miner, or custom parsers41- Access to cloud console (AWS, Azure, GCP) for API gateway inventory42- Burp Suite Professional for passive API endpoint discovery4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Plan Operations** — Define objectives, scope, and success criteria for api inventory and discovery operations.622. **Prepare Environment** — Set up tools, access, and data sources required for api inventory and discovery.633. **Execute Core Workflow** — Perform the api inventory and discovery operations following established procedures.644. **Validate Results** — Verify that results meet quality standards and objectives.655. **Report Findings** — Document results, observations, and recommendations.666. **Follow Up** — Track remediation actions and verify fixes where applicable.6768## Tools6970- **Analysis Platform** — Data processing and visualization71- **Collaboration Tools** — Team coordination and knowledge sharing727374## Process75761. **Design** — Define interface, identify patterns, plan implementation771. **Implement** — Write code following existing conventions, add tests781. **Verify** — Run tests, check integration, validate behavior7980## Verification8182- [ ] All api inventory and discovery procedures executed completely and documented83- [ ] Findings validated against multiple data sources84- [ ] False positives identified and filtered85- [ ] Results documented with evidence and timestamps86- [ ] Recommendations provided with risk-based prioritization8788## Anti-Rationalization Table8990| Rationalization | Reality |91|---|---|92| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |93| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |94| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |