Shadow API Discovery¶
Shadow APIs are the undocumented, forgotten, or rogue endpoints that sit outside your official inventory. Escape brings discovered shadow APIs into your ASM inventory for review and testing.
What Counts as a Shadow API¶
- Undocumented endpoints: routes live in production but aren't in the OpenAPI spec or the internal catalog.
- Forgotten subdomains: old marketing sites, internal tools pinned to legacy vhosts, proof-of-concept hosts still serving.
- Rogue deployments: staging environments deployed to production-like domains, personal test servers exposed by mistake.
- Drift: an endpoint that used to exist in the spec but got removed from docs while still serving traffic.
How Escape Finds Them¶
ASM combines several discovery sources:
- DNS and certificate transparency: enumerate subdomains from passive sources and CT logs.
- Service fingerprinting: hit every discovered host on a configurable port list, identify the framework, and infer the likely shape of the API.
- Application crawling and recorded exports: Escape extracts endpoints from its own crawling and from HAR/Burp exports. These sources can reveal routes missing from a declared schema.
Every shadow endpoint becomes an Asset with the usual lifecycle: severity, owner, classification. From there it's treated like any other API: scanned by DAST, tested by AI Pentesting, routed to the owning team.
Feeding Back Into the Truth¶
When ASM finds an endpoint that should have been in the schema, update the OpenAPI spec or catalog. Close rogue deployments that shouldn't be exposed. Use these findings to align your documented APIs with the services deployed in your environment.
See Asset Management for how assets are tracked over time, and Scope for including or excluding a discovered asset from the next scan.