Skip to content
← LibraryTechnique entry
W-RECON-API-DISCOReconnaissance

API Endpoint Discovery

Hunt swagger.json / openapi.yml / GraphQL /graphql, robots.txt, JS bundles — map the API surface area.

§ Where this technique fits

W-RECON-API-DISCO is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 13 approved dossiers in the registry, typically at step 1.4 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Blind XXE — Out-of-Band Exfil
    W-XXE-BLIND-OOB · Lateral Movement
    seen 1×
  2. 02
    Broken Object Level Authorization (API BOLA)
    W-BOLA · Privilege Escalation
    seen 1×
  3. 03
    Business Logic Flaw
    W-BUSINESS-LOGIC · Impact
    seen 1×
  4. 04
    ESXi OpenSLP Unauth RCE (CVE-2021-21974)
    HV-ESXI-SLP · Initial Access
    seen 1×
  5. 05
    File Upload Filter Bypass
    W-UPLOAD-BYPASS · Initial Access
    seen 1×
  6. 06
    GraphQL Introspection
    W-GRAPHQL-INTRO · Discovery
    seen 1×
  7. 07
    JWT — RS256 → HS256 Algorithm Confusion
    W-JWT-ALG-CONFUSION · Credential Access
    seen 1×
  8. 08
    MQTT Broker Open / No Auth
    IOT-MQTT-OPEN · Initial Access
    seen 1×