Recon First: Mapping SPA Attack Surface with Sec-XRay
Why I built Sec-XRay: passive and dynamic recon for modern single-page apps, from JS endpoint extraction to secret detection.
Modern web apps hide most of their attack surface inside JavaScript bundles. View-source shows almost nothing. Sec-XRay is my answer: a recon engine built for single-page applications.
The Problem
Traditional crawling misses what matters in SPAs:
- API routes only referenced inside minified JS chunks.
- Endpoints behind client-side routing that never appear as links.
- Hardcoded keys and tokens left in frontend bundles.
What Sec-XRay Does
- Deep crawl with Playwright stealth, rendering pages like a real browser.
- Endpoint extraction from JS bundles, sourcemaps, and network traffic.
- Secret detection for API keys, tokens, and credential patterns.
- Structured output so findings feed directly into manual testing.
How It Fits My Workflow
Recon output is the input to everything else: Burp Suite for interception, Nuclei for known patterns, and manual testing for logic flaws like BOLA and IDOR. Automation maps the surface; judgment finds the bugs.
Source code is public: github.com/AditCodeX/Sec-XRay.