Recon First: Mapping SPA Attack Surface with Sec-XRay

Why I built Sec-XRay: passive and dynamic recon for modern single-page apps, from JS endpoint extraction to secret detection.

Modern web apps hide most of their attack surface inside JavaScript bundles. View-source shows almost nothing. Sec-XRay is my answer: a recon engine built for single-page applications.

The Problem

Traditional crawling misses what matters in SPAs:

  • API routes only referenced inside minified JS chunks.
  • Endpoints behind client-side routing that never appear as links.
  • Hardcoded keys and tokens left in frontend bundles.

What Sec-XRay Does

  1. Deep crawl with Playwright stealth, rendering pages like a real browser.
  2. Endpoint extraction from JS bundles, sourcemaps, and network traffic.
  3. Secret detection for API keys, tokens, and credential patterns.
  4. Structured output so findings feed directly into manual testing.

How It Fits My Workflow

Recon output is the input to everything else: Burp Suite for interception, Nuclei for known patterns, and manual testing for logic flaws like BOLA and IDOR. Automation maps the surface; judgment finds the bugs.

Source code is public: github.com/AditCodeX/Sec-XRay.

<- All posts