API Spyder by Cequence Security is a SaaS-based discovery tool that provides an attacker’s view into an organization’s public-facing resources to identify external API hosts, unauthorized hosting providers, and API-specific security issues. It addresses the unique visibility and risk management problems created by the rapid expansion of API use in organizations. API Spyder discovers external API and hosting providers, identifies API-specific security issues, and reports on external API risk exposure. It uses a predictive crawling technique on public domains to discover exposed resources, including API servers and common API endpoints. API Spyder requires no installation or deployment of software, nor any network changes. It provides an outside-in view of exposed resources, revealing what an attacker may see. API Spyder can uncover Log4j and LoNg4j vulnerabilities in API servers without requiring instrumentation. It generates a few hundred API requests per API server when crawling a domain, similar to a Google Bot crawl impact. API Spyder is part of the Cequence Unified API Protection platform, which combines discovery, compliance, and protection for internal and external APIs to defend against attacks and fraud.