The process of identifying undocumented or hidden API endpoints that may lack proper security controls.