/api/v1/, /api/legacy/)staging-api., dev-api., test.)Both patterns require the attacker to find the forgotten surface. Discovery tools: path/word fuzzing (/api/v1/, /api/v2/, common paths), subdomain enumeration (certificate transparency logs, DNS brute force, staging-api.company.com), JavaScript file analysis (old API paths referenced in frontend JS), Google dorking (cached URLs), and Shodan for exposed services. None of these techniques are sophisticated — they’re all automated and freely available.