Building an application inventory is a critical but often skipped step in many Application Security programs. Security teams are overly dependent on questionnaires, word of mouth or other passive methods of application discovery. This can create gaps which are filled with unknown, legacy or otherwise risky applications in the environment. These neglected areas then become a perfect foothold for an attack. In this talk we will dissect the challenges around web application and API discovery, and outline approaches that have worked well for our team. We will outline specific techniques for automatically enumerating web applications and APIs and onboarding them into tools that can help identify risk.