A target is the URL of a Web Application, Website, or API.
:::info A target defines the scope of the scan.
:::
A DAST target is the specific entry point (URL or endpoint) of a web application, website, API, or any component that accepts input from the outside world. It defines the scope, or boundaries, of the security scan conducted by a DAST tool, limiting the tool to analyzing only those pages, links, or forms within the target’s domain.
For instance, with a target of https://example.com, the scan would cover https://example.com/app1 but not https://app2.example.com. Essentially, the scanner examines URLs beginning with “example.com.”
https://www.example.com: Top-level domain hosting the applicationhttps://example.com/blog: Sub-folder or sub-section within the applicationhttps://admin.example.com: Subdomain hosting a separate applicationhttps://api.us.example.com: Internal API hosted on a subdomainhttps://api.eu.example.com: Separate API instance hosted independentlyhttps://example.com/login: Login form within the top-level domainhttps://checkout.example.com: Checkout and payment form hosted on a subdomainexample.com, app.example.com and api.example.com) would each constitute an individual target.A clear and well-defined DAST target ensures the scan focuses on the specific areas of an application most susceptible to external threats.
When adding a new target, you can choose between Web and API. Once the target type has been selected and saved, you can’t change the type again.
To scan an API, we need its specification, the schema. You can define it with a URL pointing to the schema or uploading it. The former has the advantage of us fetching the schema before every scan, ensuring we always get the most up-to-date version.
There are a few configuration options available when setting up targets.
https://example.com/admin*
https://api.example.com/api/users*
https://example.com/account*
posts/search?query=cobalt
Header Name: Authorization
Header Value: Bearer 123456