Frequently asked questions about the DAST Scanner.
The crawler starts with the target URL and any configured seed paths. It tries to follow and click all the links on a given page. The new pages and new injection points found are added to the list of URLs to scan. The crawler can detect patterns in the URLs and mark some URLs as duplicates. Some of the duplicates will be sampled to be scanned as well.
If the internal app can be accessed via an IP whitelist, we can test it. However, if a VPN/jumpbox or similar setup is required, we don’t support that level of advanced configuration yet.
We send DAST emails to the Organization Owners only, not to the Organization Members. If you are an Organization Owner and still not receiving emails, please check your spam folder. If you still can’t find the email, please contact us.
Some common reasons are:
Go to the scan details page, where you can find more information about any existing errors or warnings.
We currently don’t have the rate-limiting option open to customers. However, here are some suggestions:
The DAST Scanner interacts with web pages similarly to how a human would, by clicking buttons and submitting forms on each crawled page. Do you have any critical pages or paths where you don’t want the crawler to interact with buttons or submit forms? Examples include Settings, User Profiles, Security, Admin section, etc. Make sure the crawler is aware of which URLs to avoid to prevent unintended interactions and potential disruptions. You can add them to the Avoided URLs in the target settings.
We don’t have this fine-grained access control yet.
‘Under Review’ status is an intermediate status before ‘Completed.’ If some vulnerabilities need to be manually confirmed by our team, the scan is set to Under Review; after this manual review, the scan changes to Completed.
If the scan is completed, then the scanner didn’t fail. However, you can check a few things:
We can’t do that at the moment, but we have it as a future roadmap candidate.
We don’t have this feature open to customers yet. However, you can contact us if you can’t work around this limitation to assist you.
We don’t have this feature open to customers yet. However, you can contact us if you can’t work around this limitation to assist you.
The DAST Scanner can handle this as long as you provide a login URL on the same domain as the target (e.g., my-app.example.com/login), and the crawler will follow the redirection to the external URL. When in doubt, you can use the sequence recorder to record the login sequence.
We don’t support this feature yet. Here are some suggestions:
Currently, we do not support standalone GraphQL API scanning. However, if there is a target with an interface that uses a GraphQL service as its backend API (e.g., SPA), then we can scan it. Standalone GraphQL API scanning is on our roadmap for future development.
If the domains are different (e.g., example.de and example.co.uk), then they are considered different targets. You can add them as separate targets in the platform. Unlike example.com/de and example.com/co.uk, which are considered different paths of the same target.