Skip to content

Schedule Scans

Scheduling is available for DAST and AI Pentesting profiles. ASM automatically schedules eligible Monitored assets when ASM scanning is enabled and the profile has a valid schedule. Third-party assets aren’t scanned.

Default Schedule

  • The DAST creation form starts with a weekly CRON schedule. API-created profiles only receive a schedule when one is supplied.
  • For DAST, edit the schedule in Profile Settings → Triggers → Scheduling.
  • AI Pentesting has separate timing controls: run now, schedule a one-shot scan for later, or save without scheduling.
  • Recurring schedules support CRON expressions.

schedule-scan

Scheduling Options

  • Daily Scans: Recommended for actively developed applications
  • Weekly Scans: Suitable for stable applications
  • Custom Schedule: Use CRON expressions for specific requirements
  • One-Shot Scan: Use a start time without a CRON expression to run once

CRON schedules are evaluated in UTC. Missed CRON occurrences aren’t replayed; the scheduler selects the next occurrence that hasn’t passed.

Best Practices

  • Schedule scans during low-traffic periods
  • Consider your application's deployment cycle
  • Align scan frequency with your security requirements