Supported Targets¶
Escape discovers and tests the targets below. Discovery support and testing depth vary by product.
APIs¶
- REST: OpenAPI 3.x, Swagger 2, Postman collections, or endpoints extracted from crawling and recorded HAR/Burp exports. See REST API DAST.
- GraphQL: SDL or introspection-based discovery, queries, mutations, and subscriptions. See GraphQL API DAST.
- gRPC: discovered and classified by ASM service discovery.
- SOAP: discovered and classified by ASM service discovery. Deep DAST testing is available for REST, GraphQL, and web applications.
Web Applications¶
- Single-page apps (SPA): React, Vue, Angular, Svelte, and similar; agentic crawling + browser-driven DAST.
- Server-rendered apps: Rails, Django, Spring, Next.js (SSR), and similar.
- Progressive web apps (PWA): browser-accessible pages and APIs.
See WebApp DAST.
AI and LLM Surfaces¶
- LLM-backed APIs: chat completions, RAG endpoints, function-calling surfaces. OWASP LLM Top 10 coverage. See LLM Security.
- AI applications: agentic apps that wrap an LLM with tools and state.
- MCP servers: Model Context Protocol servers exposed over HTTP.
Infrastructure and Discovery¶
- Domains and subdomains: owned DNS, inferred from certificates and routing, and monitored for drift.
- CIDR ranges: IPv4 ranges of /24 or narrower, either public or private through a Private Location. See Network Scanning for wider-range requirements.
- Ports and services: TCP port scanning with service fingerprinting. See Network Scanning.
- Cloud accounts: AWS, GCP, Azure inventory through the ASM Integrations.
Client and Infrastructure Scope¶
- Mobile applications (iOS, Android): Escape tests their APIs. Testing mobile binaries and mobile SAST are outside this scope.
- Native desktop applications: Escape tests their backend services. Testing the desktop client is outside this scope.
- Kernel and firmware testing: outside Escape's application and API testing scope.
If your stack isn't listed and you think it should be, write to support@escape.tech.