#36 ยท Elevate Your DAST Scans with Dynamic Authentication Token Generation! ๐๐
Exciting news for all Escape users! We're rolling out a game-changing enhancement on the scan authentication feature: Dynamic Authentication Token Generation for DAST scans. This feature is about empowering your scans with real-world authentication scenarios.
What's New?¶
- Generate Authentication Credentials Automatically: Start every DAST scan with fresh, automatically generated credentials. Whether it's tokens or other forms of authentication, we've got you covered.
- Run Scans with Multiple User Profiles: Simulate different user levels in your scans - from admins to standard users. This allows you to comprehensively test your APIs from various security standpoints.
- Effortless Authentication for Any API: With our versatile framework, authenticate against any type of API โ REST, GraphQL, or anything else.
Key Enhancements:¶
- Workflow-Driven Authentication: Tailored to fit a variety of server interactions, ensuring seamless token generation and application.
- Credential Management: Efficient extraction and injection of authentication data into your scans.
- Detailed Logging: Track every step of the authentication process with our comprehensive logs.
- Session Management and Refresh: Manage and automatically refresh tokens based on their TTL, or configure manually if needed.
Supported Authentication Methods:¶
- AWS Cognito
- Basic
- cURL & cURL Sequence
- Digest
- GraphQL
- Headers
- HTTP
- OAuth (Client Credentials, User Password)
- Webdriver
- Custom Workflows involving multiple HTTP Requests and Webdriver actions
Dive Into Action:¶
This update opens up a new realm of possibilities for your API security testing. By incorporating real-world authentication scenarios, your DAST scans are now more thorough and realistic than ever. Get ready to unleash the full potential of your API security with Escape!