#64 · HAR File Support for REST API Scanning in DAST
We're excited to announce a new capability for our DAST scanner: support for HAR files as REST API schemas. This enhancement offers you greater flexibility when scanning your APIs for vulnerabilities, especially since generating a HAR file can be faster and easier than creating or maintaining a Swagger/OpenAPI specification.
What are HAR files?¶
HTTP Archive (HAR) files are JSON-formatted files that capture network activity, including requests and responses, between a client and a server during a browsing session. With this update, our DAST scanner can now ingest HAR files to interpret and scan REST APIs, simplifying the scanning process and expanding its capabilities.
What are the benefits?¶
HAR files capture actual API interactions, including dynamically generated requests and responses during runtime. This is particularly useful in scenarios such as:
- Dynamic or undocumented APIs: When API behavior depends on real-time parameters or session states that aren’t fully documented in Swagger or OpenAPI.
- Legacy or incomplete documentation: For APIs lacking comprehensive or up-to-date schemas. Additionally, HAR files reflect real-world usage, uncovering hidden or undocumented endpoints and specific request variations that static schemas might miss. This leads to more thorough scans and improved vulnerability detection.
How it Works?¶
- Generate a HAR file by capturing the API traffic using tools like browser developer tools or network monitoring software.
-
Upload the HAR file to the DAST scanner via the API schema configuration interface:
-
Go to Security scan and click on New Application
- Select REST API
- Configure your Network and Authentication (if needed)
- Upload the HAR file to define your API schema
- 3.Initiate the scan
- Once uploaded, the scanner parses the HAR file, automatically identifying API endpoints, HTTP methods, parameters, and other details. Start the scan and let the DAST scanner analyze your API for vulnerabilities.
Start scanning smarter, not harder 😉