Skip to content

#118 · New Release: Frontend Custom Rules for Escape DAST

We’re excited to announce that Custom Rules are now available for Escape Frontend DAST.

With this release, you can go beyond Escape’s extensive built-in security tests and, in addition to handling complex authentication flows, define your own detection logic tailored to your applications and business requirements.

What this means for you

  • Adapt to your context: Build rules for specific workflows, sensitive pages, or custom attack scenarios.
  • Scale your governance: Apply your own security policies across multiple applications with a consistent, automated approach.
  • Leverage a simple, powerful language: Define rules in YAML while benefiting from Escape’s inference engine to detect issues dynamically as you navigate the application.

How it works

Custom Rules for Frontend DAST use the same YAML-based format as the Authentication action presets you may already be using. That means there’s no new syntax to learn and you can start defining rules right away.

Each rule is built from three main components:

  • Detectors: Specify the conditions that should trigger an alert, such as matching page content, evaluating JavaScript assertions, or other custom signals.
  • Alerts: Configure the severity, context, and category of the findings when a rule is triggered.
  • Seeders: Optionally guide the scan by pre-seeding it with navigation steps or requests.

You can now create rules for scenarios as simple as detecting a successful login message or as advanced as validating custom security controls in your frontend logic.

Documentation

Full documentation, including examples and YAML specifications, is available here:

Frontend Custom Rules Documentation

With Frontend Custom Rules, you now have the flexibility to extend Escape DAST to cover exactly what matters most to your applications and users.