Skip to content

2023

#24 · Custom Security Tests

🛠️ Advance Usage: Custom Security Tests (Beta)

Empower your security testing with our latest feature—custom security tests! This advanced utility enables you to create and send tailor-made requests to any URL within your organization, catering to your unique security concerns and needs.

⚙️ What's New:

  • 1. Tailored Security Assessments: Launch specialized dynamic security assessments on your web applications. This is invaluable for identifying regression bugs, conducting in-depth security checks, or probing in-house security concerns.
  • 2. Expert Tab Configuration: Set up your custom security assessments with ease via the Expert tab in your application settings.
  • 3. Dynamic Response Validation: Assess and verify server responses based on custom conditions, like a specific status code.
  • 4. Special Commands: Further customize your raw request with special commands to adjust the host, modify timeout durations, and more.
  • 5. API Configuration: Inspired by the Nuclei template engine, our API lets you seamlessly configure and manage your custom security checks.

For a more in-depth guide on how to use this feature and optimize your security testing, visit our technical documentation.

In Conclusion:

We're continuously striving to enhance the flexibility and depth of our platform. The introduction of custom security tests underpins our commitment to catering to your individual security needs. Your feedback fuels our improvements, and we're keen to hear your thoughts on this latest addition.

#23 · Advanced Authentication with Webdriver

🔐 Custom Authentication using Webdriver

We are excited to introduce our brand new feature—Custom Authentication using Webdriver. This advanced capability allows for even more tailored and secure authentication workflows, offering users the flexibility to authenticate in ways that best suit their individual or organizational needs.

⚙️ Parameters:

  • 1. Tech Parameter: Choose your preferred auth method using the tech parameter.
  • 2. Extract Location: Specify the location of the token to be extracted. Options include RequestURL, RequestHeader, RequestBody, ResponseHeader, and ResponseBody.
  • 3. Extract Regex: Utilize regular expressions to match your token, making it easier than ever to customize your authentication flow.
  • 4. Project Parameter: Assign the authentication workflow to a specific project using the project parameter.
📌 Optional Parameters:
  • Output Format: Configure the output format using a placeholder @token@.
  • Token Lifetime: Set the duration of the token's validity in seconds with the token_lifetime parameter.

For a more detailed guide on how to utilize this new feature, you can check our technical documentation.

In Conclusion:

This new feature aims to provide a flexible and secure way to authenticate within Escape. We believe these custom authentication capabilities will significantly enhance your user experience. As always, we welcome your feedback to improve further.

#22 · [Enterprise] SSO, Fine-grained Authentication & Identity Federation

We're thrilled to announce the enhancement of our authentication mechanisms. As part of our continuous efforts to bolster security and improve user experience, we have introduced Fine-grained Authentication, Identity Federation, SAML, and SSO capabilities into Escape.

⚙️ What's New:

  • 1. Fine-grained Authentication: Our advanced authentication system now offers detailed access controls, ensuring that users have appropriate permissions tailored to their roles and responsibilities.
  • 2. Identity Federation: Seamlessly integrate Escape with your organization's Identity Provider (IdP). This feature simplifies user management while maintaining the highest security standards.
  • 3. SAML (Security Assertion Markup Language) Support: Integrate Escape with any SAML 2.0 compliant Identity Provider. This ensures secure and streamlined single sign-on capabilities.
  • 4. Single Sign-On (SSO): A more seamless login experience. Users can now access Escape using a single set of credentials, reducing password fatigue and enhancing security.

Your data security and user experience are of paramount importance to us. This update epitomizes our dedication to ensuring you benefit from a seamless, secure, and efficient authentication process in Escape. We encourage you to check out our documentation for detailed information and setup guides.

In Conclusion:

With these enhancements, we aim to simplify your interaction with Escape while maintaining the highest security standards. As always, your feedback drives our progress, and we're eager to hear your thoughts on these updates.

#21 · Scan Internal APIs using Escape's Proxy

In our pursuit to enhance security and provide more accessibility, we've rolled out a feature allowing users to scan their internal APIs, which is especially beneficial for those who can't whitelist IPs. By leveraging a custom proxy, this process becomes a breeze.

⚙️ What's New:

  • Custom Proxy Deployment: If you're unable to whitelist IPs but can deploy a service and expose its IP, you now have the flexibility of a custom proxy. While you can choose any proxy, the Escape proxy is readily available for use. Ensure to allow incoming traffic to this proxy via your firewall settings.

  • Essential Setup Information: To get started, you'll need a few details:

    • User: The user permitted to connect to the proxy. If you're using the Escape proxy, this would be your organization ID.
    • Password: The password for the aforementioned user. For the Escape proxy users, this translates to your API key.
    • IP & Port: The IP address and port to connect to your proxy.
  • Configuration Guide: For a step-by-step guide on setting up the proxy and integrating it into your scan configuration, please refer to our detailed documentation.

With this update, we continue to simplify and fortify the security scanning process for our users. The ability to scan internal APIs using a proxy not only fills a pivotal gap in security testing but also caters to a broader range of user requirements. Your insights shape our journey, and we're eager for your feedback on this new addition.

#20 · Announcing Escape's Public Status Page

📢 Announcing Escape's Public Status Page

In our continued commitment to transparency and reliability, we're excited to introduce Escape's Public Status Page. This page serves as your go-to source for real-time insights into our platform's uptime and Service Level Agreement (SLA) adherence.

⚙️ What's New:

  • 1. Real-Time Uptime Monitoring: Keep track of our platform's operational status instantly. You'll now have visibility into our uptime performance, ensuring you're always in the know.
  • 2. SLA Insights: Transparency is key. With our public status page, you can gauge our adherence to the promised Service Level Agreement, ensuring we're upholding our commitment to you.
  • 3. Instant Notifications: No more guesswork. Should any interruptions occur, our status page provides immediate notifications using RSS Feed, keeping you informed every step of the way.

Your trust in Escape is paramount, and this update is a testament to our dedication to being open, accountable, and reliable. We invite you to visit our status page and stay updated on our platform's performance. Your continued feedback propels us forward, and we're excited to keep innovating for you. Here's to continuous transparency and improved reliability!

#19 · [Enterprise] Enhanced Stability and Scalability

With the surge in our user base and the subsequent unprecedented load on our systems, we recognized the paramount importance of both stability and scalability. Following our recent migration to AWS, we've not only refined the platform's stability but also fortified its capability to scale effortlessly. Our joint efforts with the AWS Engineering team have resulted in an infrastructure that is both robust and scalable.

⚙️ What's New:

  • 1. Redesigned Architecture & Data Pipeline: Our move to AWS ushered in comprehensive changes in our infrastructure. This revamped architecture is tailored to facilitate streamlined processes and provide an optimized user experience.
  • 2. Progressive Rollout: To ensure a smooth transition and heightened user experience, we are progressively introducing our newly developed pipeline to our customers.
  • 3. Intensified Focus on Stability: Addressing the inconsistencies experienced over recent weeks, we've intensified our efforts to enhance stability. Our collaboration with AWS ensures an unwavering and reliable platform.
  • 4. Embracing Scalability: In the face of unprecedented system loads, our platform is now equipped to scale seamlessly, ensuring uninterrupted service even during peak usage times.

Your unwavering trust and continued partnership motivate us to elevate our platform's standards. This update epitomizes our dedication to ensuring you benefit from a seamless, stable, and scalable Escape. Your feedback drives our progress, and we're eager to hear your thoughts on these enhancements. Here's to a scalable, stable, and superior platform!

#18 · [Enterprise] Migration to North-American Servers

To better serve our valued customers and optimize performance, we're excited to announce our server migration. We have transitioned from European servers to North American Servers, bringing you a swifter and more responsive experience.

🚀 Key benefits:

  • 1. Closer Proximity to Our Primary Customer Base: The shift to North-American servers ensures that our primary customer base benefits from reduced latency and enhanced data accessibility.
  • 2. Faster Scans: Experience significant improvements in scan speeds, making your security checks and validations quicker than ever before.
  • 3. Optimized Performance: Leveraging the robust infrastructure of AWS in North America, users can anticipate a smoother, faster, and more reliable platform experience.

This strategic migration underscores our commitment to delivering unparalleled performance and value to our customers. We understand the importance of speed and reliability in today's digital landscape, and with this move, we aim to exceed your expectations. As always, your feedback is paramount. Together, let's redefine excellence!

#17 · [Enterprise] Audit Logs

In our continuous effort to enhance the security, transparency, and manageability of our platform, we're thrilled to unveil the much-anticipated Audit Logs feature. With Audit Logs, enterprises can now have a holistic view of user activity, ensuring better compliance and oversight.

📋 What's New:

  • Centralized User Activity Stream: A unified stream capturing all user activity, enabling organizations to monitor and control access to information for enhanced security and compliance.
  • Comprehensive Event Logging: Capture application-specific user activities, security events, administrative changes, and more.

🔒 Enhanced Security Features:

  • Immutability: Ensure data remains unaltered. Deleted objects retain a separate action record.
  • Admin Accessibility: Built-in audit log viewer in the application for easy access by enterprise account admins.
  • Search: Efficiently search into events and fields like Actor, Date, Action, and Description.

We believe that adding Audit Logs will significantly enhance the accountability and transparency of our platform. Your feedback and experience are vital to us. Together, let's create a safer and more efficient digital environment. Looking forward to more updates and improvements!

#16 · [Private Beta] Announcing Escape for REST APIs

After diligently focusing on GraphQL security, we are elated to venture into the realm of REST API Security Testing. Our commitment to enhancing API security is unwavering, and our latest offering showcases our dedication to this mission.

🔥 Key features

  • Expansion to REST: Building on our stellar track record with GraphQL, we've expanded our horizons to encompass REST API Security Testing. This beta support aims to broaden our security umbrella.
  • Feedback-Driven API Exploration Technology: This unique technology, initially crafted for GraphQL, has now been molded to cater to REST APIs, fortifying our ability to detect intricate business logic-aware security issues.
  • Comprehensive Security Testing: Our REST Security testing includes a suite of checks:
    • API Security Best Practices
    • Compliance with OWASP API Top 10 2023 (and more to come)
    • Detection of Advanced Business Logic issues, such as Sensitive Data Leaks

⏭️ Upcoming Features: Our roadmap for enhancing our REST offerings includes:

  • Specification-less REST API Scanning: Recognizing the limitations of tools that solely rely on OpenAPI/Swagger documentation or Postman collections, we're pioneering a new wave of specification-less REST API security testing.
  • Tailor-made remediation for various languages and frameworks such as Java Springboot, Express.js, and Django.
  • API Catalog: Automated REST API discovery for an exhaustive security audit.

🔭 A Glimpse into the Future:

Our vision goes beyond REST and GraphQL. We're prepping the foundation to embrace other API technologies like gRPC, tRPC, and even SOAP. The ultimate aim? Assisting developers and security teams in identifying and rectifying security lapses in application business logic.

To achieve this, we've conceptualized a meta-model of API that zeroes in on the core business logic, transcending mere implementation specifics. This strategy has already proven its mettle with REST and GraphQL, and we're poised to extend its prowess to other standards.

📣 Wrapping Up:

We're thrilled to launch our private beta support for REST API testing within Escape. This monumental step aligns perfectly with our ambition of simplifying security for developers and AppSec teams. Join us in this exciting phase by registering for the REST beta directly from the Escape Platform! We value your partnership and can't wait for you to experience the enhanced Escape.

Your journey with Escape has been remarkable, and with the introduction of REST API testing, we are taking another giant leap towards a more secure digital landscape. We're eager to hear your feedback, and together, we'll continue redefining API security standards. Cheers to a more secure, adaptable, and forward-thinking platform!

#15 · Attack Surface Management with API Inventory

Escape is proud to announce the beginning of its brand new: API Inventory. Just input your company's domain, and Escape will detect exposed GraphQL endpoints and give you an overview of your Attack Surface, leveraging state-of-the-art scanning techniques.

🎊 Key highlights:

  • Endpoint discovery: Automatically identify every GraphQL endpoint exposed on your domains and subdomains.
  • Surface checks: Instantly identify open Introspections, leaking Schemas through Field Suggestions and public endpoints.

🛡 Benefits:

  • Comprehensive Security View: Security Engineers are equipped with an enhanced dashboard. This provides a 360° view of all exposed GraphQL applications, ensuring proactive management and mitigation of potential security threats.
  • Automated Refresh: Reduce manual oversight and error. Automated refresh ensures regular scanning of your attack surface.

🔜 Upcoming Enhancements:

  • We're always innovating! Our current methodology employs subdomain enumeration for the external attack surface. We're excited about expanding our capabilities. Expect richer features and broader scanning abilities in the forthcoming releases. Your security, our priority.