Skip to content

2024

#43 · New Integrations & One-Click Configuration: Seamless Workflow Enhancements 🌐

Escape is excited to announce a significant update designed to streamline your workflow: New Integrations and One-Click Configuration. This update simplifies the integration process, making it more intuitive than ever to connect Escape with your tools and services.

Effortless Integration Setup 🖱️

  • One-Click Configuration: We’ve made setting up integrations a breeze with our new one-click configuration. Say goodbye to complex setup processes and hello to instant connectivity.
  • Detailed Logging: To ensure that connections are straightforward to debug, we’ve implemented detailed logging. This feature makes it easy to troubleshoot, ensuring your integrations work smoothly.
  • Enhanced Connectivity with Access Internal Networks: A groundbreaking feature of our new integrations is the ability to connect to internal networks. This enhancement broadens the scope of what's possible with Escape, offering more flexibility and coverage for your security needs.

Expanded Inventory Integrations 🛠️

Focusing on Inventory, our aim is to enrich your automated API inventory with even more integrations. Alongside existing connections with Github & Gitlab, we're thrilled to introduce integrations with:

  • Kong & Kong Gateway: Seamlessly connect with Kong ecosystems to enhance your API management and security.
  • AWS & Azure: Leverage integrations with major cloud service providers to ensure comprehensive visibility and security across your cloud infrastructure.

Why This Matters 🚀

The introduction of one-click configuration and new integrations significantly enhances your experience with Escape, making it easier, faster, and more comprehensive:

  • Simplify Your Workflow: Reduce setup time and effort, allowing you to focus on what matters—securing your APIs.
  • Enhanced Debugging: With detailed logging, diagnosing and solving integration issues is more straightforward, ensuring a smooth operational flow.
  • Broader Integration Coverage: The addition of new integrations, especially with internal networks, Kong, and major cloud providers, ensures a more extensive and enriched API inventory. This comprehensive coverage is crucial for a thorough security posture.

Embrace the simplicity and power of Escape’s new integration capabilities. Streamline your security workflow today and unlock the full potential of your API inventory management.

#42 · Elevate Your GraphQL Security with Escape's New AI-powered Scanner 🐦‍🔥

Escape proudly introduces our latest innovation in API security - the New GraphQL Scanner, a state-of-the-art tool designed specifically for GraphQL Security Assessment. As the sole pure-player in GraphQL security and a proud member of the GraphQL Foundation, Escape stands at the forefront of safeguarding GraphQL APIs.

Leading GraphQL Security 🔍

  • Top-Ranked Solution: Escape is recognized as the top-ranked GraphQL Security solution, setting the standard for comprehensive assessments.
  • Advanced AI Technology: Utilizing cutting-edge artificial intelligence, our scanner delves deep into the security of GraphQL APIs, identifying vulnerabilities with unmatched precision.
  • Extensive Test Suite: With over 100+ security tests, including 25 that are specifically tailored to GraphQL business logic, our tool offers unparalleled coverage. Explore our tests in detail here.

Unmatched Testing Capabilities 🛠️

  • Exclusive GraphQL Support: Escape's scanner is the only tool designed to thoroughly assess GraphQL APIs, providing depth in testing that’s second to none.
  • Versatile Scan Modes: Catering to diverse needs, our scanner features different modes, including a rapid "surface scan" for OWASP TOP 10 assessments and a "business logic mode" perfect for CI/CD pipelines. Learn more about our scan modes here.
  • CI/CD Ready: Our business logic mode is optimized for CI/CD environments, ensuring comprehensive business logic scans in just a few minutes - ideal for fast-paced development cycles.
  • Scalability for Large APIs: The scanner is adept at handling extensive APIs, including Federated ones, ensuring no API is too large for a thorough security review.

Why Choose Escape for GraphQL Security? ✨

Choosing Escape's New GraphQL Scanner means not only employing the most thorough tool on the market but also aligning with a solution that’s been crafted by the leading experts in GraphQL security. Whether you're looking to conduct quick assessments or in-depth reviews, our scanner provides the flexibility, depth, and precision needed to secure your GraphQL APIs effectively.

Elevate your GraphQL security with Escape and ensure your APIs are protected by the best. Join us in redefining the standards of API security and stay ahead of threats with our advanced GraphQL scanner.

#41 · AI-Driven Prioritization: Smarter Security Insights for Immediate Action 🧠

We're thrilled to introduce a groundbreaking addition to the Escape platform that's set to transform how you prioritize security issues within your organization. Leveraging the power of Artificial Intelligence, we've created a new section that synergizes results from both the Inventory and Testing phases, offering you a Smart Prioritization of issues based on their risk level.

From Overwhelming to Actionable ✨

  • Beyond Numbers: Move away from daunting lists like "I have a total of 34 injection vulnerabilities in my organization" to precise, actionable insights. For example, the AI helps you pinpoint critical issues such as "Among those injection vulnerabilities, one is on a publicly-accessible payment API exposed on the internet that manipulates personally identifiable information". This clarity ensures you know exactly what needs your attention first.
  • Risk-Level Awareness: Understand the gravity of each vulnerability in the context of your organization's unique environment, allowing you to allocate your resources more effectively and mitigate the most significant threats first.

Why Smart Prioritization Matters 🚀

  • Focused Efforts: Concentrate on fixing the most critical vulnerabilities that pose the greatest risk to your organization, ensuring a stronger security posture.
  • Efficient Resource Allocation: Maximize the impact of your security team by directing their efforts toward mitigating high-priority issues.
  • Faster Response Time: With clear prioritization, respond to and remediate vulnerabilities more swiftly, reducing the window of opportunity for attackers.
  • Strategic Planning: Use AI-driven insights for strategic planning and strengthening your overall security framework, focusing on areas of highest risk.

Leverage AI for Enhanced Security 🛡️

This AI-driven approach to prioritizing security issues represents a significant leap forward in cybersecurity management. By integrating smart prioritization into your security strategy, you're not just reacting to threats; you're anticipating them and acting with precision and confidence. Transform your security posture with Escape's AI-driven insights and stay one step ahead in safeguarding your organization's assets.

#40 · Fine-Tuned Alerting & Notifications: Stay Ahead of Security Concerns 🔔

Escape is thrilled to introduce our enhanced Alerting and Notifications system, now with seamless integrations including Teams, Slack, Discord, Webhooks, and Email. This upgrade is designed to keep API owners in the loop with real-time alerts on new issues identified during testing, and notifications when a new API is discovered by our Inventory system.

Tailored to Your Needs 🛠️

  • Highly Configurable: Dive into a wealth of configuration options to tailor alerts and notifications to fit your specific needs. Whether you prefer detailed reports or succinct summaries, our system can be adjusted to your preferences.
  • User-Friendly: Despite its depth of options, our alerting system is incredibly straightforward to use, ensuring you can set up and customize your notifications without any hassle.

Stay Informed, Always 🌐

  • Immediate Notifications: Receive alerts as soon as new security issues are detected or new APIs are discovered, enabling swift action.
  • Comprehensive Coverage: Our system is designed to keep you informed on all fronts, from testing updates to inventory changes, ensuring you have a full overview of your API landscape.

Seamless Integration & Migration ✨

  • Widespread Integration: With support for popular platforms like Teams, Slack, Discord, and more, you can receive alerts through the channels you use every day.
  • Default Notifications: To ensure immediate value, we've set up default notifications for all organizations, getting you started right out of the box.
  • Smooth Migration: For users of our previous notifications system, we've seamlessly migrated your settings, ensuring a smooth transition with no action required on your part.

Empowering Your Security Posture 🚀

Our fine-tuned Alerting and Notifications system is not just an upgrade; it's a transformation in how you stay informed about your API security. It's designed to be as powerful or as simple as you need, ensuring

#39 · Enhanced Reporting: 8 New Graphs for Unmatched Security Insights 📊

We're excited to unveil a significant upgrade to our Reporting features, designed to provide you with a comprehensive overview of your organization's security posture. Our enhanced reporting now includes 8 insightful graphs, each crafted to offer a deeper understanding of your API security landscape.

Explore the New Graphs 📈

  • Open Security Issues: Get a clear snapshot of unresolved security vulnerabilities within your organization.
  • Open and Closed Issues Over Time: Track how security issues are being resolved over time, highlighting your team's responsiveness to threats.
  • Most Vulnerable APIs: Identify which of your APIs are most at risk, allowing for prioritized and focused security efforts.
  • Average API Health: Understand the overall health of your APIs at a glance, with scores based on security assessments.
  • Security Issues Over Time: Visualize how security issues fluctuate over time, revealing trends and the effectiveness of your security measures.
  • Most Critical Issues: Focus on the most pressing security vulnerabilities with a graph highlighting the issues that require immediate attention.
  • Top Endpoints to Scan Next: Get recommendations on which endpoints to prioritize in your next scans, based on vulnerability assessments.
  • Active Scan Coverage: Measure the extent of your scanning efforts across your API landscape, ensuring comprehensive security coverage.

Why This Matters for Your Security 🛡️

  • Proactive Security Management: Armed with these insights, you can proactively manage your organization's security posture, addressing vulnerabilities before they can be exploited.
  • Data-Driven Decisions: Make informed decisions on where to allocate resources, focusing on areas with the most significant security impact.
  • Trend Analysis: Understand how security trends evolve over time, enabling you to adjust your strategies to emerging threats.
  • Comprehensive Overview: Gain a holistic view of your organization's security health, fostering a culture of transparency and continuous improvement.
  • Efficiency and Prioritization: Streamline your security efforts by prioritizing the most critical issues and vulnerable APIs, ensuring optimal use of your time and resources.

Embrace the Power of Insightful Reporting 🌟

With these new graphs, Escape arms you with the tools you need to secure your APIs effectively. Embrace the benefits of enhanced reporting and take your organization's security to the next level. By understanding your security landscape in depth, you can foster a more secure, resilient, and efficient API ecosystem.

#38 · Simplify Your Security with Our New Configuration Stepper for Business Logic Testing 🌟

We're rolling out a groundbreaking update that makes Business Logic Dynamic Application Security Testing (DAST) more accessible and efficient than ever. Introducing our Brand New Configuration Stepper - your gateway to simplified, yet powerful security scans.

Quick and Easy Starts 🚀

  • Straightforward Scanning: Start your Business Logic DAST scans in just a few seconds with our intuitive Configuration Stepper. It's designed to guide you smoothly through the setup process, with pre-filled fields to save you time.
  • Comprehensive Configuration Options: Tailor your scans with precision. Choose your network, including Static IP and Internal Networks, configure authentication effortlessly, and upload schemas for REST (OpenAPI, Swagger, WP-JSON, Postman, Insomnia) or GraphQL Schema/Introspection for GraphQL.
  • Debugging Made Simple with Innovative Logging: The killer feature? Detailed logs that not only help you debug with ease but also guide you every step of the way. Troubleshooting has never been this straightforward.

Power in Your Hands ✨

Our new Configuration Stepper demystifies the complexity of Business Logic DAST, making thorough business logic security testing accessible to everyone. It’s not just about ease of use; it’s about empowering you with a tool that’s both incredibly simple and remarkably powerful.

Leap into the Future of DAST 🌈

Gone are the days of cumbersome setup processes. With our latest update, beginning a scan is a matter of a few clicks and seconds. We’re putting the power of comprehensive security testing in the hands of developers and security engineers alike. Start exploring the full potential of your API security with Escape today, and step into a world where thorough security testing is within everyone’s reach.

#37 · Introducing Escape Rules: Custom Security Tests Made Simple 🛡️

Hey Escape community! We're thrilled to announce a game-changer in API security testing - Escape Rules. Say goodbye to the days of rigid, hard-to-maintain business logic tests. Our latest innovation offers a fresh, dynamic approach to secure your APIs against the ever-evolving threat landscape.

Why Escape Rules?

  • Flexibility at its Best: Traditional tests, including Nuclei or bChecks, quickly become outdated as your APIs or databases evolve. Escape Rules are designed to adapt, ensuring your security tests remain relevant and robust.
  • Designed for All: Whether you're a security engineer or a developer, Escape Rules speaks your language. It's crafted to be intuitive, making the creation of business logic tests a breeze.
  • Universal Compatibility: By default, tests created with Escape Rules are automatically compatible with both REST and GraphQL APIs, ensuring broad coverage across your API landscape.

Dive Deeper 📚

Curious about how to leverage this powerful tool? We've got you covered:

Your Turn to Escape the Ordinary 🎉

With Escape Rules, your API security testing is not just about finding vulnerabilities; it's about embracing adaptability, community, and innovation. Let's redefine the boundaries of API security together. Start crafting your custom security tests today and stay one step ahead of the threats!

#36 · Elevate Your DAST Scans with Dynamic Authentication Token Generation! 🌟🔒

Exciting news for all Escape users! We're rolling out a game-changing enhancement on the scan authentication feature: Dynamic Authentication Token Generation for DAST scans. This feature is about empowering your scans with real-world authentication scenarios.

What's New?

  • Generate Authentication Credentials Automatically: Start every DAST scan with fresh, automatically generated credentials. Whether it's tokens or other forms of authentication, we've got you covered.
  • Run Scans with Multiple User Profiles: Simulate different user levels in your scans - from admins to standard users. This allows you to comprehensively test your APIs from various security standpoints.
  • Effortless Authentication for Any API: With our versatile framework, authenticate against any type of API – REST, GraphQL, or anything else.

Key Enhancements:

  • Workflow-Driven Authentication: Tailored to fit a variety of server interactions, ensuring seamless token generation and application.
  • Credential Management: Efficient extraction and injection of authentication data into your scans.
  • Detailed Logging: Track every step of the authentication process with our comprehensive logs.
  • Session Management and Refresh: Manage and automatically refresh tokens based on their TTL, or configure manually if needed.

Supported Authentication Methods:

  • AWS Cognito
  • Basic
  • cURL & cURL Sequence
  • Digest
  • GraphQL
  • Headers
  • HTTP
  • OAuth (Client Credentials, User Password)
  • Webdriver
  • Custom Workflows involving multiple HTTP Requests and Webdriver actions

Dive Into Action:

This update opens up a new realm of possibilities for your API security testing. By incorporating real-world authentication scenarios, your DAST scans are now more thorough and realistic than ever. Get ready to unleash the full potential of your API security with Escape!

#35 · Comprehensive Compliance Posture at a Glance 👮

Hey there,

We've brewed something special at Escape that's going to make your security life a whole lot easier (and a bit more fun)! Introducing the Compliance Matrix now available in the Reporting Tab.

What's Cooking?
  • All-in-One View: Get a bird's eye view of your organization's compliance posture across all applications. One matrix, complete overview!
  • Comprehensive Compliance Coverage: Supports a robust list of standards including OWASP TOP 10, PCI-DSS, GDPR, SOC 2, PSD 2, ISO 27001, NIST, NIS2 and FedRamp.
Why It's a Game-Changer for Security Pros:
  1. Holistic Compliance Overview: Quickly see where each application stands in terms of various compliance standards. This is crucial for maintaining a secure and compliant digital environment across the board. 📜
  2. Saves Time & Effort: No more jumping between reports or tools. Everything you need to know about compliance is in one place. More time for coffee! ☕
  3. Actionable Insights: Identify gaps in compliance across all applications at a glance. This enables faster decision-making and prioritization of security efforts. ⚡
  4. Streamlines Reporting: Makes reporting to stakeholders a breeze. Presenting compliance status has never been this straightforward. 📊
  5. Future-Proofing: As your organization grows, so does the complexity of managing compliance. The Compliance Matrix scales with you, ensuring you're always on top of your security game. 📈

So, dive into the Reporting Tab, check out the new Compliance Matrix, and get ready to experience a smoother, more integrated approach to managing your organization's compliance. Happy securing!

Your team at Escape