Skip to content

Release Notes

#69 · Automated API Schema Generation for C#

Automated API Schema Generation is now possible from C#!

Building APIs in C#? No need to worry about maintaining your API specifications anymore. You can effortlessly generate API specifications directly from your C# code.

Escape scans your codebase, analyzes your API's code, and generates precise specifications, saving you time and effort while ensuring accuracy.

To learn more about how automated API specification generation works, visit our documentation: Code to Cloud: API Schema Generation.

We look forward to seeing how this helps streamline your API development and security workflows. As always, your feedback is welcome!

#68 · Escape + Wiz: Unified Security for Modern, Cloud-Native Applications

We’re excited to announce our new integration with Wiz, bringing together Escape’s deep application-layer insights with Wiz’s unparalleled cloud security capabilities. This partnership empowers security teams with:

  • Practical Code-to-Cloud Security: Large organizations often struggle to bridge application-level exposures with cloud infrastructure insights. Now, they can see both in one place, track them back to the same responsible teams, and reduce friction between dev, ops, and security.
  • Immediate Assignment: The moment Escape flags a security issue, you know exactly which team needs to address it. No more guesswork, no more rummaging through outdated confluence pages or domain registries.
  • Acceleration of Remediation: When ownership data is at your fingertips, the gap between detection and remediation shrinks from weeks or months to days or even hours. It’s not just about finding vulnerabilities; it’s about fixing them fast. This empowers you to integrate security into applications early in the development lifecycle confidently.
  • Reduced Operational Overhead: Security Engineers spend less time “hunting” for who owns what. Instead, they can devote their energy to actually securing the organization. That leads to more strategic work, less administrative burden, and a meaningful drop in burnout.

How it works:

image.png

  1. Wiz External Attack Surface Management finds exposed cloud resources and hands them over to Escape.
  2. Escape Inventory then identifies, fingerprints, and classifies these resources as specific application assets—such as APIs, Single-Page Applications (SPAs), and more.

escape-interface-with-wiz.png

  1. With this enriched information, Escape DAST runs at scale on the identified applications, including APIs, without needing any network interception or agent installation.

💡 If you're a joint Wiz and Escape customer, you can find step-by-step instructions on how to set up Wiz integration in the Escape's official documentation. Feel free to set it up now 😉

#67 · Improved Postman Collections Support

We’ve drastically enhanced our support for Postman Collections!

Our DAST scanner now parses collections more effectively, even when they’re poorly implemented—a common issue we’ve addressed head-on. Postman Collections, by design, provide examples of API requests, and with this improvement, we ensure better accuracy and coverage for your scans, no matter the quality of the collection.

#66 · Enhanced Support for OpenAPI Specs with cURL Examples

We’re excited to announce that our DAST scanner now supports OpenAPI specifications with cURL traffic examples, including those built using extensions like Redocly. This enhancement leverages real-world examples to boost scan quality and simplify your security testing process.

What's new

OpenAPI specifications can include cURL traffic examples to demonstrate specific API requests and responses. With this update, our DAST scanner can now parse OpenAPI specs with embedded cURL examples and use them to initiate scans.

We’ve also added support for Redocly, a tool that simplifies creating OpenAPI specs enriched with cURL examples, ensuring seamless integration into your workflows.

How It Works

  1. Prepare Your OpenAPI Spec:

Use tools like Redocly to build your OpenAPI specification, embedding cURL examples to document API behavior and parameters.

  1. Upload the Spec to the DAST Scanner:

  2. Go to Security Scan and click New Application

  3. Select REST API
  4. Upload your OpenAPI spec with cURL examples

3.Run the Scan:

The scanner will parse the OpenAPI spec, leverage the cURL examples for precise API interactions, and begin testing for vulnerabilities!

#65 · Burp Suite Exports Support for REST API Scanning in DAST

We’re excited to introduce another great capability for our DAST scanner: support for Burp Suite exports as REST API schemas. This enhancement streamlines your workflow by allowing you to leverage Burp Suite traffic captures to define your API schema, ensuring more comprehensive and efficient vulnerability scans.

What are Burp Suite Exports, and why use them?

Burp Suite is a widely-used tool for security testing, and its exports provide detailed records of HTTP traffic captured during web application testing. With this update, our DAST scanner can now ingest Burp Suite exports to interpret and scan REST APIs.

How it works

  1. Capture Traffic with Burp Suite

Use Burp Suite to intercept and record API traffic during your testing session. Export the captured data in the supported format.

  1. Upload to DAST Scanner Configure your scan in a few easy steps:

  2. Go to Security Scan and click New Application.

  3. Select REST API.
  4. Configure your Network and Authentication settings (if required).
  5. Upload the Burp Suite export file to define your API schema.

3.Initiate the Scan

The scanner parses the Burp Suite export, identifying endpoints, HTTP methods, and other critical details. Start the scan to analyze your API for vulnerabilities.

We hope this new feature helps streamline your security testing workflow. And of course, we wish you not too many criticals found 😉

#64 · HAR File Support for REST API Scanning in DAST

We're excited to announce a new capability for our DAST scanner: support for HAR files as REST API schemas. This enhancement offers you greater flexibility when scanning your APIs for vulnerabilities, especially since generating a HAR file can be faster and easier than creating or maintaining a Swagger/OpenAPI specification.

What are HAR files?

HTTP Archive (HAR) files are JSON-formatted files that capture network activity, including requests and responses, between a client and a server during a browsing session. With this update, our DAST scanner can now ingest HAR files to interpret and scan REST APIs, simplifying the scanning process and expanding its capabilities.

What are the benefits?

HAR files capture actual API interactions, including dynamically generated requests and responses during runtime. This is particularly useful in scenarios such as:

  • Dynamic or undocumented APIs: When API behavior depends on real-time parameters or session states that aren’t fully documented in Swagger or OpenAPI.
  • Legacy or incomplete documentation: For APIs lacking comprehensive or up-to-date schemas. Additionally, HAR files reflect real-world usage, uncovering hidden or undocumented endpoints and specific request variations that static schemas might miss. This leads to more thorough scans and improved vulnerability detection.

How it Works?

  1. Generate a HAR file by capturing the API traffic using tools like browser developer tools or network monitoring software.
  2. Upload the HAR file to the DAST scanner via the API schema configuration interface:

  3. Go to Security scan and click on New Application

  4. Select REST API
  5. Configure your Network and Authentication (if needed)
  6. Upload the HAR file to define your API schema
3.Initiate the scan
Once uploaded, the scanner parses the HAR file, automatically identifying API endpoints, HTTP methods, parameters, and other details. Start the scan and let the DAST scanner analyze your API for vulnerabilities.

Start scanning smarter, not harder 😉

#63 · Manage Labels at the Org Level

We have enhanced the existing app label management functionality to provide better organization-level control and scalability. Previously, labels were managed on a per-service basis, but now you can define and update labels centrally at the organization level while still retaining the flexibility to assign and customize labels at the service level.

What are Labels?

Service labels are custom tags that help you categorize, filter, and organize your applications. They are especially useful for teams managing large numbers of apps or workflows.

How it works

  1. Navigate to the Organization Settings by clicking on the name of your org.
  2. Select the Labels section. Screenshot 2024-12-17 at 14.53.22.png
  3. Create or update org-level labels with names and dedicated colors.
  4. Go back to Inventory -> All Services, click on the Service, and assign a dedicated label to the service in question. Screenshot 2024-12-17 at 14.54.19.png
  5. You can also add a label to each scanned application by going to the Security Scan -> Tested Applications page and clicking on the plus button. Add as many labels as you want! Screenshot 2024-12-17 at 14.57.27.png

Improvement Highlights

Org-Level Label Management

You can now create and update standardized labels at the organization level. Existing app-level labels will remain unaffected unless explicitly overridden.

Permissions Control

Organization admins and editors retain exclusive permissions to manage org-level labels.

Users with viewer permissions can view or use these labels without altering org-level definitions.

Simplified Bulk Updates

Modifications made to org-level labels automatically propagate to all associated apps, reducing manual updates.

Now it's the perfect time to organize your inventory 😉

#62 · New Kubernetes Integration: Discover APIs in Kubernetes

As organizations scale their Kubernetes deployments, the number of services and APIs grows rapidly. Maintaining visibility into these resources is critical for securing the API attack surface and ensuring compliance.

Escape now supports Kubernetes integration, enabling users to discover services running in their Kubernetes clusters.

This integration simplifies the process of discovering undocumented and shadow APIs within your clusters, reducing operational risks and improving governance.

How it works?

Escape will read the services and ingresses defined in your cluster, determine if they are APIs, and will make them visible in the Escape Inventory.

Getting started

Step 1: Set Up a Private Location

You need to configure a Private Location as a Kubernetes deployment for Escape to interact with your cluster.

Step 2: Create Service Account and ClusterRoleBinding

To allow this deployment to access resources in your Kubernetes cluster, you need to create a Service Account and a ClusterRoleBinding.

You can use the sample YAML from the Escape documentation to create these authorizations (replace default with the right namespace if needed).

Step 3: Bind the Service Account

Add the following line to the spec section of your deployment YAML to bind the Service Account to the pod: serviceAccountName: escape-repeater

Step 4: Monitor Discovered APIs

Once the integration is enabled, Escape will automatically identify and display APIs in the All Services section of your inventory, allowing you to take further actions like securing, auditing, or analyzing them.

Not sure if your Kubernetes clusters have APIs? Now's the perfect time to find out! Integrate your Kubernetes with Escape and enrich your API inventory.

#61 · Escape SPA DAST Now in Beta

Modern web applications demand modern security solutions. That’s why we’re excited to announce Escape’s security platform expansion into single-page application (SPA) security testing.

We're now in closed beta. We're looking for additional users to test it out and provide feedback.

🔗 Sign up here for the closed beta

What we built

In addition to its unique, feedback-driven DAST for APIs, Escape now offers Dynamic Application Security Testing (DAST) for SPAs. This is more than just an incremental feature—it’s a powerful extension of our API security platform. Our new front-end DAST is specifically designed to detect vulnerabilities in single page applications and highlight business logic errors.

With Escape’s DAST, you'll be able to identify common static vulnerabilities, CVEs, secret leaks, and outdated or vulnerable dependencies while automatically detecting the APIs consumed by your applications (both internal and third-party) and seamlessly syncing with your existing API security workflows. The tool reinforces our API DAST capabilities by accessing more context and user stories.

What makes Escape's DAST for SPAs stand out

  • Automated Authentication: Simply enter your credentials, and the front end handles the rest. Custom manual authentication is still available.
  • Schema-Driven Precision: Your application schema can be programmatically updated to keep Escape synced with your endpoint’s evolving structure. No manual maintenance required.
  • Tailored for Front-End: While still evolving, Escape leverages our proprietary business logic algorithm, initially designed for APIs, to gain a deeper understanding of single-page applications. This allows us to detect vulnerabilities where traditional tools often struggle, with continuous improvements as we learn more about the unique challenges of front-end security.
  • Automatic API Detection, Mapping, and Security: Escape automatically detects and maps the APIs consumed by your front-end application, including both internal and third-party APIs. We generate specifications for each API and test them for vulnerabilities immediately.
  • Unified Security Insights: Vulnerability data is linked to API insights, giving you a comprehensive view of your attack surface.

Next step - Remediations: As with our DAST for APIs, we plan to customize each remediation code snippet to align with specific frameworks in the near future.

Want to help us make Escape DAST better?

🔗 Sign up here for the closed beta

With this new front-end testing feature, we’re delivering a solution that doesn’t just work but works smarter, helping teams focus on fixing vulnerabilities rather than fighting with tools.

#60 · New updates to Escape's Public API

We’re excited to announce two powerful updates to Escape's Public API, designed to enhance your workflow and make application management even more efficient:

  1. Search Endpoint /organization/{id}/applications/search​: Effortlessly locate and filter your applications with this new endpoint. Save time and streamline your workflows by quickly accessing the information you need.
  2. Scheduling via /create-application:

  3. Custom Scanning Schedules: Use cron in the request body to specify the exact frequency of your scans.

  4. Disable Scheduling: Flexibly manage scans by disabling the schedule through disable scheduling in the same endpoint.

Getting started

Ready to explore these new features? Check out the documentation for details:

🔗 Search Applications Endpoint

🔗 Scheduling Features