Skip to content

Release Notes

#39 ยท Enhanced Reporting: 8 New Graphs for Unmatched Security Insights ๐Ÿ“Š

We're excited to unveil a significant upgrade to our Reporting features, designed to provide you with a comprehensive overview of your organization's security posture. Our enhanced reporting now includes 8 insightful graphs, each crafted to offer a deeper understanding of your API security landscape.

Explore the New Graphs ๐Ÿ“ˆ

  • Open Security Issues: Get a clear snapshot of unresolved security vulnerabilities within your organization.
  • Open and Closed Issues Over Time: Track how security issues are being resolved over time, highlighting your team's responsiveness to threats.
  • Most Vulnerable APIs: Identify which of your APIs are most at risk, allowing for prioritized and focused security efforts.
  • Average API Health: Understand the overall health of your APIs at a glance, with scores based on security assessments.
  • Security Issues Over Time: Visualize how security issues fluctuate over time, revealing trends and the effectiveness of your security measures.
  • Most Critical Issues: Focus on the most pressing security vulnerabilities with a graph highlighting the issues that require immediate attention.
  • Top Endpoints to Scan Next: Get recommendations on which endpoints to prioritize in your next scans, based on vulnerability assessments.
  • Active Scan Coverage: Measure the extent of your scanning efforts across your API landscape, ensuring comprehensive security coverage.

Why This Matters for Your Security ๐Ÿ›ก๏ธ

  • Proactive Security Management: Armed with these insights, you can proactively manage your organization's security posture, addressing vulnerabilities before they can be exploited.
  • Data-Driven Decisions: Make informed decisions on where to allocate resources, focusing on areas with the most significant security impact.
  • Trend Analysis: Understand how security trends evolve over time, enabling you to adjust your strategies to emerging threats.
  • Comprehensive Overview: Gain a holistic view of your organization's security health, fostering a culture of transparency and continuous improvement.
  • Efficiency and Prioritization: Streamline your security efforts by prioritizing the most critical issues and vulnerable APIs, ensuring optimal use of your time and resources.

Embrace the Power of Insightful Reporting ๐ŸŒŸ

With these new graphs, Escape arms you with the tools you need to secure your APIs effectively. Embrace the benefits of enhanced reporting and take your organization's security to the next level. By understanding your security landscape in depth, you can foster a more secure, resilient, and efficient API ecosystem.

#38 ยท Simplify Your Security with Our New Configuration Stepper for Business Logic Testing ๐ŸŒŸ

We're rolling out a groundbreaking update that makes Business Logic Dynamic Application Security Testing (DAST) more accessible and efficient than ever. Introducing our Brand New Configuration Stepper - your gateway to simplified, yet powerful security scans.

Quick and Easy Starts ๐Ÿš€

  • Straightforward Scanning: Start your Business Logic DAST scans in just a few seconds with our intuitive Configuration Stepper. It's designed to guide you smoothly through the setup process, with pre-filled fields to save you time.
  • Comprehensive Configuration Options: Tailor your scans with precision. Choose your network, including Static IP and Internal Networks, configure authentication effortlessly, and upload schemas for REST (OpenAPI, Swagger, WP-JSON, Postman, Insomnia) or GraphQL Schema/Introspection for GraphQL.
  • Debugging Made Simple with Innovative Logging: The killer feature? Detailed logs that not only help you debug with ease but also guide you every step of the way. Troubleshooting has never been this straightforward.

Power in Your Hands โœจ

Our new Configuration Stepper demystifies the complexity of Business Logic DAST, making thorough business logic security testing accessible to everyone. Itโ€™s not just about ease of use; itโ€™s about empowering you with a tool thatโ€™s both incredibly simple and remarkably powerful.

Leap into the Future of DAST ๐ŸŒˆ

Gone are the days of cumbersome setup processes. With our latest update, beginning a scan is a matter of a few clicks and seconds. Weโ€™re putting the power of comprehensive security testing in the hands of developers and security engineers alike. Start exploring the full potential of your API security with Escape today, and step into a world where thorough security testing is within everyoneโ€™s reach.

#37 ยท Introducing Escape Rules: Custom Security Tests Made Simple ๐Ÿ›ก๏ธ

Hey Escape community! We're thrilled to announce a game-changer in API security testing - Escape Rules. Say goodbye to the days of rigid, hard-to-maintain business logic tests. Our latest innovation offers a fresh, dynamic approach to secure your APIs against the ever-evolving threat landscape.

Why Escape Rules?

  • Flexibility at its Best: Traditional tests, including Nuclei or bChecks, quickly become outdated as your APIs or databases evolve. Escape Rules are designed to adapt, ensuring your security tests remain relevant and robust.
  • Designed for All: Whether you're a security engineer or a developer, Escape Rules speaks your language. It's crafted to be intuitive, making the creation of business logic tests a breeze.
  • Universal Compatibility: By default, tests created with Escape Rules are automatically compatible with both REST and GraphQL APIs, ensuring broad coverage across your API landscape.

Dive Deeper ๐Ÿ“š

Curious about how to leverage this powerful tool? We've got you covered:

Your Turn to Escape the Ordinary ๐ŸŽ‰

With Escape Rules, your API security testing is not just about finding vulnerabilities; it's about embracing adaptability, community, and innovation. Let's redefine the boundaries of API security together. Start crafting your custom security tests today and stay one step ahead of the threats!

#36 ยท Elevate Your DAST Scans with Dynamic Authentication Token Generation! ๐ŸŒŸ๐Ÿ”’

Exciting news for all Escape users! We're rolling out a game-changing enhancement on the scan authentication feature: Dynamic Authentication Token Generation for DAST scans. This feature is about empowering your scans with real-world authentication scenarios.

What's New?

  • Generate Authentication Credentials Automatically: Start every DAST scan with fresh, automatically generated credentials. Whether it's tokens or other forms of authentication, we've got you covered.
  • Run Scans with Multiple User Profiles: Simulate different user levels in your scans - from admins to standard users. This allows you to comprehensively test your APIs from various security standpoints.
  • Effortless Authentication for Any API: With our versatile framework, authenticate against any type of API โ€“ REST, GraphQL, or anything else.

Key Enhancements:

  • Workflow-Driven Authentication: Tailored to fit a variety of server interactions, ensuring seamless token generation and application.
  • Credential Management: Efficient extraction and injection of authentication data into your scans.
  • Detailed Logging: Track every step of the authentication process with our comprehensive logs.
  • Session Management and Refresh: Manage and automatically refresh tokens based on their TTL, or configure manually if needed.

Supported Authentication Methods:

  • AWS Cognito
  • Basic
  • cURL & cURL Sequence
  • Digest
  • GraphQL
  • Headers
  • HTTP
  • OAuth (Client Credentials, User Password)
  • Webdriver
  • Custom Workflows involving multiple HTTP Requests and Webdriver actions

Dive Into Action:

This update opens up a new realm of possibilities for your API security testing. By incorporating real-world authentication scenarios, your DAST scans are now more thorough and realistic than ever. Get ready to unleash the full potential of your API security with Escape!

#35 ยท Comprehensive Compliance Posture at a Glance ๐Ÿ‘ฎ

Hey there,

We've brewed something special at Escape that's going to make your security life a whole lot easier (and a bit more fun)! Introducing the Compliance Matrix now available in the Reporting Tab.

What's Cooking?
  • All-in-One View: Get a bird's eye view of your organization's compliance posture across all applications. One matrix, complete overview!
  • Comprehensive Compliance Coverage: Supports a robust list of standards including OWASP TOP 10, PCI-DSS, GDPR, SOC 2, PSD 2, ISO 27001, NIST, NIS2 and FedRamp.
Why It's a Game-Changer for Security Pros:
  1. Holistic Compliance Overview: Quickly see where each application stands in terms of various compliance standards. This is crucial for maintaining a secure and compliant digital environment across the board. ๐Ÿ“œ
  2. Saves Time & Effort: No more jumping between reports or tools. Everything you need to know about compliance is in one place. More time for coffee! โ˜•
  3. Actionable Insights: Identify gaps in compliance across all applications at a glance. This enables faster decision-making and prioritization of security efforts. โšก
  4. Streamlines Reporting: Makes reporting to stakeholders a breeze. Presenting compliance status has never been this straightforward. ๐Ÿ“Š
  5. Future-Proofing: As your organization grows, so does the complexity of managing compliance. The Compliance Matrix scales with you, ensuring you're always on top of your security game. ๐Ÿ“ˆ

So, dive into the Reporting Tab, check out the new Compliance Matrix, and get ready to experience a smoother, more integrated approach to managing your organization's compliance. Happy securing!

Your team at Escape

#34 ยท Enhanced Scanning Capabilities through Insomnia Collections & WP-JSON Schema support ๐ŸŒ

We're excited to share a significant expansion in our Dynamic Application Security Testing (DAST) capabilities. Escape now supports a broader range of input formats, catering to diverse API testing needs and environments. ๐Ÿ› ๏ธ

Expanded Input Support ๐Ÿ”

  • Insomnia Collections: Extend your DAST capabilities to include Insomnia Collections, enabling seamless security testing for those utilizing this popular API tool.
  • WP-JSON Schema: Specifically for WordPress users, we now support WP-JSON Schema, enhancing security testing for WordPress-based APIs.
  • Continued Support for Existing Formats: Our DAST feature maintains its robust support for:
    • Swagger v2
    • OpenAPI v3
    • Postman Collection
    • GraphQL Introspection
    • GraphQL Schema

Why This Matters? ๐ŸŒŸ

  • Broader Testing Reach: Cover a wider range of API formats, ensuring comprehensive security coverage across different platforms and tools.
  • Versatility in Security Testing: Adapt to various API design and documentation practices, offering flexibility and precision in security testing.
  • Ease of Integration: Smoothly incorporate these new formats into your existing security workflows, enhancing efficiency without compromising on thoroughness.

๐Ÿ” Your Security, Our Commitment We continue to evolve our DAST capabilities to keep pace with the dynamic world of API security. Stay tuned for more updates as we constantly strive to provide top-tier security solutions.

Stay Proactive, Stay Secure!

#33 ยท New AI-Powered Business Logic Security Tests for Enhanced Access Control ๐Ÿง 

We're proud to introduce a suite of advanced AI-powered security tests at Escape Tech, specifically designed to fortify access control in your applications. Leveraging state-of-the-art artificial intelligence, these tests are engineered to uncover complex business logic vulnerabilities and attack chains with unprecedented precision. ๐Ÿค–

Cutting-Edge Security Checks ๐Ÿš€

  • Automated Tenant Isolation Control: When two users are configured, this test ensures strict tenant isolation, preventing unauthorized cross-tenant access.
  • Sensitive Endpoint Brute Force: Targets critical endpoints like login and reset-password, safeguarding against brute force attacks.
  • Broken Object Level Authorization (IDOR) Checks: Identifies vulnerabilities in object-level authorizations, an essential aspect of access control.
  • Enhanced Access Control Checks: Overall improvements in access control validations, providing a more robust security posture.
  • Public State Altering Operation Identification: Ensures that operations altering application data (like REST READ, UPDATE, DELETE requests, and GraphQL mutations) are adequately protected by authentication middleware.

The AI Edge ๐ŸŒ

These tests utilize advanced AI algorithms to generate complex sequences of requests, meticulously uncovering and exploiting business logic flaws and potential attack vectors. This approach allows for the detection of intricate vulnerabilities and attack chains that conventional methods might miss.

Compatibility and Documentation ๐Ÿ”—

  • REST & GraphQL Compatibility: Our security tests are compatible with both REST and GraphQL APIs, ensuring comprehensive coverage across different API architectures.
  • Detailed Documentation: Dive into our comprehensive guide to understand how these AI-powered tests can be integrated into your security strategy.

Elevating Security Intelligence ๐ŸŒŸ

By harnessing AI in security testing, we're pushing the boundaries of traditional cybersecurity measures. These enhancements reflect our commitment to providing cutting-edge, intelligent solutions in the ever-evolving landscape of cyber threats.

Stay Ahead of Threats with AI-Driven Security!

Escape Team

#32 ยท Create New Applications in DAST Automatically via API! ๐Ÿ”ฅ

Exciting news from Escape Tech! You can now create new Applications in our Dynamic Application Security Testing (DAST) service directly through the API. This update is all about enhancing your workflow efficiency and simplifying your security testing process. ๐Ÿ› ๏ธ

Key Features of the API Route ๐Ÿ—๏ธ

  • Flexible Application Settings: Define your application's specifics, like name, type (GraphQL or REST), and server URL.
  • Schema Customization: Provide your application's schema as a string or through a public schema URL.
  • Adaptable Scan Settings: Fine-tune your scans with settings like read/write access, customizable for safe production scans.
  • Authentication Support: Add authentication details for scanning, with options for different user names and authorization headers, or opt for no authentication.
  • Optional Repeater Use: Integrate a repeater if needed for your scanning requirements.

Advantages for You ๐ŸŒŸ

  • Streamlined Integration: Add new applications to DAST quickly and efficiently via API.
  • Diverse API Support: Compatibility with both GraphQL and REST applications.
  • Tailored Scanning Options: Customize scans for precision and safety.
  • Simplified Authentication Setup: Easy setup for various authentication scenarios.

๐Ÿ”— Check out the full API documentation here for detailed instructions and more info.

๐Ÿ” Elevating Your Security, Simplified Our commitment to enhancing your security processes continues. This new feature demonstrates our dedication to providing flexible and comprehensive security solutions.

Happy Secure Coding!

#31 ยท API Inventory under steroids ๐Ÿ’ซ

Hello, API Security Mavericks! ๐Ÿ› ๏ธ

After the successful launch of our API Inventory, we're excited to unveil its latest evolution with enhanced capabilities and integrations. Our commitment to providing comprehensive API security has led to significant additions to our Inventory feature. ๐ŸŒ

What's New? ๐Ÿ”Ž

  • Postman Integration: Seamlessly integrate with Postman to find and manage Postman Collections directly within Escape.
  • GitHub Integration: Automatically discover OpenAPI schemas in your GitHub repositories, enhancing your security oversight in code repositories.
  • Enhanced Schema Detection: Advanced automation now identifies exposed schemas on the internet, bolstering your external security posture.
  • API Framework Discovery: Identify the frameworks behind your REST and GraphQL APIs, adding another layer to your security insights.
  • Cloud Provider Identification: Determine which Cloud Provider (AWS, GCP, and more) is hosting your APIs, supporting a broad range of providers.
  • Environment Tagging: Easily distinguish between production and staging endpoints, ensuring appropriate security measures are applied.

Extended Benefits ๐ŸŒŸ

  • Comprehensive API Coverage: With these new integrations and capabilities, gain a more holistic view of your API landscape.
  • Automated Insights: Reduce manual workload with automated discovery and categorization of APIs, improving efficiency and accuracy.
  • Strategic Security Posture: Tailor your security strategy with detailed information on API frameworks, cloud providers, and environment types.

๐Ÿ“ฃ Stay Tuned for More! We're constantly enhancing our platform to ensure you stay ahead in the cybersecurity race. Keep an eye out for future updates and features!

Stay Secure and Informed! ๐Ÿ”’

#30 ยท [Enterprise] Fine-Grained Role-Based Access Control (RBAC) ๐Ÿ›ก๏ธ

We're thrilled to announce a major update that's set to enhance your experience and security management capabilities with Escape: the transition from Policy-Based Access Control (PBAC) to a more sophisticated and flexible Permission-Based Access Control (RBAC) system. ๐Ÿ”„

What's New? ๐Ÿ”

  • Fine-Grained Control: Assign specific permissions to roles and directly associate these roles with users. This granular approach ensures tighter security and tailored access rights.
  • Enhanced Feature Access: Gain more control over various Escape features, including:
    • Organization Management: Administer your organization's settings with precision. ๐Ÿ”ง
    • Inventory Oversight: Keep a meticulous track of your inventory with enhanced access control. ๐Ÿ“Š
    • Application Access: Manage access to all scanned applications with ease. ๐Ÿ“ฑ
    • Reporting Capabilities: Generate and access reports with adjustable read and write permissions. ๐Ÿ“ˆ
    • Integrations Flexibility: Seamlessly integrate and manage external tools and services. ๐Ÿ”—

Built for Enterprise: This update is especially tailored for our enterprise customers, enhancing your team's collaboration and security governance.

SSO Integration: The new RBAC system works hand-in-hand with Single Sign-On (SSO), providing a streamlined and secure user experience. ๐Ÿค

As always, we're committed to providing you with the best tools to secure your digital landscape. This update reflects our dedication to offering customizable, robust security solutions.

Stay Safe, Stay Secure! ๐Ÿ”