Skip to content

Platform

#37 ยท Introducing Escape Rules: Custom Security Tests Made Simple ๐Ÿ›ก๏ธ

Hey Escape community! We're thrilled to announce a game-changer in API security testing - Escape Rules. Say goodbye to the days of rigid, hard-to-maintain business logic tests. Our latest innovation offers a fresh, dynamic approach to secure your APIs against the ever-evolving threat landscape.

Why Escape Rules?

  • Flexibility at its Best: Traditional tests, including Nuclei or bChecks, quickly become outdated as your APIs or databases evolve. Escape Rules are designed to adapt, ensuring your security tests remain relevant and robust.
  • Designed for All: Whether you're a security engineer or a developer, Escape Rules speaks your language. It's crafted to be intuitive, making the creation of business logic tests a breeze.
  • Universal Compatibility: By default, tests created with Escape Rules are automatically compatible with both REST and GraphQL APIs, ensuring broad coverage across your API landscape.

Dive Deeper ๐Ÿ“š

Curious about how to leverage this powerful tool? We've got you covered:

Your Turn to Escape the Ordinary ๐ŸŽ‰

With Escape Rules, your API security testing is not just about finding vulnerabilities; it's about embracing adaptability, community, and innovation. Let's redefine the boundaries of API security together. Start crafting your custom security tests today and stay one step ahead of the threats!

#35 ยท Comprehensive Compliance Posture at a Glance ๐Ÿ‘ฎ

Hey there,

We've brewed something special at Escape that's going to make your security life a whole lot easier (and a bit more fun)! Introducing the Compliance Matrix now available in the Reporting Tab.

What's Cooking?
  • All-in-One View: Get a bird's eye view of your organization's compliance posture across all applications. One matrix, complete overview!
  • Comprehensive Compliance Coverage: Supports a robust list of standards including OWASP TOP 10, PCI-DSS, GDPR, SOC 2, PSD 2, ISO 27001, NIST, NIS2 and FedRamp.
Why It's a Game-Changer for Security Pros:
  1. Holistic Compliance Overview: Quickly see where each application stands in terms of various compliance standards. This is crucial for maintaining a secure and compliant digital environment across the board. ๐Ÿ“œ
  2. Saves Time & Effort: No more jumping between reports or tools. Everything you need to know about compliance is in one place. More time for coffee! โ˜•
  3. Actionable Insights: Identify gaps in compliance across all applications at a glance. This enables faster decision-making and prioritization of security efforts. โšก
  4. Streamlines Reporting: Makes reporting to stakeholders a breeze. Presenting compliance status has never been this straightforward. ๐Ÿ“Š
  5. Future-Proofing: As your organization grows, so does the complexity of managing compliance. The Compliance Matrix scales with you, ensuring you're always on top of your security game. ๐Ÿ“ˆ

So, dive into the Reporting Tab, check out the new Compliance Matrix, and get ready to experience a smoother, more integrated approach to managing your organization's compliance. Happy securing!

Your team at Escape

#33 ยท New AI-Powered Business Logic Security Tests for Enhanced Access Control ๐Ÿง 

We're proud to introduce a suite of advanced AI-powered security tests at Escape Tech, specifically designed to fortify access control in your applications. Leveraging state-of-the-art artificial intelligence, these tests are engineered to uncover complex business logic vulnerabilities and attack chains with unprecedented precision. ๐Ÿค–

Cutting-Edge Security Checks ๐Ÿš€

  • Automated Tenant Isolation Control: When two users are configured, this test ensures strict tenant isolation, preventing unauthorized cross-tenant access.
  • Sensitive Endpoint Brute Force: Targets critical endpoints like login and reset-password, safeguarding against brute force attacks.
  • Broken Object Level Authorization (IDOR) Checks: Identifies vulnerabilities in object-level authorizations, an essential aspect of access control.
  • Enhanced Access Control Checks: Overall improvements in access control validations, providing a more robust security posture.
  • Public State Altering Operation Identification: Ensures that operations altering application data (like REST READ, UPDATE, DELETE requests, and GraphQL mutations) are adequately protected by authentication middleware.

The AI Edge ๐ŸŒ

These tests utilize advanced AI algorithms to generate complex sequences of requests, meticulously uncovering and exploiting business logic flaws and potential attack vectors. This approach allows for the detection of intricate vulnerabilities and attack chains that conventional methods might miss.

Compatibility and Documentation ๐Ÿ”—

  • REST & GraphQL Compatibility: Our security tests are compatible with both REST and GraphQL APIs, ensuring comprehensive coverage across different API architectures.
  • Detailed Documentation: Dive into our comprehensive guide to understand how these AI-powered tests can be integrated into your security strategy.

Elevating Security Intelligence ๐ŸŒŸ

By harnessing AI in security testing, we're pushing the boundaries of traditional cybersecurity measures. These enhancements reflect our commitment to providing cutting-edge, intelligent solutions in the ever-evolving landscape of cyber threats.

Stay Ahead of Threats with AI-Driven Security!

Escape Team

#31 ยท API Inventory under steroids ๐Ÿ’ซ

Hello, API Security Mavericks! ๐Ÿ› ๏ธ

After the successful launch of our API Inventory, we're excited to unveil its latest evolution with enhanced capabilities and integrations. Our commitment to providing comprehensive API security has led to significant additions to our Inventory feature. ๐ŸŒ

What's New? ๐Ÿ”Ž

  • Postman Integration: Seamlessly integrate with Postman to find and manage Postman Collections directly within Escape.
  • GitHub Integration: Automatically discover OpenAPI schemas in your GitHub repositories, enhancing your security oversight in code repositories.
  • Enhanced Schema Detection: Advanced automation now identifies exposed schemas on the internet, bolstering your external security posture.
  • API Framework Discovery: Identify the frameworks behind your REST and GraphQL APIs, adding another layer to your security insights.
  • Cloud Provider Identification: Determine which Cloud Provider (AWS, GCP, and more) is hosting your APIs, supporting a broad range of providers.
  • Environment Tagging: Easily distinguish between production and staging endpoints, ensuring appropriate security measures are applied.

Extended Benefits ๐ŸŒŸ

  • Comprehensive API Coverage: With these new integrations and capabilities, gain a more holistic view of your API landscape.
  • Automated Insights: Reduce manual workload with automated discovery and categorization of APIs, improving efficiency and accuracy.
  • Strategic Security Posture: Tailor your security strategy with detailed information on API frameworks, cloud providers, and environment types.

๐Ÿ“ฃ Stay Tuned for More! We're constantly enhancing our platform to ensure you stay ahead in the cybersecurity race. Keep an eye out for future updates and features!

Stay Secure and Informed! ๐Ÿ”’

#30 ยท [Enterprise] Fine-Grained Role-Based Access Control (RBAC) ๐Ÿ›ก๏ธ

We're thrilled to announce a major update that's set to enhance your experience and security management capabilities with Escape: the transition from Policy-Based Access Control (PBAC) to a more sophisticated and flexible Permission-Based Access Control (RBAC) system. ๐Ÿ”„

What's New? ๐Ÿ”

  • Fine-Grained Control: Assign specific permissions to roles and directly associate these roles with users. This granular approach ensures tighter security and tailored access rights.
  • Enhanced Feature Access: Gain more control over various Escape features, including:
    • Organization Management: Administer your organization's settings with precision. ๐Ÿ”ง
    • Inventory Oversight: Keep a meticulous track of your inventory with enhanced access control. ๐Ÿ“Š
    • Application Access: Manage access to all scanned applications with ease. ๐Ÿ“ฑ
    • Reporting Capabilities: Generate and access reports with adjustable read and write permissions. ๐Ÿ“ˆ
    • Integrations Flexibility: Seamlessly integrate and manage external tools and services. ๐Ÿ”—

Built for Enterprise: This update is especially tailored for our enterprise customers, enhancing your team's collaboration and security governance.

SSO Integration: The new RBAC system works hand-in-hand with Single Sign-On (SSO), providing a streamlined and secure user experience. ๐Ÿค

As always, we're committed to providing you with the best tools to secure your digital landscape. This update reflects our dedication to offering customizable, robust security solutions.

Stay Safe, Stay Secure! ๐Ÿ”

#29 ยท Enhanced Application Management with Search, Filtering, and Tagging!

As we continue to grow and serve larger organizations, we've recognized the need for more advanced application management features. With a vast number of apps, sifting through to find what you're looking for can be cumbersome. Enter our new suite of tools designed to simplify and enhance your application management experience!

๐ŸŒŸ Key Highlights:

  1. Powerful Search Capabilities: Quickly find the application you're looking for with our optimized search function. Never lose sight of any app again!

  2. Dynamic Filtering:

    • By Technology: Easily categorize and view applications based on their technology stack.
    • By Risk: Prioritize and manage apps based on their risk levels to ensure you're focusing on what matters most.
  3. Custom Tagging: Beyond the default filters, tag your applications with custom labels that matter to your organization. It provides advanced filtering options tailored just for you!

๐Ÿš€ Why It Matters:

With an increasing number of applications, ensuring that you can easily access, manage, and categorize them is essential. These new features not only help declutter and organize your apps but also streamline workflows and improve overall productivity.

๐Ÿ“š Dive Deeper:

Dive into the specifics of these new features and learn how to leverage them to their full potential by checking out our comprehensive guide (link to be added).

๐Ÿ“ข We're Listening:

Your input is invaluable. Let us know how these new application management tools are enhancing your experience, and share any additional features or tweaks you'd like to see in future updates!

#28 ยท ๐Ÿ“„ Export Compliance Reports as PDF

Taking another leap forward, we're thrilled to present the PDF Compliance Report feature in Escape. The capability to seamlessly export and manage compliance reports is an essential tool for organizations, and we've made it even more streamlined and efficient!

๐ŸŒŸ Key Highlights:

  1. Individual Export: Navigate to the Compliance Tab and instantly export individual compliance reports as PDFs. Quick, efficient, and hassle-free!
  2. Bulk Download: Time is valuable! Directly download all the reports in one go under the Pentesting Report. No more waiting or multiple clicks!
  3. Compliance Coverage: We're rolling out with support for prominent compliances including OWASP TOP 10, CWE, PCI-DSS, and WASC. This ensures you're aligned with industry benchmarks and best practices.
  4. Stay Tuned: Our commitment to enhancing the user experience is unwavering. Expect more compliance reports to be added in the near future!

๐Ÿš€ Why It Matters:

Compliance isn't just about checking boxes; it's about ensuring the security and trustworthiness of your systems. With the PDF Compliance Report feature, not only can you efficiently track and manage your compliance status, but also easily share and communicate these reports within your organization or with external stakeholders such as auditors or customers.

๐Ÿ“š Dive Deeper:

To explore further and understand the intricacies and benefits of the PDF Compliance Report feature, head to our detailed documentation (link to be added).

๐Ÿ“ข We're Listening:

Your insights and feedback have always been the cornerstone of our continuous evolution. Share your thoughts on the PDF Compliance Report feature, and together, let's make the digital landscape more secure and compliant!

#27 ยท [Enterprise] Scan Internal APIs with Elevated Ease Using Escape's Repeater Agent

Dive into an advanced layer of internal API scanning with the introduction of Escapeโ€™s Repeater Agent. While the proxy method for scanning internal APIs has been steadfast, our advancement to enhance your experience, especially for our Enterprise customers, has brought forth the Agent.

๐Ÿน Repeater Agent: Your Gateway to Robust Internal API Scanning

The Repeater Agent serves as a powerful facilitator to scan Internal Apps, securely situated behind your organizationโ€™s firewall or VPN, by forming a private tunnel between Escape and one of your servers. This means all the requests from Escape are strategically channelled through your server, offering you a seamless, secure, and highly efficient internal API scanning mechanism.

๐ŸŒ Workflow Insight:

  1. Repeater Client Connection: Your locally deployed repeater client connects to the repeater manager.
  2. Scan Initiation: When a scan kicks off on Escape, requests are sent to the repeater manager, instead of directly to your server.
  3. Request Transfer: Your client receives and forwards them to your server.
  4. Result Transmission: Scan results are transmitted back to Escape, ensuring you have a clear view and control of your scansโ€™ outcomes.

๐Ÿ› ๏ธ Setup and Utilization:

  • Efficient Setup: Craft a new repeater through the Escape interface and retrieve its repeater ID for setup.
  • Repeater Client Configuration: Employ the repeater client on your server, following the guidelines provided in the readme of the repeater client.
  • Application Configuration: Adapt your applications with a simple configuration snippet, utilizing the repeater ID.

๐Ÿ“˜ Dive into the Documentation:

Navigate through a detailed guide on leveraging the Escape Repeater Agent for meticulous internal API scanning by visiting our documentation. Your path to understanding and implementing this feature adeptly begins here!

๐Ÿš€ Propel Forward:

With the Repeater Agent, drive your security scanning into a domain of enhanced control, efficiency, and security. Your journey towards fortified application security is robustly supported with features that prioritize your organizational needs and challenges.

Your feedback fuels our innovations. Share your experiences and journey with the Repeater Agent, and letโ€™s continue advancing towards a secure digital horizon together!

#24 ยท Custom Security Tests

๐Ÿ› ๏ธ Advance Usage: Custom Security Tests (Beta)

Empower your security testing with our latest featureโ€”custom security tests! This advanced utility enables you to create and send tailor-made requests to any URL within your organization, catering to your unique security concerns and needs.

โš™๏ธ What's New:

  • 1. Tailored Security Assessments: Launch specialized dynamic security assessments on your web applications. This is invaluable for identifying regression bugs, conducting in-depth security checks, or probing in-house security concerns.
  • 2. Expert Tab Configuration: Set up your custom security assessments with ease via the Expert tab in your application settings.
  • 3. Dynamic Response Validation: Assess and verify server responses based on custom conditions, like a specific status code.
  • 4. Special Commands: Further customize your raw request with special commands to adjust the host, modify timeout durations, and more.
  • 5. API Configuration: Inspired by the Nuclei template engine, our API lets you seamlessly configure and manage your custom security checks.

For a more in-depth guide on how to use this feature and optimize your security testing, visit our technical documentation.

In Conclusion:

We're continuously striving to enhance the flexibility and depth of our platform. The introduction of custom security tests underpins our commitment to catering to your individual security needs. Your feedback fuels our improvements, and we're keen to hear your thoughts on this latest addition.

#23 ยท Advanced Authentication with Webdriver

๐Ÿ” Custom Authentication using Webdriver

We are excited to introduce our brand new featureโ€”Custom Authentication using Webdriver. This advanced capability allows for even more tailored and secure authentication workflows, offering users the flexibility to authenticate in ways that best suit their individual or organizational needs.

โš™๏ธ Parameters:

  • 1. Tech Parameter: Choose your preferred auth method using the tech parameter.
  • 2. Extract Location: Specify the location of the token to be extracted. Options include RequestURL, RequestHeader, RequestBody, ResponseHeader, and ResponseBody.
  • 3. Extract Regex: Utilize regular expressions to match your token, making it easier than ever to customize your authentication flow.
  • 4. Project Parameter: Assign the authentication workflow to a specific project using the project parameter.
๐Ÿ“Œ Optional Parameters:
  • Output Format: Configure the output format using a placeholder @token@.
  • Token Lifetime: Set the duration of the token's validity in seconds with the token_lifetime parameter.

For a more detailed guide on how to utilize this new feature, you can check our technical documentation.

In Conclusion:

This new feature aims to provide a flexible and secure way to authenticate within Escape. We believe these custom authentication capabilities will significantly enhance your user experience. As always, we welcome your feedback to improve further.