Customized and Configurable Scan Discovery
Blog post from StackHawk
HawkScan is a versatile tool designed to identify vulnerabilities in web applications by employing multiple discovery mechanisms such as Spidering, HAR files, Seed Path, and Custom Scan Discovery. During the Scan Discovery phase, it utilizes spidering to map web application paths and performs Passive Scans for known vulnerabilities. HAR files provide an alternative method for precise path mapping, particularly useful for single-page apps and password-protected routes. Custom Scan Discovery in HawkScan 2.8.0 allows integration with developer tools like Postman and Cypress to intercept web traffic, enhancing flexibility and control over the scanning process. The tool supports various API protocols, including OpenAPI, GraphQL, and Soap, to adapt to different software environments, ultimately aiding security and software development teams in maintaining robust application security.