Home / Companies / StackHawk / Blog / Post Details
Content Deep Dive

Making StackHawk the Best API Security Testing Tool

Blog post from StackHawk

Post Details
Company
Date Published
Author
Rebecca Warren
Word Count
435
Language
English
Hacker News Points
-
Summary

StackHawk has introduced new API scanning capabilities designed to enhance the security testing of APIs, particularly emphasizing GraphQL and OpenAPI specifications. These updates include features like the autoPolicy flag, which applies a default security policy based on the API technology, and autoInputType, which correctly identifies the request type for various API technologies, ensuring compatibility with REST, GraphQL, and SOAP APIs. The scanner now intelligently recognizes data-driven content, preventing unnecessary rescanning of similar pages, thereby improving the accuracy and efficiency of security tests. By distinguishing between different API technologies and adapting its testing approach accordingly, StackHawk's scanner provides faster and more precise results, minimizing false positives and user frustration. Users are encouraged to explore these new features by signing up for a free StackHawk account and utilizing available resources such as a vulnerable Node Express app or webinars for further guidance.