Introducing Dynamic API Scanning
Application environments are more complex than ever, with APIs forming the critical connective tissue. But this proliferation has created a vast, often invisible, attack surface. …
Victor Arellano
We’ve shipped a few new filters to the attack surface page to help security teams easily manage their rapidly expanding attack surface. We’ve also improved how we discover subdomains and shipped a handful of new SSL assessments.
The rapidly expanding attack surface often requires security teams to deep dive into their Internet-facing assets, such as root assets and associated subdomains. Conducting these reviews can be time-consuming for security experts, particularly if they have a large attack surface made up of hundreds – or even thousands! – of subdomains.
We’ve now made it possible for users to filter their attack surface by a root asset. This means that if a user is interested in knowing all associated subdomains to example.com, they can now simply filter their attack surface to get this information (including all of the enrichment data, such as ports, IPs, and surface state).
Maintaining a record of all DNS record types associated with a specific subdomain can be tricky, especially when security teams have a diverse attack surface made up of a variety of Internet-facing assets. This made it cumbersome for users to get a view of their attack surface for specific DNS record types, such as CNAME records.
Users can now view their attack surface by DNS record type. This also means users can now easily access the DNS record page for each asset to get information like historical DNS data.
Log in to get an overview of what is exposed on your attack surface.
We’re hiring engineers, product managers, sales, & more! Learn more.
Application environments are more complex than ever, with APIs forming the critical connective tissue. But this proliferation has created a vast, often invisible, attack surface. …
The average organization is missing testing 9 out of 10 of their complex web apps that are attacker-attractive targets. To address this, we’re launching new …