Recorded explore
The Recorded explore feature lets you crawl specific parts of your application, to "guide" AppScan 360° to those areas, ensuring that they are tested in the DAST scan, and that AppScan 360° has the information needed to browse links in a specific order.
Use Recorded explore when specific user input is required, or when a site responds only to a different type of tool or device.
- Using the AppScan Activity Recorder (an extension for your Chrome or Edge web browser)
- Using the HCL AppScan Traffic Recorder (may be most suitable in the case of web APIs)
DAST.CONFIG
file.Alternatively, you can also upload a traffic file recorded using AppScan Standard or
AppScan Dynamic Analysis Client (ADAC) that is saved as a .EXD
file.
When you upload a file with multiple domains, the domains are added to the "domains to test" list. Only the allowed or verified domains will be tested. AppScan 360° can only scan up to 5 domains in each scan.
- Using the file options in Recorded explore:
- Use both recorded and automatic explore stages for comprehensive testing: In addition to an automatic Explore stage, AppScan 360° explores the application automatically and tests both your recording and its own explore data.
- Analyze and test only the recorded explored data: During the Explore stage of the scan, test only the parts of the application included in your recording.
- Use Manual Explore in AppScan Standard, save
it as a
SCANfile, and upload the file to AppScan 360° to create a scan. Manual Explore in AppScan Standard is similar to Recorded explore in AppScan 360°.
Recorded explore applies to DAST scans only. Your DAST.CONFIG
or .EXD file is uploaded and guidance is configured in the
Explore stage of the scan wizard. See DAST scan configuration > Explore
step.
For details of how to record the traffic, see Recording traffic.
Multistep explore
Multistep explore is a specific type of recorded explore, where you not only show AppScan 360° which links to crawl, but the specific order in which to crawl. Use multistep for testing parts of the site that can be reached only by sending requests in a specific order, such as an online shop where the user adds items to a cart before paying for them.
- User adds one or more items to a shopping cart.
- User fills in payment and shipping details.
- User receives confirmation that the order is complete.
DAST.CONFIG) where you browse. AppScan 360° would extract the necessary
sub-sequences from this sequence, as required: when testing page two it would send a
page one request first; when testing page three, it would send page one followed by
page two.Multiple DAST.CONFIG files
You can upload more than one file for a single scan. If activated, the Multistep setting is applied to all the files, see DAST scan configuration > Explore step.