How to create an API scan using ADAC
You can scan a web API using ADAC from AppScan Enterprise where you can create and run a DAST scan. Scanning web API requires some manual input by the user, to show AppScan Enterprise how to use the API. This can be done by using the Manual Explore section, where you can record traffic using an external client like Postman, SOAP UI or any other external client, or, import a previously recorded traffic file.
About this task
The basic steps to create an API scan using ADAC is discussed.
Procedure
What to do next
When scan results are ready, you can view the reports on the Results tab. Reports
display information about your web API and provide the functionality to navigate to
more details. You can review the results to evaluate the security status of your web
API. You may also want to:
- Explore additional links
- Review Remediation Tasks
- Print Reports
- Review the scan results, modify the scan configuration, and scan again