AppScan QA & Audit: Key Features
Home
Solutions
  - AppShield™
  - AppShield Appliance
  - AppScan™
    - Develop
    - Testing
    - Deployment
    - FAQ
    - FREE Trial
    - Detailed Information
  - AppScan™DE
  - AppAudit
  - Whitepapers
Demos
Partners
Inside Sanctum
Web Perversion
Customers
News & Events
Support & Training
Contact Us
Gov't Legislation
and Compliance
Key Features   Knowledge Center

S.A.F.E.: Speed, Accuracy, Flexibility and Efficiency

As the leading security scanning and testing tool, AppScan delivers an unparalleled combination of the benefits that matter most: speed, accuracy, flexibility and efficiency. Its features and performance make it a powerful tool in the hands of both security novices and experts.

  • Intuitive User Interface—AppScan's user interface makes it easy to setup, configure, and run tests. Likewise, analyzing results and generating reports can be done simply and quickly within AppScan's UI.
  • Contextual Help—No matter where you are in AppScan or what you are doing with it, AppScan provides context-sensitive tips, descriptions, and guides that assist you.
  • Business Process Record and Play—AppScan 3.5 enables users to target specific business processes for one-time tests or as a part of regression testing during development.
  • One-Click Update—One-Click Update automatically updates AppScan with the latest security vulnerabilities and security testing technology with one click of the mouse. Updates are available 24 hours a day, 7 days a week.
  • Scan Scheduling—Schedule one-time, regular, and concurrent tests directly from the user interface, from the command line, or from external test scripts.
  • Transient Management SystemCreating and maintaining a session is a fundamental function of any web application. Testing tools have historically had trouble managing transients like cookies and URL parameters that are used for state management and session tracking. AppScan's Transient Management System automates the transient detection, management, and modification process so that exploring and testing can occur within stateful environments.
  • Exposed Proxy—Exploring and testing of applications isn't restricted to HTML browsers. With AppScan, users can explore and test applications through AppScan using any client, not only HTML browsers.
  • Client Side Logic—Nearly every site and application use JavaScript. Traditionally, client-side logic has represented a "blind spot" for application scanners and testing tools. AppScan 3.5 now automatically explores and parses JavaScript, tests embedded links, and identifies potentially dangerous comments and uses of parameters in JavaScript.
  • Custom Error Page Recognition—Custom error pages can be a source of an enormous number of false positive results unless the scanning tool can recognize them. Unlike other testing tools that require the user to write rules to detect error pages, AppScan automatically recognizes both standard 404 and custom error pages out of the box.

Site Smart: Automated Behavioral Detection and Precision Testing

AppScan tests for Web application vulnerabilities automatically and produces minimal false positive and false negative results.

  • Patented Policy Recognition Engine—In order to deliver accurate results, AppScan first learns the business logic and structure as it explores the application. It then creates custom tests that are designed to identify security defects and vulnerabilities in the application's logic and structure.
  • SiteSmart Testing System—Once AppScan has created the custom tests, it sends these tests up to ten at a time to the application. Each response from the application is then parsed and validated automatically by AppScan to identify the responses that indicate vulnerabilities and the severity of every vulnerability detected.
  • Comprehensive Knowledge Database—AppScan's knowledge database contains the information that is combined with vulnerable test results so that an auditor, administrator, tester, or developer can quickly locate and patch or fix the defect or vulnerability. The database is updated continually.
  • Code Sanitation and Content Review—AppScan gathers and presents a comprehensive view of information about the application that affects its security but cannot be tested directly. One such example is comments in the source code left behind by developers. AppScan collects, organizes, and displays this information for users to review and incorporate into their plan for tightening the security of the application.
  • Custom Rule Definitions defined by user—While AppScan creates and customizes tests automatically, users can create their own tests using the Custom Rule Definitions. This is a useful feature for users that must define and run a very specific test against the application.
  • Supports Client-Side Certificates, SSL, and NTLM—For applications that require authentication prior to use, AppScan automatically authenticates using certificates, SSL, and NTLM. Settings and options are managed from within the AppScan UI.
  • Precision Filters enable users to avoid wasting scan time and cycles by precisely defining the scope and depth of every scan—Controlling what the AppScan automatically explores and how it tests is easy with the many filters and configuration options during setup.

Actionable Results

  • Interactive "Index Cards"—In order to understand and fix security defects and vulnerabilities, auditors, testers, and developers need a wide variety of information relating to the vulnerability, the tests run, and the recommended fix. AppScan users find all of this information and more in AppScan's Interactive Vulnerability Index Cards.
  • Traffic Logging—If an AppScan user wants to investigate further the details of a vulnerability, he/she can open and analyze a traffic log that contains every transaction detail between AppScan and the application
  • Custom Reports—Getting the right results in the right format to the right person or people is why AppScan is a valuable tool at the end of the day. Once testing is complete, AppScan users can build and customize (add logos, edit results, insert comments etc.) executive summary and detailed reports quickly and easily. Furthermore, results can be exported in standard formats like CSV and Crystal Reports for further analysis, reporting, and tracking.
  • Online/Offline Results Analysis and Reporting—AppScan users don't have to be online in order to review results or generate reports.

 
 Datasheet
 Product White Paper
 AppScan Features
 - What's New
 FAQ's
 Case Studies
 OWASP Compliance
 Press Releases
 AppScan in the News
 Support & Training
 AppScan Demo
 AppScan FREE Trial
 AppScan Extranet

Free AppScan Trial

Strategic Partner Solutions
 - AppScan Express
 - PricewaterhouseCoopers
Because you need a fast, cost-effective route to web application security.
 - Partner Directory

Contact Me Now
Click here if you would like a Sanctum Sales Rep to contact you within 24 hours.

 © 2003 Sanctum, Inc.    Privacy Statement  |   Legal Disclaimer
  1. https://www.gustudentassociation.org/
  2. https://kimmerestaurant.com/
  3. https://www.nyonyafood.com/
  4. https://www.perfectotech.com/
  5. https://www.planetgapyear.com/
  6. https://whatcomvet.com/
  7. https://theclassicyachtexperience.com/
  8. https://www.batonrougerosesociety.org/
  9. https://www.finburysullivan.com/
  10. https://mikrofinanzinstitut.com/
  11. https://oakgroveplantationsc.com/
  12. https://www.the-vision-of-harmony.org/
  13. https://www.pantheonpress.com/
  14. https://thefinancialgraduate.com/
  15. https://www.thenutkitchen.com/
  16. https://altiboutique.com/
  17. https://ambushsweden.com/
  18. https://goingonforgod.com/
  19. https://lasdopestattorney.com/
  20. https://www.sewardne.com/
  21. https://www.tehranfestival.com/
  22. https://www.bistrotmarin.com/
  23. https://brysonchristianmontessorischool.com/
  24. https://www.excalibureurope.com/
  25. https://www.tropicaltopless.com/
  26. https://www.originallotsoflox.com/
  27. https://www.wavespace-berlin.com/
  28. https://www.nicolasboutruche.com/
  29. https://www.michiganmediates.org/
  30. https://www.victoria-abbott.com/
  31. https://www.yourmyrtlebeachproperty.com/
  32. https://metrcconference.com/
  33. https://biotechscope.com/
  34. https://jzbrasil.com/
  35. https://kingswoodacquisition.com/
  36. https://www.mobilegourmetkitchen.com/
  37. https://saafootball.org/
  38. https://griefergames.info/
  39. https://ampalauragarcianoblejas.com/
  40. sbobet
  41. judi parlay
  42. togel kamboja
  43. Pengeluaran Cambodia
  44. judi bola
  45. demo slot
  46. Togel Kamboja
  47. keluaran Kamboja
  48. slot thailand
  49. togel kamboja
  50. keluaran kamboja
  51. togel Kamboja
  52. slot demo
  53. keluaran cambodia
  54. togel cambodia
  55. demo mahjong
  56. live draw macau
  57. slot thailand
  58. pengeluaran kamboja
  59. judi bola
  60. sbobet
  61. slot demo
  62. togel sdy