Send discovered applications to DAST
Use the integration between External Attack Surface Management (EASM) and DAST to export web applications discovered in your external attack surface directly into DAST.
Discover external attack surface with EASM
Before scanning web applications or APIs with DAST, run an EASM scan to identify vulnerable assets in your external attack surface. To scan your attack surface, follow the steps in Discover external assets.
Triage discovered assets for DAST scans
After completing a discovery scan, identify web applications that are appropriate for a DAST scan.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- Select the Navigate to a project.
- Select the required project.
- Select the project dashboard icon
.
- At the top of the page, use the dropdown and select Things.
- To refine the results, at the top-right corner of the page, use the dropdown and select applications.
- Review the discovered applications. Pay attention to attributes such as:
- Whether the application is publicly accessible
- The detected technology stack
- Any existing security indicators
- Business criticality based on the domain or functionality
Enroll applications in the DAST Candidates security program
Once you've identified suitable applications for DAST scanning, enroll them in the DAST Candidates security program.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- Select the Navigate to a project.
- Select the required project.
- Select the project dashboard icon
.
- At the top of the page, use the dropdown and select Things.
- To refine the results, at the top-right corner of the page, use the dropdown and select applications.
- To select the web applications that you want to scan with DAST, select the checkboxes in the corresponding rows.
- At the top-right corner of the page, select EDIT SELECTED.
- In the Bulk edit panel that appears, select Security program Onboarding > ONBOARD ITEM.
- From the Select security program dropdown, select DAST Candidates. If necessary, update the date range.
- Select ONBOARD ITEM.
Update the current test to send data to DAST
After enrolling the applications, update the current test to send data to DAST.
To complete this task:
- Remain in the EASM interface after enrolling applications.
- Select the scan icon
or the check icon
.
- Select Manual scans.
- In the Update scan section, select Deep discovery to scan all assets related to your organization. To scan only a specific item within the same domain, skip this option.
- Select Launch scan.
Access discovered targets in DAST
After sending the applications to DAST, you can manage them as targets and include them in DAST scans.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > DAST.
- Select the Navigate to a project.
- Select the required project.
- On the Target list page, select Discovered Targets.