Skip to main content

Send discovered applications to DAST

Use the integration between External Attack Surface Management (EASM) and DAST to export web applications discovered in your external attack surface directly into DAST.

Discover external attack surface with EASM

Before scanning web applications or APIs with DAST, run an EASM scan to identify vulnerable assets in your external attack surface. To scan your attack surface, follow the steps in Discover external assets.

Triage discovered assets for DAST scans

After completing a discovery scan, identify web applications that are appropriate for a DAST scan.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. Select the Navigate to a project.
  4. Select the required project.
  5. Select the project dashboard icon dashboard_easm.png.
  6. At the top of the page, use the dropdown and select Things.
  7. To refine the results, at the top-right corner of the page, use the dropdown and select applications.
  8. Review the discovered applications. Pay attention to attributes such as:
    • Whether the application is publicly accessible
    • The detected technology stack
    • Any existing security indicators
    • Business criticality based on the domain or functionality

Enroll applications in the DAST Candidates security program

Once you've identified suitable applications for DAST scanning, enroll them in the DAST Candidates security program.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. Select the Navigate to a project.
  4. Select the required project.
  5. Select the project dashboard icon dashboard_easm.png.
  6. At the top of the page, use the dropdown and select Things.
  7. To refine the results, at the top-right corner of the page, use the dropdown and select applications.
  8. To select the web applications that you want to scan with DAST, select the checkboxes in the corresponding rows.
  9. At the top-right corner of the page, select EDIT SELECTED.
  10. In the Bulk edit panel that appears, select Security program Onboarding > ONBOARD ITEM.
  11. From the Select security program dropdown, select DAST Candidates. If necessary, update the date range.
  12. Select ONBOARD ITEM.

Update the current test to send data to DAST

After enrolling the applications, update the current test to send data to DAST.

To complete this task:

  1. Remain in the EASM interface after enrolling applications.
  2. Select the scan icon start_scan_easm.png or the check icon check_icon_easm.png.
  3. Select Manual scans.
  4. In the Update scan section, select Deep discovery to scan all assets related to your organization. To scan only a specific item within the same domain, skip this option.
  5. Select Launch scan.

Access discovered targets in DAST

After sending the applications to DAST, you can manage them as targets and include them in DAST scans.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > DAST.
  3. Select the Navigate to a project.
  4. Select the required project.
  5. On the Target list page, select Discovered Targets.