Send discovered applications to DAST
Use the integration between External Attack Surface Management (EASM) and DAST to export web applications discovered in your external attack surface directly into DAST.
Discover external attack surface with EASM
Before scanning web applications or APIs with DAST, run an EASM scan to identify vulnerable assets in your external attack surface. To scan your attack surface, follow the steps in Discover external assets.
Enroll applications in the DAST Candidates security program
After you identify suitable applications for DAST scanning, enroll them in the DAST Candidates security program.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- From the top-left corner of the screen, use the dropdown to select the required project.
- Select Inventory or the inventory icon
.
- At the top of the page, use the filters to select Web Apps. The filtered results appear in the table.
- In the rows for the web applications you want to scan with DAST, select the checkboxes.
- Select Onboard to program.
- For Security program, select DAST Candidates.
- Select the date range.
- Select Onboard item.
Access discovered targets in DAST
After sending the applications to DAST, you can manage them as targets and include them in DAST scans.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > DAST.
- Select Navigate to a project.
- Select the required project.
- On the Target list page, select Discovered Targets.