SolidLab
SolidPoint DAST

SolidPoint DAST

A modern solution for dynamically analyzing web applications and APIs for information security vulnerabilities, using intelligent algorithms to increase the likelihood of detecting hidden flaws and reduce the number of false positives.

Use cases

  • Security assessment of browser-based web apps, including static-dynamic JavaScript analysis;
  • Security assessment of mobile applications and web services;
  • Testing application delivery infrastructure for vulnerabilities;
  • Checking vulnerabilities related to authentication and authorization;
  • Inventory of web app component composition and API change management;
  • Validating production app analysis rules and aligning with SDLC;
  • Detecting IT infrastructure vulnerabilities within vulnerability management and patch management processes;
  • Available as a cloud service or an on-premise solution.

SolidPoint DAST benefits

  • Works with modern web applications, including single-page apps (SPA);
  • Efficient component analysis and input point discovery;
  • Detects complex vulnerability classes (e.g., DOM-based XSS / Prototype Pollution);
  • Scalable configurations and flexible load control;
  • Management via Web UI, CLI, and API; CI/CD integration;
  • Integration with SolidWall WAF and other tools.

Key functional features

⌘

Application delivery infrastructure analysis

Scanning delivery infrastructure for known vulnerabilities and misconfigurations, and discovering web applications available for analysis.

◎

Application endpoint discovery

Supports a wide range of endpoint discovery technologies: static and dynamic crawling, directory and file brute-forcing with wordlists, import and discovery of OpenAPI, SOAP, GraphQL and HAR specifications, integration with SolidWall WAF to import endpoints from traffic, and static-dynamic analysis of client-side JavaScript code.

!

Detection of multiple vulnerability classes

Scanning modules detect injections (including XSS, SQLi, SSTI), serialization and format parsing issues, authorization and authentication problems, and more.

⇄

Integration into automation and CI/CD processes

Supports integration via REST API or CLI, with synchronous or asynchronous scan execution, and export of JSON reports to external vulnerability management systems.

➜]

Authentication support in target applications

Basic methods
  • Cookie
  • Headers
  • HTTP Basic Auth
  • Local storage
  • Client TLS certificate
Advanced methods
  • Authentication verification algorithm
  • Authentication refresh via HTTP request
  • Updating authentication using a browser script
  • Authentication in web forms

Professional services and support

  • Scan target configuration, including authentication parameters
  • Analysis of scan results
  • Running scans with configuration and validation of target parameters
  • Integration with third-party solutions