AppSpider web GUI fields
AppSpider web GUI fields The following sections map AppSpider Pro GUI to the corresponding
attributes in the XML config.
Main
| AppSpider web GUI fields | XML config |
|---|---|
| Scan Name |
|
| URL List |
|
| Max Links |
|
| Restrict scan to seed URLs |
|
| Browser |
|
Attack policy
| AppSpider web GUI fields | XML configs | |
|---|---|---|
| Attack Policy | Attack Policy Name |
|
| Attack Prioritization |
| |
| Attacks per input |
| |
| Attacks Collection |
| |
| Browser Encoding |
| |
| False Positive Regex |
| |
| Module Policy | Enabled |
|
| Name |
| |
| Severity |
| |
| Max Findings |
| |
| Attack Locations | Attack |
|
| Type | N/A | |
| Description | N/A | |
Proxy
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Proxy settings |
| |
| Proxy requires authentication | User Name |
|
| Password |
| |
Authentication
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Automated Login |
| |
| User Name |
| |
| Password |
| |
| SSO |
| |
| Macro Authentication |
| |
| MacroRecordsFile |
| |
| Display Macro Replay |
| |
| Browser |
| |
| HTTP Authentication |
| |
| Use Form credentials |
| |
| User Name |
| |
| Password |
| |
| Scan Bootstrap |
| |
| Selenium Script Authentication |
| |
| Web Driver |
| |
| Selenium Script File |
| |
| Proxy Log Authentication |
| |
| Proxy Log File |
| |
| Session Hijacking |
| |
| Session Cookie |
| |
| Lock cookie values for duration of scan |
| |
| New cookie list |
| |
| HMAC |
| |
| Username |
| |
| Secret Key |
| |
| Hash Algorithm |
| |
| HMAC Generator DLL |
| |
| OAUTH |
| |
| Resource Server URL |
| |
| Authorization Server URL |
| |
| Redirect URI |
| |
| Client Scope |
| |
| Client Secret |
| |
| Client Id |
| |
| Client State |
| |
| Username |
| |
| Password |
| |
| Grant Type |
| |
| Advanced Settings |
| |
| Configure SSL Certificates | SSL Certificate |
|
| ||
| ||
| SSL Subject name |
| |
| ||
| ||
| Logged In Regex |
| |
| Assume Good Login |
| |
| Allow Initial Redirect for Non-Form Auth Single Sign-on |
| |
Crawler restrictions
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Comprehensiveness |
| |
| Default |
| |
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| Fast Scan |
| |
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| URL |
| |
| Match Type |
| |
| Action |
| |
| VERB |
| |
Attack restrictions
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Inherit crawl restrictions |
| |
| Attack restrictions | URL |
|
| Match Type |
| |
| Action |
| |
| VERB |
| |
| Regular expression for parameters by name to be excluded from being attacked |
| |
HTTPs headers
| AppSpider web GUI fields | XML config |
|---|---|
| Protocol |
|
| User-Agent |
|
| Accept Header |
|
| Accept-Charset |
|
| Accept-Language |
|
| Extra Header |
|
| Accept-Encoding |
|
| Cookie |
|
| Lock cookie values for duration of scan |
|
| Cookie to lock |
|
Performance
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Network Settings | Number of URL Retry Attempts |
|
| Min Delay Between Requests, ms |
| |
| Connection Timeout, ms |
| |
| Read Timeout, ms |
| |
| Maximum Bandwidth, KB/s |
| |
| Max Concurrent Requests (1-64) |
| |
| Server Load |
| |
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| Secure Protocols |
| |
| Sequential Scan |
| |
| Anti DoS |
| |
| Performance Settings | Max CPU Usage |
|
| Maximum memory ceiling (Mb) |
| |
| Disable system resources monitoring |
| |
| Logging Options | Operation log |
|
Reporting
| AppSpider web GUI fields | XML config | |
|---|---|---|
| XML | CrawledLinks XML |
|
| Main |
| |
| Summary |
| |
| Index | Application |
|
| Database |
| |
| Executive Summary |
| |
| Index |
| |
| Resource Details |
| |
| HTML | All-links |
|
| App Threat Modeling |
| |
| Best Practices |
| |
| By Site |
| |
| Reflection |
| |
| Remediation Summary |
| |
| Resource Summary Breakdown |
| |
| Resources |
| |
| Server |
| |
| Site Links |
| |
| StatusAndConfig |
| |
| Vulnerabilities |
| |
| Vulnerabilities By Url Standalone |
| |
| Compliance | CWESANS |
|
| DISASTIG |
| |
| FISMA |
| |
| GDPR 2016 |
| |
| GLB |
| |
| HIPAA |
| |
| OWASP 2017 |
| |
| OWASP 2021 |
| |
| PCI31 |
| |
| SOX |
| |
| Privacy | Comments |
|
| Cookies |
| |
| Privacy |
| |
| JSON | Attack Locations |
|
| Attack Modules |
| |
| Attack Vectors |
| |
| Browser Links |
| |
| Crawl Results |
| |
| Crawled Links |
| |
| Findings |
| |
| Forms |
| |
| Scan Status |
| |
| UserMessage Log Entries |
| |
| Validation |
| |
| Vulnerabilities Summary |
| |
| Web Resources |
| |
| WebAppScan Selected Children |
| |
| WebSites |
| |
| Advanced | Confidence |
|
| IncludeDbInZip |
| |
| OWASP2017 |
| |
| OWASP2010 |
| |
| OWASP2013 |
| |
| PCI |
| |
| PCI30 |
| |
| TreatNTOEFindingFlagsSameAsUI |
| |
| UseSQLite |
| |
| ValidateApplet |
| |
| Generate PDF |
| |
| Create report ZIP file |
| |
Web service
| AppSpider web GUI fields | XML config | |
|---|---|---|
| Restrict scan to Swagger imported files |
| |
| Restrict scan to Web Service |
| |
| Swagger | Provide a hostname to overwrite the hostname from the swagger file |
|
| Swagger List |
| |
| WSDL | Auto discover |
|
| Content Type |
| |
| RegEx |
| |
| Web services ehancements |
| |
| User name |
| |
| Password |
| |
| Password option |
| |
| WSDLs list |
| |
| Web service authentication | Custom web service authentication |
|
| Web service |
| |
| Authentication web method |
| |
| Extract and apply Authentication Token |
| |
| AuthToken parameter name in the Authentication method response |
| |
| AuthToken parameter name in regualt (non-auth) method request |
| |
Recorded traffic
| AppSpider Web GUI fields | XML config |
|---|---|
| Restrict scan to recorded traffic |
|
| Traffic file List |
|
| Import Cookies From Traffic |
|
Browser macro
| AppSpider Web GUI fields | XML Config |
|---|---|
| Restrict scan to MACRO |
|
| Macro record files |
|
Selenium recordings
| AppSpider web GUI fields | XML config |
|---|---|
| Restrict scan to Selenium recording |
|
| Selenium record files |
|
| Web Driver |
|
Parameters training
| AppSpider Web GUI fields | XML config | |
|---|---|---|
| Simple | Parameter |
|
| Value |
| |
| Match Criteria |
| |
| Advanced |
| |
| Pattern |
| |
| Text Match |
| |
| Value Match |
| |
| Value |
| |
| Language |
| |
| Match Type |
| |
| Control Types |
| |
Custom URLs
| AppSpider web GUI field | XML config | |
|---|---|---|
| Custom Parsers | Name |
|
| Rule Regex |
| |
| Path Regex |
| |
| Query Regex |
| |
| Path Groups |
| |
| Query Groups |
| |
Advanced options
| AppSpider web GUI fields | XML config |
|---|---|
| AnalyzerConfig |
|
| AttackerConfig |
|
| AttackPolicyConfig |
|
| AuthConfig |
|
| AutoSequenceConfig |
|
| ChromeHostConfig |
|
| CrawlConfig |
|
| CVSSConfig |
|
| HTTPHeadersConfig |
|
| MacroConfig |
|
| ManualCrawlingConfig |
|
| NetworkSettingsConfig |
|
| NexposeRESTConfig |
|
| OneTimeTokenConfig |
|
| ParameterParserConfig |
|
| ParameterTrainingConfig |
|
| ParameterValueConfig |
|
| PerformanceConfig |
|
| ProxyConfig |
|
| RemediationConfig |
|
| ReportConfig |
|
| RTCConfig |
|
| ScheduleConfig |
|
| SeleniumConfig |
|
| SiteTechnologyConfig |
|
| SSLCertConfig |
|
| SystemRecommendationsConfig |
|
| WAFConfig |
|
| WebServiceConfig |
|