Úsalo si
Verify control of an internet-facing asset, launch a bounded application scan, follow durable progress, and interpret findings or partial-result warnings safely.
Verify control of an internet-facing asset, launch a bounded application scan, follow durable progress, and interpret findings or partial-result warnings safely. Audiencia: Application security teams, workspace admins, and service owners. Tiempo típico de configuración: 10-20 minutes.
Verify control of an internet-facing asset, launch a bounded application scan, follow durable progress, and interpret findings or partial-result warnings safely.
Paso 1
BlackShield disables active scanning until the workspace proves control of the exact DNS name or public IP.
Cómo se ve el éxito
Choose Check verification. Verification lasts 30 days and does not automatically cover subdomains.
Paso 2
Launch Deep Scan from EASM or open the DAST Scanner and select one or more verified assets.
Cómo se ve el éxito
Each target has a 12-minute execution budget and a maximum of two scans may be active per workspace.
Paso 3
Scan History reports queued, crawling, testing, finalizing, completed, warning, failed, and cancelled states.
Cómo se ve el éxito
Cancel active jobs from Scan History. Late worker results are ignored after cancellation.
Solo demostración
Esta configuración está diseñada para facilitar el uso. Para desplegar clientes de escaneo a escala, planifique su arquitectura de despliegue en consecuencia o contáctenos para obtener las mejores prácticas empresariales.
curl -X POST "$BLACKSHIELD_URL/api/v1/dast/scans" \
-H "Authorization: Bearer $BLACKSHIELD_TOKEN" \
-H "Content-Type: application/json" \
-d '{"config":{"targets":[{"asset_id":"<asset-id>","scheme":"https","base_path":"/"}],"profile":"standard"}}'