Product Update: AppCheck Adds Enhanced API Scanning Capabilities

With complex authentication flows, parameter mining, request signing, and much more, AppCheck’s new dedicated API scanning tool ensures you are getting complete coverage.

We are pleased to announce today that we have added a new product to the AppCheck line up: Dedicated API Scanning.

AppCheck has supported scanning API end points since around 2016. However, the way APIs are deployed and developed has changed and with APIs now making up roughly 61% of internet traffic companies cannot afford to overlook robust security testing in this area. We have seen shortcomings in the approach to testing these services, with many methods resulting in rubbish in, rubbish out and an overall lack of visibility.

With AppCheck’s new dedicated API scanning tools, you can ensure you are getting complete coverage through complex authentication flows, client certificates, ToTP AWS request signing and automatic authentication support for larger security teams.

 

Automated Authentication example within the API Explorer Wizard on AppCheck’s scanner.

 

And that’s not all. With many modern APIs – if you fail to get a good request to start with – you can send as many payloads as you like to an application and likely get nowhere. With AppCheck, as well as fixture data mining for a good request, our platform supports parameter mining to match up real application data from your APIs into the correct parameter in the request to ensure it is fully tested; offering complete coverage.

 

Parameter mining example 1 within the API Explorer Wizard on AppCheck’s scanner.
Parameter mining example 2 within the API Explorer Wizard on AppCheck’s scanner.

 

Discover how AppCheck’s dedicated API scanning can ensure complete coverage for your APIs. Visit our API Security Scanning page to learn more and request a free trial: appcheck-ng.com/api-security-scanning/.

 


 

Security Updates

To keep up to date with future high-profile advisories for critical ongoing exploitations that may threaten your technical estate, tune in next Friday for next week’s KEV roundup.

We now offer additional coverage of critical security updates from several key vendors too, including:

  • Our End-of-Month Roundups of critical patch updates for all CISCO Products – next due on 29th November 2024
  • Our Quarterly Roundups of Security Updates from IVANTI – next due on 2nd December 2024
  • Our monthly coverage of the ‘Patch Tuesday’ updates from MICROSOFT and several other major vendors – next due on 10th December 2024
  • Our Monthly Security Advisory Roundups for PALO ALTO NETWORKS – next due on 12th December 2024
  • Our quarterly coverage of the ‘Critical Patch Updates’ from ORACLE – next due on 21st January 2025

 

 

About AppCheck

AppCheck is a software security vendor based in the UK, offering a leading security scanning platform that automates the discovery of security flaws within organisations websites, applications, network, and cloud infrastructure. AppCheck are authorized by the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA).

Get started with Appcheck

No software to download or install.

Contact us or call us 0113 887 8380

About Appcheck

AppCheck is a software security vendor based in the UK, offering a leading security scanning platform that automates the discovery of security flaws within organisations websites, applications, network and cloud infrastructure. AppCheck are authorized by te Common Vulnerabilities and Exposures (CVE) Program aas a CVE Numbering Authority (CNA)

No software to download or install.
Contact us or call us 0113 887 8380

Start your free trial

Your details
IP Addresses
URLs

Get in touch