Scan Configuration
Fuzzing Hero enables customers to configure scans to their preferences.
Authentication
Review the Configure Authentication task for more information on how to configure authentication for your scans.
Scan Categories
Fuzzing Hero has high-level categories that group related scan checks together, such as Vulnerability, Logical, and Structural. We recommend you run all categories by default, however you can customize your scan categories to focus on specific areas or reduce scan time.
Vulnerability checks allow for granular decisioning over what types of vulnerabilities are scanned for. Logical and structural categories can be enabled or disabled.
Logical testing will attempt different conditions by flipping values (0 -> 1, true -> false, etc.) to identify unexpected behavior. It's a strong starting point for input validation and business logic testing.
Structural testing is focused on the structure of inputs. We will run a gauntlet of tests against structured data like JSON and XML, which is aimed at discovering parsing bugs, application-level denial of service, and malformed input issues.
Additionally, if you are using directives and validators, you will be able to opt-in to these on your scan categories.
Scan Settings
These settings allow you to tweak scan output and scan behavior.
For example, the Redact Authentication scan setting allows for request header values (like Authorization or cookies) to be redacted in scan output to ensure sample requests, responses, and HAR files don't contain credentials.
The Rate Limit scan setting can be used to adjust the speed of of the scan. The default value of 0 will automatically adjust to scan your application based on how responsive it is. Slower values like 5 and 10 may be appropriate for less-stable applications.