Skip to main content

Create a Validator

Validators are your way to report custom issues based on patterns identified during scanning.

Setting Up A New Validator​

  1. Navigate to the Validators tab on the left side-bar.
  2. Click on the New Validator button.
  3. Give the validator a name and description.
  4. Select the visibility setting depending on the type of collection you wish to use the validator with. A validator can only be shared with one organization at a time.
  5. Enforce any match conditions. At least 1 condition is required. You can match by response status code, body, and if the response was a result of a directive.
  6. Next select if this validator should report a Vulnerability or an Observation.
  • If it is a Vulnerability, fill out the title, severity, and description.
  • If it is an Observation, fill out the title, summary, and suggested investigation.
  1. Click on the Create Validator button to save it.

Using a Validator​

  1. Go to the Collections tab on the left side-bar.
  2. Click on the collection you want to use the validator with.
  3. Click on the Scan Categories tab.
  4. Look for the Directives & Validators section. If it doesn't appear, then check that your validator has the same privacy setting as the collection you are editing.
  5. Check All Applicable Validators or select the individual validator you wish to add.
  6. Click the Save Changes button.
  7. Kick off a scan by clicking the Start Scan button in the top-right corner. Your validators will be used in the scan if the filtered conditions apply.

Match Conditions​

Match Status Code​

  • Exact: Match on a single HTTP status code from 100 through 699 (e.g., 200)
  • Range: Match on an inclusive lower-to-upper range (e.g., 100 through 300)
  • List: Match on a list of HTTP status codes (e.g., 200, 201, 204, 401, 403, 404, 500)

Match Body​

  • Contains
  • Regex

Optionally, you can select to exclude a match if the string or expression was present in the baseline response.

Match Directive​

This option can be used to match responses that were generated by a directive. It works best when used in combination with other filters.