Table of Contents

SwyftComply for API Scan

Rama Sadhu Updated by Rama Sadhu

Introduction

The objective of enabling SwyftComply for API scanning is to generate a clean report within 72 hours. This report helps in patching critical, high & medium vulnerabilities, ensuring efficient response to security issues.

How SwyftComply works for API Scan 

Steps to Initiate API Scan 
  • Select application and click Start API Scan
  • A confirmation pop-up opens. Click Confirm to initiate the scan. 
For APIs configuration or to upload a postman file, go to Settings > Select Application > WAF > API Endpoint definition.
Select the API Application and Select a Scan  
  • Go to Detect > select API Site
  • Before using SwyftComply, ensure that at least one API scan is completed.  
  • Choose the specific scan log to initiate the report generation in SwyftComply or complete the API scan (If not started).
Download Scan Report 

Once the scan is completed, click Scan Report Download

A sample scan report can be accessed here.

View Scan Summary for Vulnerabilities 

Scroll to Scan summary section and find the vulnerabilities identified. 

The vulnerabilities identified: for customers an option is provided to filter the identified vulnerability data by their category and severity level.

Initiate SwyftComply 
  1. Select the scan log, and from the SwyftComply Report section, click Initiate SwyftComply.
  2. Read the information and conditions given on the pop-up carefully. 
  3. Click Start SwyftComply.
  4. Once the SwyftComply is started successfully, all the vulnerabilities identified in the selected scan will be protected within 72 hours. 
Protected Vulnerabilities Summary after SwyftComply 

Scroll to Scan Summary section and find the vulnerabilities protected. 

The protected vulnerabilities: Customers can filter the protected vulnerabilities data by: 

  •  Vulnerability Category 
  • Protection Status (All, Protected, Unprotected, Fix in Code) 

Protection Type (All, API rules, custom rules, positive security rules)

Download SwyftComply Report 

Once the SwyftComply request is completed, a report will be generated. 

Click View SwyftComply Report.

The report offers detailed insights into each vulnerability addressed during the SwyftComply process, ensuring complete coverage of your application's security status.

The report shows details of patched, and fix required in code vulnerabilities, such as category, HTTP method, OWASP category, patch status, and so on. 

A sample SwyftComply report is accessed here

How did we do?

Enhance Your API Security with API Classification

Custom Bot Configuration

Contact

This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.