StackHawk
Hamburger Icon

December Product Update 🎄🎁

brian erickson

Brian Erickson|December 11, 2024

Wrap up the year with powerful new features from StackHawk! This December update includes Oversight for better app management, smarter API Discovery, and the latest HawkScan enhancements to simplify your security testing.

As the holidays approach, we’re wrapping up the year with some exciting updates to make your security testing with StackHawk smoother, smarter, and faster. From Oversight for better application management to new API capabilities and the latest HawkScan improvements, this release is packed with gifts for your team.

Let’s dive into what’s new! 🎅✨

Oversight: Simplified Security Management

As the number of applications under test grows, keeping track of security testing can become overwhelming. That’s where Oversight comes in. With a streamlined view of your applications and their security status across environments, you can easily manage testing efforts at scale. Use the new app list with filters to quickly find what you need, and explore detailed app insights to maintain a strong security posture.

Oversight December Product Update Image 1 image

API Discovery: See Your Attack Surface Like Never Before

Understanding your APIs just got easier. The new Attack Surface Report gives you a high-level summary of your API exposure, while detailed repo views include AI-powered insights, topics, and languages to help prioritize testing. Plus, the new “Repos Added” card keeps you up to date on newly discovered repositories in your attack surface.

API Discovery Repo Details December Product Update Image 2 image

Platform Updates: Better Collaboration and Reporting 

Make sharing and collaboration easier than ever with these updates:

  • PDF Scan Reports: Create polished, shareable reports that are perfect for keeping stakeholders informed.

  • Comment on Findings: Your team can now leave comments directly on findings without changing their triage status, streamlining communication between developers and security teams to resolve issues faster.

Comment Feature December Product Update Image 3 image

Scan Performance: Unlock Faster, More Accurate Scans

The key to effective security testing in CI/CD is fast, efficient scans. After working with many customers to tune their scans, we’ve seen how diagnosing application and network performance can dramatically improve scan speeds and reduce false positives.

With the new Scan Performance feature, you can now view detailed application performance metrics directly in the Scan Details screen. This includes:

  • Response Duration: See how quickly your application responds to requests.

  • Status Codes: Understand the HTTP status codes returned by your application.

Scan Performance Featyre December Product Update Image 4 image

New API Capabilities: Greater Flexibility and Control

Our latest API updates give you more power to automate and scale your application security program:

  • Application and Environment v2: Robust filtering and additional context make it easier to manage your apps and environments.

  • Scan Alert Details: Access detailed insights into scan findings to help your team prioritize and resolve issues faster.

  • Scan Deletion: Programmatically clean up your scan history for better organization and efficiency.

HawkScan 4.2 + 4.3: Smarter, Faster Scans

With the latest HawkScan updates, you’ll see improvements across the board:

  • Log Cleanup and Error Handling: Cleaner logs and smarter error messaging to reduce friction.

  • Performance Boosts and Bug Fixes: Faster scans and fixes for proxy configuration and plugin commands.

  • Smarter gRPC and OpenAPI Scanning: Improved support for gRPC input vectors and single-path OpenAPI specs.

  • SOAP WSDL Improvements: Better handling of linked files for seamless SOAP testing.

Check out the change log and upgrade to the latest version from our downloads page and enjoy a faster, more reliable scanning experience.

Read more (link out to call to actions or additional resources (docs, website, etc):


Brian Erickson  |  December 11, 2024

Read More

Introducing Oversight Providing a Birds-Eye View of API Security- Thumbnail

Introducing Oversight: Providing a Birds-Eye View of API Security

Announcing API Discovery-352-126

Announcing API Discovery Powered by HawkAI

API Discovery vs. API Monitoring Why Proactive API Security is the Future- Thumbnail

API Discovery vs. API Monitoring: Why Proactive API Security is the Future