Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

Data Sheet

Secuirty

WebInspect: Automated Dynamic


Application Security Testing
Micro Focus® Fortify WebInspect is a dynamic application security testing tool that identifies ap-
plication vulnerabilities in deployed web applications and services.

WebInspect scans modern frameworks and Product Highlights Key Features


web technology with the most comprehensive
Find More Vulnerabilities Manage Enterprise Application Security Risk
and accurate dynamic scanner. The product is • Monitor trends and take action on vulnerabilities
WebInspect is a comprehensive dynamic ap-
easily deployable in enterprise environments, within an application.
plication scanner that has the ability to crawl
has exhaustive REST APIs to benefit integration
modern frameworks and web technology with a Save Time with Automation and Integrations
and has the flexibility to manage security risks • Fully-automated solution that helps meet
comprehensive audit of all vulnerability classes.
either through intuitive UI or run completely DevOps and scalability needs. Integrates with the
via automation. WebInspect provides the ■■ Support for the latest web SDLC without additional overhead to minimize
broadest dynamic application security test- technologies including HTML5, friction in your software development process.
ing (DAST) coverage and detects new types JSON, AJAX, JavaScript, and more. Compliance Management
of vulnerabilities that often go undetected by ■■ Ability to scan Single Page • Pre-configured policies and reports for all
black-box security testing technologies. Applications (SPA) major compliance regulations related to web
application security, including PCI DSS, DISA
STIG, NIST 800-53, ISO 27K, OWASP,
and HIPPAA.
Optimize Scan Results with Agent Technology
• Get additional visibility and stack trace insight
from scanned web applications. Optimize
the scanning process based for both speed
and accuracy using this technology.
Available On-Premise or as a Service
• Start quickly and scale as needed on premise or
as a service, or as a hybrid.

Figure 1. Live dynamic scan visualization


Data Sheet
Repeat of Main Title from Front Cover Goes Here

■■ Deduplication: Reduce # of attacks sent,


by avoiding scanning the same class/
function in a different part of the app.
■■ Check Avoidance: Reduce # of
attacks sent by avoiding sending
multiple attacks to a specific check
type if the agent determines the app
can handle the attack. Info is loaded
into Fortify Software Security Center
(SSC) & used with Fortify Static
Code Analyzer (SCA) scan results
where issues are correlated.

Enterprise Ready / Integration


WebInspect offers interactive vulnerability re-
Figure 2. Comprehensive details to pinpoint and fix the issue view and retest features that helps the security
team validate issues and regression test fixes
■■ Test mobile-optimized websites as Find Vulnerabilities Faster / Earlier from development. The closed feedback loop
well as native web service calls. WebInspect can be tuned by variety of con- from security testing through development
■■ Provides more details so dev can fix trols to find vulnerabilities fast and tune per- improves the overall security effectiveness
vulnerabilities faster (line of code detail & formance optimized for your application and across the organization.
return stack trace info back to vulnerability organizational security exposure.
via Fortify WebInspect Agent technology). Manage application security risk across the
Enhance scan with agent technology that ex- enterprise with reports for remediation and
■■ Software Security Research team
pands the coverage of the attack surface and management oversight. Monitor trends and
translates cutting-edge research
detect additional types of vulnerabilities. take action on vulnerabilities within an appli-
into security intelligence.
■■ Integrates dynamic and runtime analysis cation. Build an enterprise-wide AppSec pro-
to find more vulnerabilities—and fix gram that manages and provides visibility to
Key Benefits your risk profile via dashboards and reports,
them faster. WebInspect Agent crawls
Automation with Integration more of an application to expand the so you can confirm remediation, track metrics,
WebInspect can be run as a fully-automated coverage of the attack surface (hidden trends and progress. WebInspect Enterprise
solution to meet DevOps and scaling needs, directories & pages, OATH Authentication, establishes a shared service to centralize re-
and integrate with the SDLC without adding Unused Parameters/Backdoor, Privacy sults while distributing security intelligence.
additional overhead. violation) and detect new types of Site Explorer—Standalone allows develop-
vulnerabilities that can go undetected by ers to get rich remediation information and
■■ REST APIs help achieve a
black-box security testing technologies. WebInspect-like views.
tighter integration and help
automate scans and check whether IAST follows what is already entered in
the application by functional tests. Compliance Management with pre-configured
compliance requirements have
policies and reports for all major compliance
been met. Incremental Scans target vulnerability detec-
regulations related to application security, in-
■■ Leverage prebuilt integrations for tion in newly generated application surface.
cluding PCI, SOC, ISO, OWASP, and HIPPAA.
Micro Focus Application Lifecycle Flexible access to the feature through REST
Customizing existing or creating new policies
Management (ALM) and Quality API, GUI, or command line.
is supported through the compliance manager
Center, and other security testing tool.
and management systems. Prioritization with advanced technologies:
■■ Scan RESTful web services: supports ■■ Run custom policies that are tuned Flexible delivery model enables a quick start
Swagger and OData formats via towards high speed with policy manager and can scale as needed with an on premise
WISwag command line tool. ■■ Simultaneous crawl and audit or as-a-service approach.

2
About Fortify About Micro Focus protection, and data security to protect to-
Fortify offers the most comprehensive static Micro Focus is a leading provider of security day’s hybrid IT infrastructure from sophisti-
and dynamic application security testing and compliance solutions for the modern cated cyber threats.
technologies, along with runtime application enterprise that wants to mitigate risk in their
monitoring and protections, backed by indus- hybrid environment and defend against ad- Learn More At
try-leading security research. Solutions can be vanced threats. Based on market-leading https://software.microfocus.com/en-us/
deployed in-house or as a service to build a products from Micro Focus Data Security, software/webinspect
scalable, nimble Software Security Assurance ArcSight, and Fortify, the Micro Focus Security
program that meets the evolving needs of to- Intelligence Platform uniquely delivers the ad-
day’s IT organization. vanced correlation and analytics, application

www.microfocus.com 3
Contact us at:
www.microfocus.com

360-000044-002 | 4AA1-5363 | H | 06/18 | © 2018 Micro Focus or one of its affiliates. Micro Focus and the Micro Focus logo, among others, are
trademarks or registered trademarks of Micro Focus or its subsidiaries or affiliated companies in the United Kingdom, United States and other countries.
All other marks are the property of their respective owners.

You might also like