Skip to main content
A web application must exist before you can run a web security scan against it. The setup wizard at /web-applications/new takes four steps. Completed steps stay clickable in the progress bar at the top, so you can jump back to an earlier step without losing what you have entered.

Step 1: General information

  1. Go to /web-applications and click Add new.
  2. Fill in the fields:
Step 1 of the web application wizard with name, asset, risk owner, and remediation owner fields

Step 2: Target details

Click Next, then configure how the scanner reaches and crawls the application: If the start URL points at an unverified domain, a domain verification dialog prompts you to prove ownership before continuing. Step 2 of the wizard showing start URL, crawl scope, and sitemap configuration

Step 3: Scan configuration

Click Next to reach scan configuration: Step 3 scan configuration with the authentication records selector and robots.txt option

Creating an auth record inline

Clicking Create in the Authentication Records section opens the Add New Authentication Record dialog:
  • Name (required) — identifies the credential set. Empty submit returns Name is required.
  • Type (required) — the authentication method, such as Standard, Selenium Script, or Header Authentication. Empty submit returns Type is required.
  • Username and Password — required when Standard is selected.
Click Save. The record is created and attached to the web application you are setting up. Add New Authentication Record dialog with name, type, username, password, and comments fields

Step 4: Review

Check the summary across General Information, Target Details, and Scan Configuration, then click Finish to save and provision the web application. Review step summarizing the configured general information, target details, and scan configuration