What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Integration list: only partially confirmed, verify against vendor docs
- Deployment options for internal scanning appliances: confirm
- API and single page application coverage depth: verify with vendor
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
AppCheck runs unauthenticated and authenticated scans against web applications and against the hosts and services behind them. On the application side it crawls the target, including rendering pages so that client side generated links and forms are picked up, then probes discovered parameters with an attack library for injection, cross site scripting, file inclusion, deserialization and access control indicators. On the infrastructure side it performs port and service discovery and checks identified services against known vulnerability signatures, which puts host level exposure and application level exposure in the same report.
The vendor maintains its own vulnerability research function, and a recurring selling point is that checks for newly disclosed issues are written in house and pushed to the scanning engine rather than waiting on an upstream feed. Scan targets can include internal networks by placing a scanning component inside the perimeter and reporting back to the hosted console.
Where it fits
This sits with a security team or a managed service provider rather than with individual developers. Typical use is scheduled recurring scans of an external perimeter plus deeper authenticated application scans on a longer cycle, with findings triaged in the platform and pushed to a ticketing system. It assumes you have an inventory of what to scan, credentials for authenticated coverage, and someone who will own the queue of results. It is not a pull request gate.
Strengths
- One console covering both application and infrastructure findings avoids stitching together two separate scanning products.
- In house research means detection for newly published issues does not depend solely on third party feeds.
- Supports scanning of internal estates as well as internet facing assets.
- Reporting is oriented toward remediation ownership rather than raw output.
Limitations
- Breadth across application and infrastructure means it is rarely the deepest option in either discipline compared with specialists.
- As with any automated dynamic scanner, authorization and business logic flaws are largely out of reach.
- Authenticated scanning requires credential maintenance and breaks when login flows change.
- Smaller vendor footprint than the large enterprise DAST suites, so third party integrations and community tooling are thinner.
Who it suits
A reasonable fit for a mid sized organization, or a UK and European team with a compliance driven scanning requirement, that wants perimeter and application coverage from one supplier with a support relationship rather than a self service tool. Less suitable for engineering led teams who want scanning embedded in developer workflow, and not the right choice if you need deep manual testing capability, which this complements rather than replaces.
Used AppCheck? Recommend it under your own name and title.
Recommend this tool