AppSecNews
DAST Commercial Established

Black Duck Web Scanner

by Black Duck

Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

Visit blackduck.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Black Duck Web Scanner in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 4 points in this profile are not yet confirmed against vendor documentation.
  • Product naming and packaging: the vendor renamed from Synopsys Software Integrity Group, confirm current product name and how it is sold
  • Relationship to the vendor's other dynamic offerings (managed dynamic testing versus this scanner): verify
  • Integration list: only partially confirmed, verify against vendor docs
  • Language and framework specific crawling support: unconfirmed

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Black Duck Web Scanner performs dynamic testing against a running web application or API. It crawls the target to discover reachable endpoints, forms and parameters, then sends attack traffic against them and evaluates the responses for evidence of injection, cross site scripting, transport and header misconfiguration, information disclosure and similar externally observable issues. For APIs the scanner can be driven from a specification so that endpoints are exercised directly rather than discovered by walking a user interface.

The lineage here matters more than the check list. This offering came into the portfolio through acquisition of a scanner built for automation first use, and that shows in how it is packaged: it is designed to be triggered by a pipeline and to return machine readable results, rather than to be driven interactively by a tester. It is sold as one analysis engine among several on the vendor's application security platform, so findings sit next to static analysis and software composition results for the same application rather than in a separate console.

Where it fits

This belongs in a build or release pipeline at an organization that has already standardized on Black Duck for other analysis types. A security team configures targets, scan policies and credentials, and developers see results through the shared platform and whatever ticketing integration is in place. It needs a deployed, reachable environment to test, which usually means a staging tier that is kept close enough to production for results to be meaningful.

Strengths

  • Consolidated reporting alongside static and composition analysis for the same application, which reduces the number of consoles a team has to work in.
  • Automation oriented design, intended to be invoked from pipelines rather than operated by hand.
  • API testing driven from a specification rather than only from crawling.
  • Backed by a vendor with an established enterprise support and procurement footprint.

Limitations

  • Value depends heavily on already owning the surrounding platform. As a standalone scanner it is harder to justify against dedicated DAST specialists.
  • Product naming and packaging have changed through acquisition and rebranding, which makes documentation and community knowledge harder to navigate.
  • Automated dynamic testing cannot reach authorization and business logic flaws, and this is no exception.
  • Depth of interactive testing capability is limited compared with a proxy based tool a human drives.

Who it suits

A reasonable addition for an enterprise already running Black Duck for software composition analysis or static analysis that wants dynamic coverage without adding a separate vendor relationship. Not the tool to choose if dynamic testing is your primary need and you are starting from a blank sheet, and not a fit for a team that wants a hands on proxy for manual testing.

Used Black Duck Web Scanner? Recommend it under your own name and title.

Recommend this tool