Gain back your time.
Core functionality
- Server-stack identification.
- Identify amount and types (link, form, cookie etc.) of inputs.
- Identify input/output characteristics.
- Data sinks (HTTP, HTML, DOM, JS)
- Active and inactive server-side inputs.
- Active and inactive client-side inputs.
- Parallel webapp scans.
- Multi-role scans.
- More to come...
Bleeding edge technology
By being backed-up by Google Chrome, Codename RKN is on the bleeding edge of support for modern web applications.
- JavaScript/DOM/HTML5/AJAX.
- Tracing of data and execution flows of DOM and JavaScript environments.
- Extra tracing optimizations for common JavaScript frameworks.
Web applications are no longer black-boxes with its client-side IAST/DAST hybrid approach.
Intelligent
On-the-fly adaptation to each web application, down to the single input.
Analysis of each resource individually, which in turn allows for tailoring each request to the technologies being used, as well as the behavioral characteristics of each individual input vector.
Articles
The Arachni Chronicles
A story of curiosity, experimentation, development, million euro deal, fraudsters, abandonment and revitalization. From the inception of the F/OSS Arachni...
Continuous client-side IAST/DAST Hybrid approach for Single-Page-Applications
Some very interesting technology was presented a few days ago in the following articles: Following the data: Taint-tracing in the...
Managing an SCNR cloud over REST
New products and their terminology can be daunting, especially when it has to do with architectural things. To take care...