Discover Potential Web Applications and APIs
The Discovery tab explores TAS integration with sources to discover potential web applications and APIs from your environment.
TAS - TotalCloud
The TAS-TotalCloud integration leverages the configuration of the cloud environment to autonomously identify and catalog potential web applications within your subscription. These potential web applications can be added to your subscription and scanned to identify the vulnerabilities.
To get the WAS-TotalCloud integration, contact your Technical Account Manager or Qualys Support representative.
Once the connection with TotalCloud is activated, the Discovery > Sources tab displays AWS connectors available under your subscription.
To add more connectors, click Create Connector. It opens the Qualys Connector user interface. To learn more about adding a new connector, refer to Create a Connector to Onboard your AWS Organization.
To view and manage discovered web applications, click Discovered Web Applications (xx). It opens the Discovered Web Applications tab. To learn more about managing them, refer to Discovered Web Applications.
MuleSoft API Connectors
With the MuleSoft API Connectors, TotalAppSec can discover Swagger files with all endpoints exposed in your environment. This enhances TotalAppSec's discovery feature and strengthens your organization's security posture.
To create a MuleSoft Connector, navigate to MuleSoft API Connectors and click Create Connector.
Once the connector is created, the APIs discovered from your environment are displayed in the Discovered APIs tab.
Azure API Connectors
With the Azure API Connectors, TotalAppSec can now discover Swagger files with all endpoints exposed in your Azure environment. This enhances TotalAppSec's discovery feature and strengthens your organization's security posture.
To create an Azure API Connector, navigate to Azure API Connectors and click Create Connector.
Once the connector is created, the discovered APIs are displayed in the Discovered APIs tab.
AWS API Connectors
With the AWS API Connectors, TotalAppSec can discover Swagger files with all endpoints exposed in your AWS environment. This enhances TotalAppSec's discovery feature and strengthens your organization's security posture.
To create an AWS Connector, navigate to AWS API Connectors and click Create Connector.
Once the connector is created, the APIs discovered from your environment are displayed in the Discovered APIs tab.
Source Code API Connectors
With Source Code API Connectors, TotalAppSec can discover APIs directly from your source code repositories, without requiring an API gateway. The connector scans the branch or tag you configure, generates OpenAPI 3.x specifications from the annotations in supported Python and Java source code, and imports the discovered APIs as CODE_REPO web application assets. Scans are registered automatically, so you do not need to upload Swagger or OpenAPI specification files manually.
The following Source Code API connectors are available:
-
Bitbucket Source Code API: Authenticate using a user name and app password, or an access token.
-
Azure DevOps Source Code API: Authenticate using a personal access token.
-
GitHub Source Code API: Authenticate using a personal access token.
-
GitLab Source Code API: Authenticate using a personal access token.
-
Gitea Source Code API: Authenticate using a personal access token.
-
Codeberg Source Code API: Authenticate using a personal access token.
To create a Source Code API Connector, navigate to Discovery > Sources, select the required Source Code API connector, and click Create Connector.
Once the connector is created, the APIs discovered from your repository are displayed in the Discovered APIs tab.
Swagger API Discovery
With Swagger discovery scan, TAS discovers potential Swagger and OpenAPI specification files of the web applications in your subscription.
To launch API discovery scan, navigate to Applications > Web Applications. Select a web application, and click API Discovery Scan from the Quick Actions.
The APIs are displayed in the Discovered APIs tab.