Discover Potential Web Applications and APIs

The Discovery tab explores TAS integration with sources to discover potential web applications and APIs from your environment. 

TAS - TotalCloud 

The TAS-TotalCloud integration leverages the configuration of the cloud environment to autonomously identify and catalog potential web applications within your subscription. These potential web applications can be added to your subscription and scanned to identify the vulnerabilities.

To get the WAS-TotalCloud integration, contact your Technical Account Manager or Qualys Support representative.

Once the connection with TotalCloud is activated, the Discovery > Sources tab displays AWS connectors available under your subscription.

To add more connectors, click Create Connector. It opens the Qualys Connector user interface. To learn more about adding a new connector, refer to Create a Connector to Onboard your AWS Organization.

To view and manage discovered web applications, click Discovred Web Applications (xx). It opens the Discovered Web Applications tab. To learn more about managing them, refer to Discovered Web Applications.

MuleSoft API Connectors

With the MuleSoft API Connectors, TotalAppSec can discover Swagger files with all endpoints exposed in your environment. This enhances the TotalAppSec's discovery feature and strengthens your organization's security posture. 

To create a MuleSoft Connector, navigate to MuleSoft API Connectors and click Create Connector 

Once the connector is created, the APIs discovered from your environment are displayed in the Discovered APIs tab.

Azure API Connectors 

With the Azure API Connectors, TotalAppSec can now discover Swagger files with all endpoints exposed in your Azure environment. This enhances the TotalAppSec's discovery feature and strengthens your organization's security posture. 

To create an Azure API Connector, navigate to Azure API Connectors and click Create Connector.  

Once the connector is created, the discovered APIs are displayed in the Discovered APIs tab.

Swagger API Discovery 

With Swagger discovery scan, TAS discovers potential Swagger and OpenAPI specification files of the web applications in your subscription. 

To launch API discovery scan, navigate to Applications > Web Applications. Select a web application, and click API Discovery Scan from the Quick Actions

The APIs are displayed in the Discovered APIs tab.