What This Article Covers

This guide walks you through the configuration process for Astra’s vulnerability scanner on web applications — from setting the scan scope to enabling login authentication. Proper configuration ensures maximum vulnerability coverage with minimal noise.

Who Should Read This

Security engineers, DevOps, and developers setting up web application scans. Access to the Astra dashboard and knowledge of your app's architecture and authentication are required.

Why This Matters

Accurate configuration allows the scanner to explore the entire attack surface, including authenticated areas, and reduces false positives by targeting only what matters.

Pre-requisites (For Pentest/Manual Scan)

Before starting the setup, ensure the following details are available :

Mandatory:

Step-by-Step Configuration

Step 1: Access the Scanner Setup

  1. Go to the Targets page on the Astra dashboard.

  2. Click on the Setup Target button next to the target you wish to configure.

1.png
  1. You'll now enter the setup wizard where you define your scan configuration.

Breakdown of This Step:

Define the Target URL & Scope of the Scan

To avoid scanning unnecessary third-party services, specify the scope precisely.

2.png

Learn how to configure scope
Choosing between production vs staging environments

Configure Subdomain Crawling

Decide how much of your domain tree should be explored:

3.png

Add Additional Hosts

If your app uses other hostnames (CDNs, microservices, external APIs), add them here so they’re included in the scan.

4.png

Step 2: API Scanning

Enhance scanner coverage by:

5.png

Step 3: User Roles

If your application requires login:

6.png

Create temporary accounts to avoid unwanted data in production


Step 4: Login Recording

Use Chrome DevTools Recorder to capture the login process:

7.png

Step 5: Optimize Tech Stack

Select technologies your app uses to:

Supported stack options include frameworks (React, Django), languages, CMSs, etc.

8.png

Step 6: Add Application Details

Give a brief overview of your app’s purpose and key features:

Example: A SaaS app for booking appointments online. Users can view availability, schedule, and pay through the portal. Built with Vue.js frontend and Node.js backend.

This context helps Astra create business logic test cases during manual testing.

9.png

Step 7: Advanced Settings

Customize the scan further:

10.png

Step 8: Complete Setup

Review your configuration. Once satisfied, click Complete Setup.

Any config changes made mid-scan will only apply to the next scan.

11.png

Need Help?

Reach out to our support team via the dashboard or submit a ticket if you face issues during setup.