How to proactively assess you security posture with F5 Distributed Cloud Web App Scanning

F5 DevCentral CommunityAbout 3 min readJun 18, 2025Watch original
THE SUMMARYAI-generated

Web App Scanning: F5 Distributed Cloud

Key Concepts:

  • Web App Scanning
  • Inventory Discovery (Recon Module)
  • Vulnerability Scanning (Scan Module)
  • Application Portfolio Security
  • API Discovery
  • Security Score
  • OWASP Top 10
  • SAS-based deployment
  • On-premises deployment

Challenges Addressed

Web App Scanning addresses two primary challenges:

  1. Difficulty in Establishing an Inventory of Exposed Assets: Many organizations struggle to identify all their applications and APIs exposed to the internet.
  2. Logistic Burden of Securing Large-Scale Application Portfolios: Manually securing a large number of applications, especially those requiring authentication, is resource-intensive and often infeasible.

Inventory Discovery (Recon Module)

  • Purpose: Creates accurate and complete application and API inventories in an automated fashion.
  • Functionality:
    • Requires only a domain name to start.
    • Discovers network address blocks, servers, and services associated with the domain.
    • Identifies potential issues like dangling CNAME records.
  • Process:
    1. Add a domain to the Recon module.
    2. Specify automatic domain discovery (optional).
    3. Optionally disable automated service scanning for manual selection.
    4. Review the discovered inventory, grouped by network address block, server software, and service.
    5. Export the inventory for further analysis.
    6. Export identified issues (e.g., dangling CNAME records).

Vulnerability Scanning (Scan Module)

  • Purpose: Discovers vulnerabilities in applications and APIs.
  • Functionality:
    • Automated process suitable for large-scale portfolios.
    • Can be scheduled for recurrent testing.
    • Performs service-specific vulnerability scans.
    • Performs API discovery.
  • Process:
    1. Select a service from the inventory discovered by the Recon module.
    2. Create a new scan for the selected service.
    3. The Scan module automatically creates an application entry.
    4. Monitor the scan status in the Scan module dashboard.
    5. Review the scan results, including:
      • Overall security score.
      • Found issues grouped by severity (tabular and graphical format).
      • Test report.

Interface and Reporting

  • Dashboard: Displays a list of domains and discovered assets (network address blocks, servers, services).
  • Issues Details: Provides information on each vulnerability, including:
    • Mapping.
    • Status.
    • Detailed description.
    • Explanation provided by a generative AI assistant, including context and recommended mitigation.
  • API Endpoints: Displays discovered API endpoints, including request/response pairs and number of occurrences.
  • Scan Report:
    • Maps vulnerabilities to the OWASP Top 10.
    • Includes a video recording of the actions taken by the Scan module (useful for audit purposes).
    • Generates customizable PDF reports for presenting test results.

Deployment Model

  • SAS-based: The default deployment model.
  • On-premises: Can be installed on-premises for security or regulatory compliance reasons.

Conclusion

Web App Scanning in F5's Distributed Cloud offers a comprehensive solution for discovering and securing web applications and APIs. By automating inventory discovery and vulnerability scanning, it addresses the challenges of managing large-scale application portfolios. The platform provides detailed reports, AI-powered explanations, and flexible deployment options, making it a valuable tool for organizations seeking to improve their web application security posture.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.