One guide to the complete application security workflow.
Learn how VulnSign brings automated DAST, manual validation, network discovery, AI-assisted analysis, reporting, and team remediation together in a locally managed desktop platform.
- documentation areas
- 13
- report formats
- 3
- interface languages
- 9
- unified workflow
- 1
Getting started
Move from installation to your first security scan with a clear, repeatable workflow.
Initial setup
Create the first administrator, sign in, and prepare the local VulnSign environment.
Add a target
Register the application URL, attach a default scan profile, and organize it for future testing.
Configure coverage
Choose a profile and policy, then define authentication, discovery, scope, and attack behavior.
Start and review
Run the scan, follow progress in real time, inspect evidence, and create a report.
Dashboard & operational overview
Monitor the current security posture and quickly reach work that needs attention.
Security overview
View scan, target, issue, and severity signals from one landing area.
Recent activity
Keep track of recent scans and changes without moving between individual records.
Actionable navigation
Jump directly into targets, scans, issues, workspaces, network discovery, and reports.
Targets & attack surface
Model the applications you own, group related assets, and preserve reusable testing context.
Target inventory
Create, edit, inspect, and scan web targets from a central inventory.
Target groups
Group applications by product, environment, customer, or internal ownership.
Default profiles
Associate a preferred scan profile with a target to reduce setup time and configuration drift.
WAF-aware launch
Check for a web application firewall before a scan and choose an appropriate WAF mode.
Automated DAST
Configure, launch, schedule, and compare active and passive application security scans.
Scan profiles
Reuse complete scan configurations, including discovery, authentication, scope, and runtime options.
Scan policies
Control which scanner rules run and maintain shared policies for consistent team coverage.
Custom payloads
Extend attack testing with organization-specific payload collections where the edition allows it.
Scheduled scans
Create recurring tasks so important applications are tested on an operational cadence.
Live scan detail
Follow scan state, discovered URLs, active and passive results, logs, and observed technologies.
Scan comparison
Compare scan runs to understand new, persistent, resolved, and changed findings.
Authentication & scan context
Reach protected application states by carrying the identity and request context your application expects.
Form authentication
Configure personas and credentials for sign-in flows used during authenticated discovery.
Headers and parameters
Supply request headers, parameter authentication, imported credentials, and starting links.
Scope controls
Keep exploration and attacks focused on the intended hosts, routes, and application boundaries.
Connection handling
Review insecure connection, SSL bypass, and authentication warnings before testing.
Manual security workspace
Validate automated results and conduct hands-on web testing without leaving the project context.
HTTP history
Inspect captured requests and responses with filtering and reusable evidence.
WebSocket history
Review WebSocket conversations alongside traditional HTTP application traffic.
Intercept
Pause, inspect, modify, and forward requests while interacting with the target.
Repeater
Create multiple request tabs, edit raw HTTP, and replay requests for focused verification.
Intruder
Run parameterized request variations for targeted, analyst-controlled attack workflows.
Replacer & passive scan
Apply reusable request replacements and submit captured traffic for passive analysis.
Site map
Explore the observed application structure and move captured endpoints into manual tools.
Remote browser
Browse the target through the testing environment while traffic and application state stay connected.
Remote Android
Operate a server-side Android emulator, control its proxy connection, and keep mobile traffic in the same workspace.
AI-guided mobile crawl
Follow live AI crawl turns for mobile-application scans and review how the application is explored.
Findings & remediation lifecycle
Turn scanner output into evidence-backed issues that teams can triage, fix, and verify.
Unified issue queue
Review issues by severity and workflow state across scans and targets.
Evidence-rich detail
Inspect technical context, affected locations, HTTP evidence, confidence, and remediation guidance.
Manual findings
Document analyst-discovered issues in the same system as automated findings.
Status workflow
Move work through To Do, Waiting for Retest, Addressed, and complete issue views.
Retesting
Verify remediation and retain the relationship between the original finding and its validation.
False-positive handling
Classify non-actionable results so reports and remediation views remain focused.
Network & subdomain discovery
Add external infrastructure context to application findings and map exposed services.
Network hub
Review network risk and exposed services from a consolidated dashboard.
Port scanning
Start port scans, inspect results, and understand the services visible on an asset.
Subdomain scanning
Discover subdomains that expand the known web attack surface.
Scheduled network scans
Repeat port discovery on a schedule and watch the exposed surface over time.
Technology inventory
Review technologies observed during testing to support prioritization and investigation.
AI-assisted security
Use embedded assistance to plan tests, understand evidence, and communicate risk more efficiently.
AI chat
Create focused conversations and ask questions within the application security workflow.
Finding analysis
Open issue-aware chat to reason about evidence, impact, validation, and remediation.
Scan instruction
Provide natural-language direction while preparing supported scan workflows.
Attack chains
Connect related weaknesses to communicate compound attack paths rather than isolated alerts.
Executive summaries
Generate stakeholder-oriented report narratives when AI reporting is available.
Provider settings
Manage assistant configuration from a dedicated settings area.
Reporting & exports
Produce technical and executive deliverables for developers, security teams, and automation.
PDF reports
Generate printable reports with cover, contents, summaries, issue categories, evidence, and recommendations.
JSON export
Export machine-readable scan data for custom processing and internal tooling.
SARIF export
Send structured findings into DevSecOps and source-code security workflows.
Report controls
Filter by severity or specific issue and include HTTP details, attacked URLs, network surface, and technology stack.
Audience-ready summaries
Add a manual summary or an AI-generated executive summary to supported PDF reports.
Report history
Keep generated deliverables discoverable from the reports area.
Integrations & automation
Connect security testing with delivery pipelines, issue workflows, distributed agents, and custom clients.
CI/CD
Bring DAST into automated delivery workflows with generated integration guidance and scripts.
Issue trackers
Configure external issue-management connections for remediation coordination.
Agents
Manage scanning agents used to reach or distribute testing across environments.
API keys
Create and manage credentials for programmatic access and automation.
Teams, roles & governance
Coordinate security work while keeping access and accountability visible.
Team members
View and manage the people who participate in the security program.
Roles
Define role-based access appropriate to operators, analysts, and stakeholders.
Activity trail
Review team activity for operational awareness and accountability.
Shared configuration
Share selected policies and reusable testing configuration across the team.
Notifications
Keep users informed about relevant product and testing events.
Platform administration
Adapt the local interface and runtime behavior to the organization and its environment.
Account management
Maintain the signed-in user’s profile and account preferences.
Application settings
Configure platform behavior from a centralized settings page.
DAST output
Inspect scanner output in a dedicated control view for troubleshooting and visibility.
Resource awareness
Surface capacity warnings before a scan starts to protect the local environment.
Themes
Use light, dark, system, and interface theme controls.
Languages
Use the desktop interface in English, Turkish, German, Spanish, French, Portuguese, Arabic, Japanese, or Chinese.
Ready to put the workflow into practice?
Download VulnSign for your environment or compare editions to find the feature set that matches your program.