Forum Discussion

1 Reply

  • ASM is a web application firewall, and is not specifically designed to be an application security testing tool. However, if you create a security policy and place it into Transparent enforcement mode, you can review the violations and learning suggestions that will be generated as HTTP traffic is observed. This will give you some idea about the threats facing your application. There are plenty of vulnerability assessment tools out there, such as WhiteHat, AppScan, Immuniweb, and others which can be configured to crawl your application and then report on identified vulnerabilities.