
How to set up Attack Surface Custom Policies
Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …

In October, we launched a new feature called Attack Surface Custom Policies for Surface Monitoring customers. Attack Surface Custom Policies makes it possible to set, enforce, and scale customizable security policies so you can focus on the issues that matter most.

Since launching this feature, we’ve generated thousands of alerts on potential risks for our customers. For some customers, it was particularly difficult to view these reports. We’ve now made it possible to view alerts page-by-page so you can easily take action on resolving risks as they occur on your attack surface.
Are you a Surface Monitoring customer and not using Attack Surface Custom Policies yet? Check out this guide on how to set up your first custom policy. You can also find additional information on how Attack Surface Custom Policies works through our knowledge base.
Modern web applications that rely on heavy JavaScript usage and SPAs will now see better coverage with Application Scanning. These improvements to crawling will do a better job at reaching more parts of your web application to run security tests on. We have experimented with this new crawling functionality with a select group of customers, but it is now running on all Application Scans.
Here is a list of all new medium, high, and critical severity modules added in the recent days from our community of ethical hackers. You can find a complete list of new vulnerabilities added to Surface Monitoring and Application Scanning by viewing the “What’s New?” section in-tool.
Today, security teams can use Attack Surface Custom Policies on open ports. In the coming weeks, we will begin rolling out additional functionality. Future improvements include scoping custom policies to specific domains, technologies, and much more. If you’re interested in trying Detectify, book a demo or sign up for a 2-week free trial and start testing your web apps with Detectify today.

Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …

Introducing Attack Surface Custom Policies If you’re responsible for security, then you know how useful it is to have clearly-defined security policies that are simple …