Skip to content
Mockingjay

Scan the app your users actually log into.

Mockingjay DAST crawls modern single-page apps behind SSO and MFA, tests every role, and validates each finding before it reaches your backlog. Run it on a schedule, or as a quality gate on every pull request.

SCAN-4812 · app.example.com · triggered by pull request #482Authenticated scan · SSO + MFA · 3 user roles
Testing · 78%
  1. Authenticate, 100% complete
    SSO + MFA · 3 roles
  2. Crawl, 100% complete
    2,316 URLs · 184 forms
  3. Discover APIs, 100% complete
    212 XHR endpoints
  4. Active tests, 78% complete
    41,880 / 53,600 checks
  5. Validate, 30% complete
    Re-confirming 6 issues
Findings in this scan3 new · 2 fixed · 11 unchanged
  • NewHighStored XSS in profile display name/settings/profile · role: userValidated
  • NewMediumSession cookie missing SameSite attributeapp.example.com · all routesValidated
  • NewMediumOpen redirect on logout/auth/logout?next=Validated
  • FixedHighSQL injection in report filter/reports?sort=Retest passed
  • FixedLowServer version disclosed in headersall responsesRetest passed
  • OpenMediumCSRF on billing address update/billing/address · role: adminValidated
Pull request check
mockingjay/dast — 1 new high
  • Policy: block merge on new High or Critical
  • Baseline: main @ 9f3c2a1
  • Report: app.mockingjay.io/scans/4812
Schedule
Full scan
Nightly · 02:00 SGT
Incremental
Every pull request
Rate limit
20 req/s
Illustrative product view · sample data

Fewer false positives. More of the app covered.

Catch it in review, not in production.

Add one step to your workflow. Mockingjay scans the preview environment, compares results against your main branch and only fails the build on new issues that cross your policy.

  • GitHub Actions
  • GitLab CI
  • Azure Pipelines
  • Jenkins
name: security
on: [pull_request]
jobs:
  dast:
    runs-on: ubuntu-latest
    steps:
      - uses: mockingjay/dast-action@v2
        with:
          target: ${{ env.PREVIEW_URL }}
          profile: app-example-sso
          fail-on: high
          token: ${{ secrets.MJ_TOKEN }}

Mapped to the OWASP Top 10.

  • A01Broken access control
  • A02Cryptographic failures
  • A03Injection
  • A04Insecure design
  • A05Security misconfiguration
  • A06Vulnerable components
  • A07Authentication failures
  • A08Integrity failures
  • A09Logging and monitoring gaps
  • A10Server-side request forgery

DAST questions

How is this different from a pentest?
DAST runs automatically and often, catching known vulnerability classes as code changes. A pentest adds human judgement for business logic and chained attacks. Most teams run both, and Mockingjay keeps their findings in one place.
Can it scan production?
Yes, with a safe-check profile, rate limits and excluded paths. Many teams scan a staging or preview environment on every change and production on a schedule.
What do you need to set up authentication?
A test account for each role and a recorded login. For SSO, we support SAML and OIDC flows, and TOTP-based MFA.
How long does a scan take?
Incremental pull request scans usually finish in minutes. Full scans depend on app size and usually take 2–6 hours.

See a scan of your own app.

We'll set up an authenticated profile with you and walk through the first results together.

Book a demo