Azure web app security vulnerability (Infra/DAST) scanning service

Michael Solomon 21 Reputation points
2021-11-18T16:23:10.783+00:00

Can you please provide the list of security vulnerability scanning option built into the Azure App Service management?

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,939 questions
0 comments No comments
{count} votes

Accepted answer
  1. SnehaAgrawal-MSFT 22,706 Reputation points Moderator
    2021-11-22T12:22:50.567+00:00

    Thanks for asking question! As its documented here Important update for Tinfoil security - Azure App Service,

    "We’re announcing that Tinfoil Security addon will no longer be available through App Service."

    As per my knowledge Azure does not provide any internal web vulnerability testing tools. Just like “Tinfoil Security”, you need to use a third-party application to do the vulnerability scan.

    Here are some third-party reference documents:

    a. For “Tinfoil Security”, you can visit the official website of "Tinfoil Security" for consulting, url: API Security Testing & DAST Tools | Tinfoil (tinfoilsecurity.com).
    b. You can kindly read this document, OWASP Foundation | Open Source Foundation for Application Security, to find a third-party security tool.
    c. In addition, refer to Vulnerability Scanning Tools | OWASP, this document lists many third-party web vulnerability scanning tools.

    Hope this helps, let us know.

    Disclaimer: This response contains a reference to a third-party World Wide Web site. Microsoft is providing this information as a convenience to you. Microsoft does not control these sites and has not tested any software or information found on these sites; therefore, Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. There are inherent dangers in the use of any software found on the Internet, and Microsoft cautions you to make sure that you completely understand the risk before retrieving any software from the Internet.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.