VulnSign product documentation

One guide to the complete application security workflow.

Learn how VulnSign brings automated DAST, manual validation, network discovery, AI-assisted analysis, reporting, and team remediation together in a locally managed desktop platform.

documentation areas
13
report formats
3
interface languages
9
unified workflow
1
01

Getting started

Move from installation to your first security scan with a clear, repeatable workflow.

Initial setup

Create the first administrator, sign in, and prepare the local VulnSign environment.

Add a target

Register the application URL, attach a default scan profile, and organize it for future testing.

Configure coverage

Choose a profile and policy, then define authentication, discovery, scope, and attack behavior.

Start and review

Run the scan, follow progress in real time, inspect evidence, and create a report.

Good to know: Recommended path: Target → Scan profile → Scan → Findings → Retest → Report.
02

Dashboard & operational overview

Monitor the current security posture and quickly reach work that needs attention.

Security overview

View scan, target, issue, and severity signals from one landing area.

Recent activity

Keep track of recent scans and changes without moving between individual records.

Actionable navigation

Jump directly into targets, scans, issues, workspaces, network discovery, and reports.

03

Targets & attack surface

Model the applications you own, group related assets, and preserve reusable testing context.

Target inventory

Create, edit, inspect, and scan web targets from a central inventory.

Target groups

Group applications by product, environment, customer, or internal ownership.

Default profiles

Associate a preferred scan profile with a target to reduce setup time and configuration drift.

WAF-aware launch

Check for a web application firewall before a scan and choose an appropriate WAF mode.

04

Automated DAST

Configure, launch, schedule, and compare active and passive application security scans.

Scan profiles

Reuse complete scan configurations, including discovery, authentication, scope, and runtime options.

Scan policies

Control which scanner rules run and maintain shared policies for consistent team coverage.

Custom payloads

Extend attack testing with organization-specific payload collections where the edition allows it.

Scheduled scans

Create recurring tasks so important applications are tested on an operational cadence.

Live scan detail

Follow scan state, discovered URLs, active and passive results, logs, and observed technologies.

Scan comparison

Compare scan runs to understand new, persistent, resolved, and changed findings.

05

Authentication & scan context

Reach protected application states by carrying the identity and request context your application expects.

Form authentication

Configure personas and credentials for sign-in flows used during authenticated discovery.

Headers and parameters

Supply request headers, parameter authentication, imported credentials, and starting links.

Scope controls

Keep exploration and attacks focused on the intended hosts, routes, and application boundaries.

Connection handling

Review insecure connection, SSL bypass, and authentication warnings before testing.

06

Manual security workspace

Validate automated results and conduct hands-on web testing without leaving the project context.

HTTP history

Inspect captured requests and responses with filtering and reusable evidence.

WebSocket history

Review WebSocket conversations alongside traditional HTTP application traffic.

Intercept

Pause, inspect, modify, and forward requests while interacting with the target.

Repeater

Create multiple request tabs, edit raw HTTP, and replay requests for focused verification.

Intruder

Run parameterized request variations for targeted, analyst-controlled attack workflows.

Replacer & passive scan

Apply reusable request replacements and submit captured traffic for passive analysis.

Site map

Explore the observed application structure and move captured endpoints into manual tools.

Remote browser

Browse the target through the testing environment while traffic and application state stay connected.

Remote Android

Operate a server-side Android emulator, control its proxy connection, and keep mobile traffic in the same workspace.

AI-guided mobile crawl

Follow live AI crawl turns for mobile-application scans and review how the application is explored.

07

Findings & remediation lifecycle

Turn scanner output into evidence-backed issues that teams can triage, fix, and verify.

Unified issue queue

Review issues by severity and workflow state across scans and targets.

Evidence-rich detail

Inspect technical context, affected locations, HTTP evidence, confidence, and remediation guidance.

Manual findings

Document analyst-discovered issues in the same system as automated findings.

Status workflow

Move work through To Do, Waiting for Retest, Addressed, and complete issue views.

Retesting

Verify remediation and retain the relationship between the original finding and its validation.

False-positive handling

Classify non-actionable results so reports and remediation views remain focused.

08

Network & subdomain discovery

Add external infrastructure context to application findings and map exposed services.

Network hub

Review network risk and exposed services from a consolidated dashboard.

Port scanning

Start port scans, inspect results, and understand the services visible on an asset.

Subdomain scanning

Discover subdomains that expand the known web attack surface.

Scheduled network scans

Repeat port discovery on a schedule and watch the exposed surface over time.

Technology inventory

Review technologies observed during testing to support prioritization and investigation.

09

AI-assisted security

Use embedded assistance to plan tests, understand evidence, and communicate risk more efficiently.

AI chat

Create focused conversations and ask questions within the application security workflow.

Finding analysis

Open issue-aware chat to reason about evidence, impact, validation, and remediation.

Scan instruction

Provide natural-language direction while preparing supported scan workflows.

Attack chains

Connect related weaknesses to communicate compound attack paths rather than isolated alerts.

Executive summaries

Generate stakeholder-oriented report narratives when AI reporting is available.

Provider settings

Manage assistant configuration from a dedicated settings area.

Good to know: AI capabilities are edition-dependent and support analyst decisions; evidence should still be reviewed before remediation.
10

Reporting & exports

Produce technical and executive deliverables for developers, security teams, and automation.

PDF reports

Generate printable reports with cover, contents, summaries, issue categories, evidence, and recommendations.

JSON export

Export machine-readable scan data for custom processing and internal tooling.

SARIF export

Send structured findings into DevSecOps and source-code security workflows.

Report controls

Filter by severity or specific issue and include HTTP details, attacked URLs, network surface, and technology stack.

Audience-ready summaries

Add a manual summary or an AI-generated executive summary to supported PDF reports.

Report history

Keep generated deliverables discoverable from the reports area.

11

Integrations & automation

Connect security testing with delivery pipelines, issue workflows, distributed agents, and custom clients.

CI/CD

Bring DAST into automated delivery workflows with generated integration guidance and scripts.

Issue trackers

Configure external issue-management connections for remediation coordination.

Agents

Manage scanning agents used to reach or distribute testing across environments.

API keys

Create and manage credentials for programmatic access and automation.

12

Teams, roles & governance

Coordinate security work while keeping access and accountability visible.

Team members

View and manage the people who participate in the security program.

Roles

Define role-based access appropriate to operators, analysts, and stakeholders.

Activity trail

Review team activity for operational awareness and accountability.

Shared configuration

Share selected policies and reusable testing configuration across the team.

Notifications

Keep users informed about relevant product and testing events.

13

Platform administration

Adapt the local interface and runtime behavior to the organization and its environment.

Account management

Maintain the signed-in user’s profile and account preferences.

Application settings

Configure platform behavior from a centralized settings page.

DAST output

Inspect scanner output in a dedicated control view for troubleshooting and visibility.

Resource awareness

Surface capacity warnings before a scan starts to protect the local environment.

Themes

Use light, dark, system, and interface theme controls.

Languages

Use the desktop interface in English, Turkish, German, Spanish, French, Portuguese, Arabic, Japanese, or Chinese.

Ready to put the workflow into practice?

Download VulnSign for your environment or compare editions to find the feature set that matches your program.