Can i scan behind authentication or login pages
Yes. You can configure S4E to crawl and scan authenticated areas by adding the required headers.
To do this:
-
Go to Asset Manager.
-
Open the settings for your asset.
-
Go to the Crawler tab and open the Header section.
-
Add authentication-related headers such as Authorization, Cookie, or X-API-Key.
-
Set the Valid Time if the headers expire.
S4E will use these headers during crawling and scanning. Make sure the values stay valid while the scan is running.