Authenticated Scanning Onboarding

StackHawk - DAST Security

Product Design

The Barrier to Success

Context

StackHawk is the leading DAST (Dynamic Application Security Testing) tool for modern companies. Focused on developer integration and workflow for catching security vulnerabilities before hitting production.

The unfortunate reality of security is that it quickly becomes very technical and confusing. For any DAST tool to work properly, not just StackHawk, a user must tell the DAST Scanner how to login to the application to fully test the application. This is an area that most users were struggling, and most support calls were around this issue. Half the problem was StackHawk not having any tools to help make facilitate setup, and it being an area most users didn’t have enough technical skills to complete.

Solution

After lots of research, we found the largest pain point we could influence was education. Every application is unique so a “one size fits most solution” was not a realistic goal.

So we built a wizard in the UI to simulate the conversations the support team were having with customers. We focused explaining complicated options as simply as possible and prompting the user to find the right types of information to be able to begin solving the problem.