馃帹 Design: Add additional customization options for scanner and site profiles

Actionable Insights

Actionable insights always have a follow-up action that needs to take place as a result of the research observation or data, and a clear recommendation or action associated with it. An actionable insight both defines the insight and clearly calls out the next step. These insights are tracked over time.

Dovetail link: https://dovetailapp.com/projects/354235e3-a3d8-41d2-a87e-df06f03f6326/insights/9a54dce4-3646-4005-865a-803fcb6faef4
Details: Users mentioned some ways in which they鈥檇 like to customize their scanner and site profiles.
Action to take: Add additional customization options to both scanner and site profiles (examples below)

Why do users want more customization options?

  • Not hit a website too hard and cause latency on production

  • Save time (create a profile that only does a basic scan, and maybe one that hits everything, and another one that鈥檚 sort of in the middle)

Customization examples:

For scanner profiles:

  • Scan for specific types of vulnerabilities (example: SQL injections)

  • Set client or system proxy

  • Choose different technology stacks (?)

  • Limit time for scan

For site profiles:

  • Add an Allowlist (or Denylist) for specific URLs (in case you鈥檙e using CDNs or other external resources)
Edited by Annabel Dunstone Gray