OpenTextのホームページ。
Application Security

OpenText Fortify DAST Aviator

Automate login macros for authenticated DAST at DevSecOps scale

Gartner® named OpenText a leader in application securityGet the Magic Quadrant report

Eliminate the biggest bottleneck in authenticated DAST

Creating login macros has long been one of the most time-consuming, error-prone steps in DAST onboarding. OpenText™ Fortify™ DAST Aviator™ changes that.

Watch how AI-powered DAST Aviator eliminates manual login macro scripting

With Fortify DAST Aviator, security teams provide a URL, credentials, and optional MFA. An LLM browser agent, working with proven TruClient object-detection capabilities, analyzes the authentication flow and builds a parameterized macro in seconds, ready to use in a scan. It’s that easy.
データシートを読む

Why OpenText Fortify DAST Aviator?

Fortify DAST Aviator brings AI-driven automation to authenticated dynamic testing, engineered for the scale, speed, and security demands of modern DevSecOps.

  • 速度
    Find exploitable vulnerabilities faster
    Surface real, exploitable issues with automated testing built for modern apps. Intelligent triage focuses teams on what matters.
  • 自動化
    Reduce manual effort across the scan lifecycle
    Automate scans via APIs, CLI, or containers. AI-assisted login macro generation streamlines authenticated testing, even in MFA environments.
  • Coverage
    Test today's complex web stacks
    Analyze modern web stacks like JavaScript, JSON, AJAX, GraphQL, and HTTP/2 with the coverage and performance enterprise teams need.

Authenticated DAST use cases

Fortify DAST Aviator applies across a range of authenticated DAST scenarios, from scaling scan coverage to integrating dynamic testing into CI/CD.

  • Extend authenticated DAST coverage across your entire portfolio without adding headcount or specialized scripting expertise. Fortify DAST Aviator automates macro generation for enterprises that can’t manually create macros for hundreds of applications.

  • Eliminate hours or days of macro setup. With Fortify DAST Aviator, teams provide a URL and credentials and get a working macro in seconds, collapsing onboarding from a multi-day task to a same-day activity.

  • Update credentials without regenerating the macro. Parameterized Fortify DAST Aviator macros enable security teams to run authenticated DAST scans as part of automated build pipelines, without re-recording macros or managing scripts in source control.

  • Regenerate macros on demand rather than rebuilding fragile recorded flows when UIs change or credentials rotate. This keeps authenticated DAST coverage accurate as applications evolve, without manual rework.

    Key features of Fortify DAST Aviator

    Fortify DAST Aviator is built into OpenText Fortify ScanCentral DAST and Software Security Center—no external tooling, no manual recording, and credentials that stay in your environment.

    AI-driven login macro generation

    Uses a multi-model LLM to simulate human user actions and drive a recording of a macro without human intervention. Provide a URL and credentials; the agent handles the rest.

    TruClient foundation

    Powers object detection and action execution using proven TruClient capabilities, guided by the LLM for accurate and resilient login flow navigation across diverse web applications.

    Parameterized credentials

    Updates usernames, passwords, and other inputs without regenerating the macro. Supports credential rotation policies and multi-environment scanning across dev, staging, and production.

    MFA and TOTP support

    Handles modern authentication flows, including time-based one-time passwords. Optionally accept a QR code or TOTP secret at setup for fully automated authenticated scanning.


    統合

    Fortify DAST Aviator inherits the Fortify ScanCentral DAST integration set, so generated macros drop directly into the CI/CD tools your DevSecOps teams already use.

    JenkinsJenkins
    AzureAzure DevOps
    githubGitHub Actions
    gitlabGitLab
    JiraJira
    ServiceNowServiceNow
    bambooBamboo
    circleciCircleCI

    Accelerate the value of OpenText Fortify DAST Aviator

    Add-ons

    Extend the value of Fortify DAST Aviator across the broader Fortify AppSec platform.

    導入

    あらゆる規模のグローバル組織に対応するスケーラブルで柔軟な導入オプションを探る

    OpenText Fortify DAST Aviator Resources

    • Fortify DAST Aviator uses a multi-model LLM to simulate human user actions to automatically generate login macros for authenticated dynamic application security testing (DAST) scans. Security teams provide a URL, credentials, and optional MFA, and Aviator produces a structured, parameterized macro in seconds, eliminating one of the most manual steps in DAST onboarding.

    • Credentials never leave the customer environment. They are not transmitted to the underlying large language model or to the Fortify Aviator service. Beyond control and metric data such as accounts, licenses, and usage telemetry, no application data is stored in the Fortify Aviator service.

    • Yes. Fortify DAST Aviator handles modern authentication flows including time-based one-time passwords (TOTP). At setup, teams can optionally provide a QR code or TOTP secret for fully automated authenticated scanning.

    • Fortify DAST Aviator is built into Fortify ScanCentral DAST and Software Security Center (SSC).

    • Generated macros are parameterized, so credentials can be updated without recreating the macro. Macros integrate directly into Fortify ScanCentral DAST and drop into existing CI/CD pipelines, enabling continuous authenticated scanning at DevSecOps scale.

      OpenText™ Fortify™ Remediation Aviator™

      Learn more

      OpenText™ Fortify™ SAST

      Learn more

      OpenText™ Fortify™ AppSec portfolio

      Learn more

      OpenText™ Fortify™ SAST

      Learn more

      OpenText™ Fortify™ AppSec portfolio

      Learn more

      次のステップへ

      Bring AI-driven automation to authenticated DAST. Talk with our team about how Fortify DAST Aviator can scale dynamic testing across your application portfolio.

      お問い合わせ