StackHawk

StackHawk Announces HawkScan Test Engine

Share on LinkedIn
Share on X
Share on Facebook
Share on Reddit
Send us an email
Scott Gerlach Blog Image

We are excited to announce that with the release of HawkScan 4.0, the transition to the HawkScan Test Engine (HSTE) will be complete. HSTE is the foundation of our scanning technology, embodying all of the enhancements and improvements StackHawk has developed to the Dynamic Application Security Testing capability. This move not only reinforces our commitment to providing top-tier security testing tools but also ensures that our customers benefit from faster updates and more robust features tailored to their needs.

The decision to fork ZAP was driven by the need for a development process that could keep pace with the rapid innovation demanded by StackHawk’s users. By forking ZAP, StackHawk has created a more agile and responsive development environment that aligns more closely with its strategic goals and customer requirements, including much deeper investment in API Security Testing.

Over time, the development work required to support StackHawk customers required a great deal of custom development for core functionality, speed, innovation, and also custom tests (what we test) as well as testing capabilities (how we test) to address web 3.0 and API driven development. This internal fork allows StackHawk to rework, remove and replace ZAP’s internals, making it easier to develop and support new features, ultimately accelerating time-to-market for enhancements critical to StackHawk’s customer base. We remain grateful to the ZAP community and are committed to contributing to the open-source ecosystem in meaningful ways.

More Hawksome Posts

Stop Choosing Between SAST and DAST—Start Connecting Them

Stop Choosing Between SAST and DAST—Start Connecting Them

AppSec teams spend up to 60% of their time chasing duplicate findings across SAST, DAST, and other tools. Correlating results eliminates redundant work, prioritizes based on real exploitability, and gives developers clear, actionable fixes. StackHawk makes this seamless by connecting code-level context with runtime validation directly in your CI/CD pipeline.

DAST Onboarding in Minutes with StackHawk’s GitHub Copilot Custom Agent

DAST Onboarding in Minutes with StackHawk’s GitHub Copilot Custom Agent

We are excited to announce StackHawk’s GitHub Copilot Custom Agent that analyzes your repository’s source code, generates a complete DAST configuration, and creates a working CI/CD security testing workflow—all in just minutes. No more setup friction between development and security. No more “we’ll add security testing later.” Just intelligent configuration that identifies what you should test, and starts finding runtime vulnerabilities faster.