StackHawk

StackHawk Announces Integration with Microsoft Defender for Cloud

Share on LinkedIn
Share on X
Share on Facebook
Share on Reddit
Send us an email
News Blog Thumbnail

DENVER, Colorado – May 07, 2024 – StackHawk , the company delivering API and application security testing as part of modern software delivery practices, announced a new integration with Microsoft Defender for Cloud to help organizations build software more securely. APIs are crucial to building modern applications. As a result, the API layer has become a critical security risk for many organizations. Efficient and proactive API security testing remains a pivotal challenge for security teams looking to strengthen their API security posture.

StackHawk’s latest product integration with Microsoft Defender for Cloud – a cloud-native application protection platform , gives security professionals greater visibility into the security status of their APIs during the time of development within one unified viewpoint and complements the runtime API security capabilities provided by Defender for APIs. The integration with StackHawk will enable users to aggregate API security findings and posture insights across multiple tools, providing AppSec professionals with a correlated view of current risks and a more integrated approach to securing APIs.

StackHawk continues to bridge the gap between application owners and security teams by combining shift-left and developer automation with visibility and insights into the health of an organization’s security posture. This latest product integration adds to StackHawk’s existing integrations across the Microsoft and GitHub ecosystems, allowing engineers to automate security testing via GitHub Actions and GitHub Advanced Security and now giving AppSec teams the API Security insights and oversight with Microsoft Defender for Cloud.

Microsoft customers looking to prioritize API security testing now have a seamless path with StackHawk. The StackHawk platform is intricately woven into the Microsoft ecosystem. Developers can quickly activate a free trial of StackHawk , integrating security testing workflows with CI/CD platforms like GitHub Actions or Azure DevOps.When graduating from the free tier, Microsoft customers can purchase StackHawk through the Azure Marketplace to reduce or completely eliminate procurement time. Information about how to integrate StackHawk scan results into Defender for Cloud can be found here .

“StackHawk’s integration with Microsoft Defender for Cloud extends the ability to assess the API security posture of an application beyond what’s happening in production,” said Joni Klippert, CEO and co-founder at StackHawk. “The StackHawk platform is designed to support teams in identifying and fixing API security vulnerabilities earlier in the development process while delivering secure code prior to production. This collaboration with Microsoft will enable customers to seamlessly pinpoint API security risks across their entire API ecosystem, strengthening their security posture.”

“Our collaboration with StackHawk builds upon Defender for Cloud’s current API security capabilities, providing our customers with a proactive approach to identifying vulnerabilities in APIs,” said Vlad Korsunksky, Vice President, Cloud & Enterprise Security at Microsoft. “Working together with StackHawk, we equip security teams with the knowledge, context and clarity needed to identify and mitigate API security risks across their entire lifecycle.”

For more information about how StackHawk integrates with Microsoft Defender for Cloud, please visit: https://www.stackhawk.com/partners/microsoft/

Additionally, customers can purchase StackHawk through the Microsoft Azure Marketplace .

About StackHawk StackHawk is making API and application security testing part of software delivery. The StackHawk platform empowers engineers to easily find and fix application security bugs at any stage of software development. With a strong founding team that has deep experience in security and DevOps, and some of the best venture investors in the business, StackHawk is putting application security testing into the hands of engineers. Learn more and sign up for a free trial at www.stackhawk.com .

Media Contact Sena McGrand Lumina Communications for StackHawk stackhawk@luminapr.com

More Hawksome Posts

Business Logic Vulnerability Testing: Why Your Scanner Can’t Find What It Doesn’t Understand

Business Logic Vulnerability Testing: Why Your Scanner Can’t Find What It Doesn’t Understand

Not all security flaws live in broken code. Some, like business logic vulnerabilities, hide in plain sight—within the workflows that make your app function. In 2019, millions of travelers’ data was exposed when a booking system treated a six-character code as full authentication. The system worked exactly as designed, and that was the problem. As APIs power more of the world’s digital experiences, protecting against these logic-based flaws requires context, creativity, and collaboration—because scanners can’t secure what they don’t understand.

Understanding LLM Security Risks: OWASP Top 10 for LLMs (2025)

Understanding LLM Security Risks: OWASP Top 10 for LLMs (2025)

As LLMs like ChatGPT moved from research to real-world applications, traditional security frameworks fell behind. OWASP’s Top 10 for LLM Applications highlights new risks—from prompt injection to model poisoning and system prompt leakage—that come with AI-driven systems. Understanding these threats is key to securing the next generation of applications. StackHawk helps teams find and fix vulnerabilities early, including those in AI-powered apps.

Top Security Testing Strategies for Software Development

Top Security Testing Strategies for Software Development

Security testing is a critical step in modern software development, ensuring applications stay resilient against evolving cyber threats. By identifying vulnerabilities early in the SDLC, teams can prevent breaches, protect data, and maintain user trust. This article explores key security testing types, benefits, challenges, best practices, and essential tools to help you strengthen your application’s defense—from code to runtime.