Stackhawk Adds Business Logic Testing (BLT) to its AppSec Platform Menu
New testing capability addresses authorization flaws responsible for 34% of security breaches, automating what used to require manual penetration testing.
Business logic flaws, such as broken object level authorization (BOLA) and broken function level authorization (BFLA), are top application security concerns that Stackhawk's new BLT solution directly addresses. Identifying these flaws requires testing running applications with multiple users simultaneously—functionality that SAST and legacy DAST tools fundamentally lack. Manual penetration testing has been the only option for AppSec teams, consuming valuable budget and internal team time that doesn't scale with modern development velocity.
Key Features of StackHawk Business Logic Testing:
- Multi-User Role Testing: Allows detection of BOLA and BFLA vulnerabilities by configuring multiple user profiles to evaluate both horizontal authorization (User A accessing User B's data) and vertical authorization (regular users performing admin functions).
- Context-Aware Test Orchestration: Automatically generates intelligent test sequences from OpenAPI specifications, coordinating requests across user profiles to test whether authorization boundaries hold—no manual configuration of test flows required. StackHawk understands how your APIs relate: what order endpoints should be called, what data from one response feeds into the next request, and how to generate contextually appropriate test data.
- Transparent Test Sequences: Visualized test sequence evidence in the StackHawk platform provides a comprehensive view of which roles were exercised, which parameters were extracted and injected, and the exact chain of steps leading to each discovered business logic flaw.
"Authorization testing has been notoriously difficult to automate because it requires orchestrating multiple user sessions and understanding complex API relationships," said
StackHawk was recently named the outstanding API security platform by the Global Infosec Awards at RSA 2025. These prestigious global awards, by Cyber Defense Magazine, recognize innovators with compelling value propositions for their products in competitive infosecurity industries.
About StackHawk
StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.
Media Contact
Founder of 10KMedia
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/stackhawk-adds-business-logic-testing-blt-to-its-appsec-platform-menu-302640202.html
SOURCE StackHawk
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Kreyco Calls for Independent Investigation into NYC Department of Education Contracting, Oversight, Student Protection, and Accountability Practices
- Silvercorp Announces Filing of Updated Technical Reports
- Hanwha Power Marks U.S. Market with Successful Commissioning of Trumbull Energy Center CCGT
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share