> For the complete documentation index, see [llms.txt](https://docs.opsmx.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.opsmx.com/code-to-cloud-security-and-scanners/dynamic-testing-and-api-security/dast/how-to-do-a-dast-scan.md).

# How to do a DAST Scan

The Dynamic Application Security Testing (DAST) scan emphasis scanning of essential details such as the service URL and related configuration parameters that is collected from the ZAP integrator.&#x20;

This page explains the process of integrating ZAP with SSD and perform the  Adhoc DAST scan.&#x20;

* Before starting with the scan, you need to integrate ZAP with the OpsMx platform. Follow the steps provided in [Integrating ZAP](https://docs.opsmx.com/opsmx-delivery-shield-platform/getting-started/integrating-security-scanning-tools-in-delivery-shield/zap) to complete the process.
* If ZAP data needs to be mapped to a specific team, you need to create the team first. If no team-level segregation is required, skip this step. Follow the steps provided in [Managing Teams](https://docs.opsmx.com/opsmx-delivery-shield-platform/user-guide/manage-teams-and-access) to complete the process.&#x20;

### To Access Dast Scan

* Click on **Scan Now** button at the top right corner of the screen.

<figure><img src="https://docs.opsmx.com/~gitbook/image?url=https%3A%2F%2F2047464521-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252F-MBEa1hoX6SqpDj-ymNs%252Fuploads%252FrJIKrYmqJVFzsym10w2D%252Fscan%2520now%2520.png%3Falt%3Dmedia%26token%3D56c19f36-9c4c-4212-80d3-43a1d9853d03&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=4d2e53fd&#x26;sv=2" alt=""><figcaption></figcaption></figure>

* In the screen that appears, select **Dast Scan** from the left panel.

<figure><img src="/files/GVHmVAZN2DRF0TcJG1x5" alt=""><figcaption></figcaption></figure>

Now you can **Add Project, Upload Project** or **Sync Project** to proceed with the scan.

### To Add a Project&#x20;

* To add or update a new project with artifact scan configurations, click **Add Project**.&#x20;
* The **Create Project** details page is displayed as shown below. Enter the details for the following fields:

<figure><img src="/files/MMOl59iiGlejoftNRo7k" alt=""><figcaption></figcaption></figure>

* **Name** : Enter a name for the project.&#x20;
* **Team** : Select the team for which you want to create the project.&#x20;
* **Scan Type** : The default type is Dast Scan.&#x20;
* **Platform** : Select the platform type, ZAP.
* **Scan Type** : The default scan type is Dast Scan.&#x20;
* **Account** : Choose the needed account that has been integrated for the selected platform. If no account is available for the selected platform then click **Add Account**.
  * The integration page is displayed. You can add a new account.&#x20;
* **Service URL :** Enter the URL link for which the scan needs to be done.&#x20;
* **Scan Level** : Select the scan level; either Web level or App level for which the scan needs to be applied.&#x20;
* **Schedule Scan** : You can set the scan schedule as to minutes or hours or days.
* Click Save.&#x20;

The project gets added for scanning.

### Saving Configuration &#x20;

* After adding the configuration details you can click the **Save Configuration** option to save the adding details and trigger the scan at a later period. &#x20;

<figure><img src="/files/1moJLFD7MqMCnmRnq0Vc" alt=""><figcaption></figcaption></figure>

* The added project displays in the list with a **Paused** scan status.

<figure><img src="/files/rnMvKubS6dHkFmiMJ7LY" alt=""><figcaption></figcaption></figure>

* When you want to scan the saved project you can click the Trigger Scan option to initiate the scan.

<figure><img src="/files/E2HRL0ZURKTZz3vilGVf" alt=""><figcaption></figcaption></figure>

### &#x20;To Upload a Project

1. To upload a project from your local, click **Upload Project**.

<figure><img src="/files/voCdjygwZZe2rRhJY0WB" alt=""><figcaption></figcaption></figure>

2. Click **Upload File** and select the project you want to add for scanning. &#x20;

<figure><img src="/files/t7rLh9NnvsL1pycjVtZA" alt=""><figcaption></figcaption></figure>

3. Click **Save**.&#x20;

The file gets added for scanning.&#x20;

### To Integrate JIRA at Project Level

JIRA can be integrated at project level to create tickets whenever an alert is identified.&#x20;

* To integrate JIRA, click the Integrations icon on expanding the project.&#x20;

<figure><img src="/files/D87SrN8JKJlZ7rfSXbON" alt=""><figcaption></figcaption></figure>

* The JIRA integration page is displayed. Click **Add Account** and enter the details.&#x20;

<figure><img src="/files/zfsM6BarJXhWpjlfjjR2" alt=""><figcaption></figcaption></figure>

* Enter the values for the following fields:
  * **Account Name -** Enter the JIRA account name.&#x20;
  * **Jira Project Key -** Enter the name of your Jira project.&#x20;
  * **Jira** **URL -** Enter your Jira host Url&#x20;
  * **Jira Email Id -** Enter the username to access Jira.&#x20;
  * **Token -** Enter the password / token for the Jira account.&#x20;
  * Enable **Automatically create Jira tickets during the scan** to create JIRA ticket to the team owner when the alerts are identified.&#x20;
  * **Trigger Type** - Indicates at which level Jira tickets should be created.&#x20;
    * **Create Jira ticket at the Component Alert level** - Jira tickets will be created for each individual impacted component.&#x20;
    * **Create Jira ticket at the Deduplication Alert level** -  A single Jira ticket will be created for all the impacted components.&#x20;
    * **Creation Scope** - If Vulnerabilities is selected, Jira is created only for Critical and High alerts. If All Policies is selected Jira is created for all alerts.&#x20;
  * Enable **Assign the Jira ticket to the Team owner** if you want to assign the ticket to the team owner.&#x20;
  * **Fields -** Enter the labels that need to be added in the created Jira ticket.&#x20;
  * **Values -** Enter the values that need to be given in the Jira ticket. The given variables are replaced with actual values when the tickets are created.&#x20;
  * **Status Keyword Mapping** - You can set the keywords for the status.&#x20;
* Click **Test** to check if the entered values are valid.
* Once validated, click **Save**. The tool is connected.

### To View AI-Based Remediation Details

AI Remediation is integrated in the Scan Now option.&#x20;

1. Expand the project for which you want to view the remediation details.&#x20;
2. Click **Open Issues** to view the list of alerts.&#x20;

<figure><img src="/files/81Yfo5MHt22pqUQHq4oq" alt=""><figcaption></figcaption></figure>

3. From the alerts list, select the required alert.

<figure><img src="/files/CfxUuwD4p6lXBvtZD6Ze" alt=""><figcaption></figcaption></figure>

4. Navigate to the **Impacted Components** section and click on it.
5. In the list of applications, identify the relevant application and click **Remediate**.

<figure><img src="/files/WBeNueu8GkfIXl93QYVa" alt=""><figcaption></figcaption></figure>

The AI Remediation window is displayed. It analyzes the selected alert and provides a detailed summary of the issue, recommended remediation steps and possible workarounds.&#x20;

<figure><img src="/files/4CuuUFztzaA7F711TXEv" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
AI Remediation is supported only for repositories hosted on GitHub Cloud. Remediation is performed only when the source details of the associated artifacts or projects are available.
{% endhint %}

### To Sync Project

### To View and Interpret Scan Results <a href="#to-view-and-interpret-scan-results" id="to-view-and-interpret-scan-results"></a>

Once the scan is complete, a confirmation message is updated within the project and OpsMx generates the overall results. They are displayed as shown below:

* Repos Registered
* Total Artifact Tags
* Total Scans
* Total Projects
* Auto Scan Enabled Repos

<figure><img src="/files/jUa6PK4RtiDcajcWhdNh" alt=""><figcaption></figcaption></figure>

The panel at the bottom displays the project details. On expanding each project you can view the complete details of it.

{% hint style="info" %}
The current status of the scan (completed, pending or failed) is displayed to notify the status of the project.&#x20;
{% endhint %}

* To edit the configuration details of the project, click the **Edit** button.&#x20;

<figure><img src="/files/YNpbdDykJzxm72UynK4I" alt=""><figcaption></figcaption></figure>

* Click the **View** option in the **Action** button, to view the SAST and SCA scan results of the project.&#x20;

<figure><img src="/files/1OUjvi39nvR0WeSyq76p" alt=""><figcaption></figcaption></figure>

* The results page displays the complete data of the scan details.&#x20;
  * On clicking the **Download** button, the scan results are downloaded in .json or .csv format.
  * On clicking Report, the scan results are downloaded in a report format.&#x20;
  * On clicking Go to Artifact Page, you are redirected to the related artifact page.&#x20;

<figure><img src="/files/52ClscU4mfPJ9hu4byTO" alt=""><figcaption></figcaption></figure>

### Quick Actions

Each project displays 5 quick action buttons as shown:

<figure><img src="/files/69TarDn8T8llapok7H5Y" alt=""><figcaption></figcaption></figure>

1. **Trigger Scan** – Initiates a new scan for the project or runs a scan using a previously saved configuration.
2. **Integrations** – Opens the project's **Integrations** page, where all available integrations for the project are listed.
3. **Policies** – Displays the list of policies that have been configured for the project.
4. **Edit Project** – Opens the project configuration settings, allowing you to modify the project's details and scan settings.
5. **Delete** – Removes the project from the system.
