OWASP coverage
OWASP Top 10 testing that runs as often as you ship.
AI agents test your app for the OWASP Top 10 and API Security Top 10 the way an attacker would, continuously or on demand. Reports map to OWASP WSTG. Passive monitoring covers the configuration categories between runs.
Tested by the AI pentest
The exploit classes need real testing.
Findings are checked against the live app before they're reported. From Standard up a security engineer reviews them, and retests of found issues are free.
A01:2021
Broken access control
The AI pentest tests for IDOR and privilege escalation, for example one user reading another tenant's orders by changing an ID.
A03:2021
Injection
SQL injection, command injection, and reflected or stored XSS. Confirmed findings come with the request and response.
A07:2021
Identification & authentication failures
Session handling, login flows and token weaknesses, tested behind login with the credentials you provide.
A10:2021
Server-side request forgery
Checks whether your app can be made to fetch internal or cloud metadata URLs on an attacker's behalf.
Watched by passive monitoring
The configuration categories, between pentests.
A02:2021
Cryptographic failures
TLS version, cipher suites, certificate chain, HSTS and mixed content, watched for drift between deploys.
A05:2021
Security misconfiguration
Headers, cookie flags, framework leakage and server information disclosure.
A06:2021
Vulnerable & outdated components
Known-vulnerable JavaScript libraries on your live pages, with version-specific fixes.
What's not covered automatically
The categories that need people.
- ✓A04:2021 Insecure design, which needs threat modeling and design review
- ✓A08:2021 Software & data integrity failures, which needs supply-chain context
FAQ
OWASP coverage, answered.
What does OWASP Top 10 coverage actually mean?
The OWASP Top 10 (2021 edition, which the category ids on this page use) is a list of the most critical web application security risks, published by the Open Worldwide Application Security Project. Coverage means a tool actually tests for issues in each category. The exploit classes (A01 Broken Access Control, A03 Injection, A07 Identification and Authentication Failures, A10 SSRF) need a pentest that sends requests and checks the responses, which is what Barrion's AI pentest does. Passive monitoring covers the configuration categories (A02 Cryptographic Failures, A05 Security Misconfiguration, A06 Vulnerable Components) between pentests.
What about OWASP API Security Top 10?
The AI pentest tests API surfaces for broken object level authorization (API1), broken authentication (API2), broken object property level authorization (API3), unrestricted resource consumption (API4), broken function level authorization (API5), unrestricted access to sensitive business flows (API6), and server-side request forgery (API7). APIs are first-class targets in an AI pentest, not an afterthought.
How is this different from running OWASP ZAP myself?
ZAP is one of the tools the AI pentest's agents use, alongside sqlmap, nuclei and others, and we credit the project openly. The difference is what sits around it: specialist agents per test area, findings checked against the live app before they're reported, an OWASP WSTG coverage matrix in the report, and from Standard up a security engineer reviewing the findings. ZAP is a great tool to run yourself if you have the team to operate it.
Can the OWASP testing run continuously?
Yes, on the Business plan. A saved pentest reruns on a schedule or on demand, and each run labels earlier findings as new, still open, resolved or regressed. So if an injection fix gets undone in a later release, it comes back as a regression. On other plans you start single pentests on demand.
Which OWASP categories are NOT covered by Barrion?
Two categories need business-domain knowledge or human judgment that automated testing can't fully supply: A04:2021 Insecure Design (best caught by threat modeling and design review) and A08:2021 Software and Data Integrity Failures (which needs supply-chain context Barrion doesn't have). For these, pair Barrion with design review and your own supply-chain controls.
Test your app against the OWASP Top 10.
Start a single AI pentest today, or book a call about continuous testing.