Skip to main content

NowSecure Workstation

Application Security

The NowSecure Workstation connector ingests NowSecure Workstation assessment reports. Workstation performs automated mobile application security testing (MAST) — combining static (SAST), dynamic (DAST), interactive (IAST), and API security testing on real physical devices — and exports its results as XML report files. The connector reads these report files from a configured reports folder and imports the assessed application, each failed control as a finding, and the reusable control definitions behind those findings.

This is a file-based integration: no network connection or authentication is required. Report files are picked up from the reports folder, processed, and optionally renamed after processing.

Each report produces three models:

  • Application — the assessed mobile app, with its name, version, and the test device's operating system.
  • DynamicCodeFinding — one finding for every failed control on that app, carrying the target application, device and OS context, evidence details, and the time the control was last found.
  • DynamicCodeFindingDefinition — the reusable control behind each finding (for example "Certificate Validation Test"), with its description, developer remediation, severity, CVSS score, CWEs, and regulatory-framework references.

Data retrieved from NowSecure Workstation​

Connector ObjectRequiredMaps to Data Model
ApplicationYesApplication
DynamicCodeFindingYesDynamic Code Finding
DynamicCodeFindingDefinitionYesDynamic Code Finding Definition

Model relationships​

note

For detailed steps on how to view the data retrieved from NowSecure Workstation in the Brinqa Platform, see How to view your data.