DAST scanner

Last updated: Apr 24, 2026


General configuration file keys

Here is an overview of the general configuration file keys. Remember that this applies to all of Fluid Attacks' scanners.

namespace: myapp
output:
  file_path: ./Fluid-Attacks-Results.csv
  format: CSV
working_dir: .
language: EN

Specific configuration file keys

The following keys are available only for the DAST scanner, nested under the dast key:

urls

A list of URLs to analyze. Each entry requires a url field and accepts an optional environment_id field:

dast:
  urls:
    - url: https://my-app.com
    - url: http://localhost
      environment_id: my-environment

Configuration file example

Below is an example of a highly personalized configuration file:

namespace: my_app
working_dir: ./
commit: e59607b9de3ef4c13d292705fg3da1ff0c67eb38
language: EN
output:
  file_path: /fluid-attacks-results.csv
  format: CSV
checks:
  - F043
strict: true
dast:
  urls:
    - url: https://www.my_app.com

On this page