HCL AppScan
{{Short description|Web security testing and monitoring tools}}
{{Infobox software
| name = HCL AppScan
| title = HCL AppScan
| logo =
| screenshot =
| caption =
| collapsible =
| author =
| developer = HCLSoftware, a division of HCLTech
| released =
| discontinued =
| latest release version = Version 10.0
| latest release date =
| latest preview version =
| latest preview date =
| programming language =
| operating system =
| platform =
| size =
| language =
| genre = Security testing
| license = Proprietary
| website = {{URL|https://www.hcl-software.com/appscan}}
}}
HCL AppScan (previously known as IBM AppScan) is a family of desktop and web security testing and monitoring tools, formerly a part of the Rational Software division of IBM. In July 2019, the product was acquired by HCLTech{{Cite web|url=https://www.zdnet.com/article/hcl-now-fully-controls-ibm-software-including-notes-and-domino/|title=HCL now fully controls IBM software including Notes and Domino|last=Kwan|first=Campbell|website=ZDNet|language=en|access-date=2019-09-16}} and is currently marketed under HCLSoftware, a product development division of HCLTech.
History
AppScan was originally developed by Israeli software company Sanctum Ltd. (formerly Perfecto Technologies) and was first released in 1998. A year later, Sanctum expanded its web security service and launched an Application firewall, called AppShield.{{cite news|title=New tool blocks wily e-comm hacker tricks|url=http://www.cnn.com/TECH/computing/9909/07/ecomm.hack.idg/index.html|author=Ellen Messmer|date=7 September 1999|accessdate=17 November 2010|publisher=CNN}} The first version of AppShield was developed by a team led by Gili Raanan, and was running on a dedicated Linux server.
AppScan version 2.0 was released in February 2001, adding a policy recognition engine and knowledge database, an automatic and customizable crawler engine, and an attack simulator.{{cite news|last=Mimoso|first=Michael S.|title=AppScan release secures Web applications|url=http://searchsecurity.techtarget.com/news/520223/Quick-Takes-AppScan-release-secures-Web-applications|newspaper=SearchSecurity|date=6 February 2001}} Version 3 was released in April 2002, adding collaborative testing capabilities, where different tasks can be assigned to different testers; and a number of user interface enhancements in both the scanning and reporting sections of the program.{{cite news|last=Costello|first=Sam|title=Sanctum boosts tests, reports in AppScan 3.0|url=http://www.computerworld.com.au/article/23334/sanctum_boosts_tests_reports_appscan_3_0/|newspaper=Computerworld|date=30 April 2002}} By 2003 AppScan was used by over 500 enterprise customers and had nearly $30 Million (USD) in annual revenue.{{cite news|title=Sanctum acquired by Watchfire|url=http://www.ivc-online.com/ivcWeeklyItem.asp?articleID=2015|newspaper=Israel Venture Capital Research Center|date=26 July 2004|url-status=dead|archiveurl=https://archive.today/20070810083415/http://www.ivc-online.com/ivcWeeklyItem.asp?articleID=2015|archivedate=10 August 2007}}
In July 2004, Sanctum was acquired by Massachusetts based company Watchfire, which developed a web applications management platform named WebXM. AppScan became Watchfire's flagship product and Sanctum's R&D center in Herzliya, Israel, became Watchfire's main R&D location.
In June 2007, Watchfire was acquired by IBM and incorporated into the Rational Software product line, enabling IBM to cover more of the application development lifecycle with the addition of a new tool to help developers further bolster the security of the application itself.{{cite news|last=Ogren|first=Eric|title=AppScan lives on with IBM|url=http://blogs.computerworld.com/node/5652|newspaper=Computerworld|date=8 June 2007|url-status=dead|archiveurl=https://web.archive.org/web/20110131081131/http://blogs.computerworld.com/node/5652|archivedate=31 January 2011}} Watchfire R&D center was incorporated into IBM R&D Labs in Israel.{{cite news|title=Watchfire Israel goes to IBM|url=http://www.globes.co.il/serveen/globes/docview.asp?did=1000219398|newspaper=Globes|date=7 June 2007}}
In 2009 IBM acquired Ounce Labs and added yet another tool to AppScan to find and correct vulnerabilities in software source code. This new version was quickly re-packaged as a separate edition of AppScan: AppScan Source Edition.{{cite news|last=Rick|first=Whiting|title=IBM: Design Security Into New Applications During Development|url=http://www.crn.com/news/security/225500021/ibm-design-security-into-new-applications-during-development.htm;jsessionid=sAdQrMEqh7kWNepNsBEm-w**.ecappj02|newspaper=CRN|date=8 June 2010}}
In June 2019, HCL acquired select IBM collaboration, commerce, digital experience, AppScan and BigFix solutions.[https://www.ibm.com/supply-chain/hcl-divestiture HCL Technologies to acquire select IBM software products][https://www.hcltech.com/press-releases/products-and-platforms/hcl-technologies-acquire-select-ibm-software-products-18b HCL Technologies to Acquire Select IBM Software Products for $1.8B]