Using a SoapUI Project with passing Functional TestCases. The Scans can only be applied to TestStep Requests.
- Set up Scans and Parameters to target fields of interest
- Inspect results and structure - note the warning of “Missing assertions”
- Consider business and security requirements
- Add scans to appropriate TestSteps
- Add Assertions to the Scans (Security Assertions use the same type of editor as Functional Assertions)
- Execute Security Test using the Security TestRunner Launcher with a designated reporting directory
- Review results. Provide actionable recommendations to team
capec.org Security Exploit Database
Exploratory testing repo with "naughty tokens" for security scanning Security Testing Techniques with SoapUI. (google doc)