Set test execution options

Configure XBOW to run penetration testing successfully without causing server problems.

  • Enterprise users: Execution options are shown on the “Target configuration” page.
  • Lightspeed users: Execution options are shown on the “Configuration check” page.

Important: You cannot change the execution settings after an assessment starts.

Configure test windows

By default, XBOW tests your asset at any time to return results as soon as possible. To better meet your company’s needs, you can instead configure an allowed testing window.

  1. In the “Allowed window” area, click one of the following options:

    • Business hours: XBOW can only test your asset Monday through Friday from 9 AM to 5 PM in your time zone. By limiting testing to business hours, you can actively monitor test traffic and respond quickly to any issues.
    • Off-hours: XBOW can only test your asset outside of business hours, ensuring minimal impact on production systems with active users during the workday.
    • Custom: Build a flexible testing schedule to meet your specific needs. For example, you can restrict testing to periods when your asset tends to have lower traffic.
  2. From the Timezone dropdown, select the time zone where your server is located.

  3. If you are creating a custom test window, click and drag inside the scheduler to build your schedule.

When you restrict testing to a window, the assessment pauses outside that window and resumes automatically when the next window opens. For more information, see Approved hours in “Troubleshooting assessments”.

Set request rate limits

Configure the maximum number of requests per second (RPS) that XBOW sends to your application.

Use the slider in the “Rate limit” field to set an appropriate value. For guidance on choosing a starting rate, see Choosing an appropriate starting rate.

Best practice: Start with a conservative rate limit to avoid overloading your application and pausing your assessment. Have your operations team monitor application performance, then adjust the rate limit as needed for future assessments.

Set parallel or sequential testing mode

By default, XBOW runs multiple test agents concurrently. Each agent logs in to your application using the same test account.

If your server supports concurrent sessions for the test account, parallel testing allows XBOW to complete assessments faster. However, if your server does not support concurrent sessions, the assessment may fail.

If your application does not support concurrent sessions for the same user, enable Sequential mode to run one test agent at a time.

Next steps

Was this helpful?