Validating Browser Sessions
Post creation of browser sessions validate them to ensure successful scans
Browser session validation checks that a recorded session works before security scans. It verifies authentication, that actions can be replayed, and that the site behaves as expected.
Validation States
Sessions have three states:
Pending Validation (Yellow) - Not yet validated. New sessions start here.
Validated (Green) - All checks passed. Ready for scans.
Validation Failed (Red) - At least one check failed. Fix issues before using.
Validation Checks

1. Authenticated Check
Checks if the session authenticates correctly when loaded.
Loads the session (cookies, storage)
Visits the authentication URL
Compares the result to the expected authenticated page
Passed: Shows authenticated content (dashboard, profile, etc.)
Failed: Shows login page or error (session expired/invalid)
2. Unauthenticated Check
Checks if the site shows the login page when no session is present.
Visits the same URL without session data
Compares to the expected unauthenticated page
Passed: Shows login page or "access denied"
Failed: Shows authenticated content (security issue)
3. Replay Test
Checks if the recorded browser actions can be replayed successfully.
Replays the recorded actions (clicks, typing, navigation)
Compares the final page to the expected authenticated state
Passed: Actions complete and result in authenticated state
Failed: Actions fail or don't reach authenticated state
4. Parallel Tab Testing
Checks if the application can handle 3 authenticated tabs open at the same time
Opens 3 tabs with authenticated session
Reloads all tabs simultaneously to simulate actions like refreshing the page/navigation
Passed: All tabs maintain the authenticated state after reloads
Failed: Any one of the tab does not maintain the authenticated state
How to Trigger Validation
Open the Browser Session Manager modal by clicking Import Browser Session while configuring an assessment for a domain.

Select an existing session from the dropdown. The session loads in preview mode
(Optional) Review or edit session details, context, tags, or browser actions.
Click "Validate Session" and wait 1-2 minutes (You can view the live process of validation on the VNC URL).

Review results when they appear. Green borders = passed, red borders = failed. Click the eye icon to view screenshots.
Please note: If any of the validations fail the scan that triggered might not be successful, please ensure all 3 checks pass before running an authenticated scan.
Last updated