|
9 | 9 | "type": "SAST" |
10 | 10 | }, |
11 | 11 | { |
| 12 | + "title": "CVE Scanner", |
| 13 | + "url": "https://www.cvescanner.co.uk", |
| 14 | + "owner": "CVE Scanner", |
| 15 | + "license": "Commercial", |
| 16 | + "platforms": "SaaS", |
| 17 | + "note": "Real-time scanning of your domain for known CVEs is free. If any are found, a detailed breakdown of the identified CVEs is available for just £10, which includes two free rescans. We use a live black-box HTTP probing approach.", |
| 18 | + "type": "DAST" |
| 19 | + }, |
| 20 | + { |
| 21 | + "title": "Astrée", |
| 22 | + "url": "https://www.absint.com/astree/index.htm", |
| 23 | + "owner": "AbsInt Angewandte Informatik GmbH", |
| 24 | + "license": "Commercial", |
| 25 | + "platforms": "Windows and Linux", |
| 26 | + "note": "Astrée is a static analyzer designed to prove the absence of runtime errors and further critical program defects, including code-level cybersecurity vulnerabilities like buffer overflows, data races, etc. It is based on abstract interpretation, a provably correct formal method. Astrée supports C and C++.", |
| 27 | + "type": "SAST" |
| 28 | + }, |
| 29 | + { |
| 30 | + "title": "Panoptic Scans", |
| 31 | + "url": "https://panopticscans.com", |
| 32 | + "owner": "Panoptic Scans", |
| 33 | + "license": "Commercial", |
| 34 | + "platforms": "SaaS", |
| 35 | + "note": "Panoptic Scans enables automated network and application scans using tools like OpenVAS, ZAP, and Nmap. Users can schedule scans to meet compliance requirements for SOC 2, HIPAA, ISO 27001, NIST 800-53, and CMMC while detecting issues such as unpatched software, vulnerabilities, misconfigurations, and open ports.", |
| 36 | + "type": "DAST" |
| 37 | + }, |
| 38 | + { |
12 | 39 | "title": "ZeroPath", |
13 | 40 | "url": "https://zeropath.com/", |
14 | 41 | "owner": "ZeroPath", |
15 | 42 | "license": "Commercial or Free", |
16 | 43 | "platforms": "SaaS, On-Premises", |
17 | | - "note": "Scans over 10 languages to identify and fix conventional technical vulnerabilities (e.g., XSS, SQL injection, SSRF) as well as business logic flaws and auth bugs.", |
| 44 | + "note": "ZeroPath is an AI Native SAST that scans over 15 languages to identify and fix conventional technical vulnerabilities (e.g., XSS, SQL injection, SSRF) as well as business logic flaws and auth bugs.", |
18 | 45 | "type": "SAST" |
19 | 46 | }, |
20 | 47 | { |
|
23 | 50 | "owner": "joernio", |
24 | 51 | "license": "Open Source or Free", |
25 | 52 | "platforms": null, |
26 | | - "note": "Scans C/C++/Java/Binary/Javascript/Python/Kotlin.", |
| 53 | + "note": "Scans C/C++/Java/Binary/Javascript/Python/Kotlin/JVM Bytecode/PHP/Go/Ruby/Swift/C#.", |
27 | 54 | "type": "SAST" |
28 | 55 | }, |
29 | 56 | { |
|
110 | 137 | { |
111 | 138 | "title": "ZeroThreat", |
112 | 139 | "url": "https://zerothreat.ai", |
113 | | - "owner": "ZeroThreat", |
114 | | - "license": "Free", |
115 | | - "platforms": "SaaS", |
116 | | - "note": "ZeroThreat is a fast web app and API security scanner providing DAST capabilities with modern solutions for modern web applications, and it is free to use.", |
| 140 | + "owner": "ZeroThreat INC", |
| 141 | + "license": "Commercial or Free", |
| 142 | + "platforms": "SaaS or On-Premise", |
| 143 | + "note": "ZeroThreat is an AI-powered modern DAST tool built for today’s web applications and APIs.", |
117 | 144 | "type": "DAST" |
118 | 145 | }, |
119 | 146 | { |
|
167 | 194 | "owner": "Escape", |
168 | 195 | "license": "Commercial", |
169 | 196 | "platforms": "SaaS", |
170 | | - "note": "Run thousands of GraphQL security scans", |
| 197 | + "note": "Escape is a modern DAST with a native business logic security testing algorithm. It supports modern web frameworks, integrates easily into CI/CD pipelines, and provides framework-specific, developer-friendly code snippets.", |
171 | 198 | "type": "DAST" |
172 | 199 | }, |
173 | 200 | { |
|
953 | 980 | "note": "20% off with OWASP20", |
954 | 981 | "type": "DAST" |
955 | 982 | }, |
| 983 | + { |
| 984 | + "title": "WuppieFuzz", |
| 985 | + "url": "https://github.com/TNO-S3/WuppieFuzz", |
| 986 | + "owner": "TNO", |
| 987 | + "license": "Open Source", |
| 988 | + "platforms": "Windows, Linux, Macintosh", |
| 989 | + "note": "WuppieFuzz is a coverage-guided REST API fuzzer developed on top of LibAFL, targeting a wide audience of end-users, with a strong focus on ease-of-use, explainability of the discovered flaws and modularity. WuppieFuzz supports all three settings of testing (black box, grey box and white box).", |
| 990 | + "type": "DAST" |
| 991 | + }, |
956 | 992 | { |
957 | 993 | "title": "Barrion", |
958 | 994 | "url": "https://barrion.io/", |
|
1388 | 1424 | { |
1389 | 1425 | "title": "DerScanner", |
1390 | 1426 | "url": "https://derscanner.com/", |
1391 | | - "owner": "DerScanner Ltd.", |
| 1427 | + "owner": "DerSecur Ltd.", |
1392 | 1428 | "license": "Commercial", |
1393 | | - "platforms": null, |
1394 | | - "note": "Capable of identifying vulnerabilities and backdoors (undocumented features) in over 30 programming languages by analyzing source code or executables, without requiring debug info.", |
| 1429 | + "platforms": "SaaS or On-Premises", |
| 1430 | + "note": "DerScanner is an AI-powered application security testing platform suitable for air-gapped environments. It combines SAST, DAST, IAST, MAST, SCA, and binary analysis into a unified solution, securing modern and legacy applications with support for 43 programming languages.", |
1395 | 1431 | "type": "SAST" |
1396 | 1432 | }, |
1397 | 1433 | { |
|
1857 | 1893 | "title": "AppSweep", |
1858 | 1894 | "url": "https://www.guardsquare.com/appsweep-mobile-application-security-testing", |
1859 | 1895 | "owner": "Guardsquare", |
1860 | | - "license": "Open Source or Free", |
| 1896 | + "license": "Commercial", |
1861 | 1897 | "platforms": "SaaS", |
1862 | | - "note": "Mobile application security testing tool for compiled Android apps with support of CI/CD integration", |
| 1898 | + "note": "Mobile application security testing tool for compiled Android and iOS apps with support of CI/CD integration", |
1863 | 1899 | "type": "SAST" |
1864 | 1900 | }, |
1865 | 1901 | { |
|
2132 | 2168 | "platforms": "SaaS", |
2133 | 2169 | "note": "ResilientX UEM provides an All-in-One Continuous Testing and Monitoring solution, by integrating ASM, DAST, CSPM", |
2134 | 2170 | "type": "DAST" |
| 2171 | + }, |
| 2172 | + { |
| 2173 | + "title": "Agentic Radar", |
| 2174 | + "url": "https://github.com/splx-ai/agentic-radar", |
| 2175 | + "owner": "SplxAI", |
| 2176 | + "license": "Free", |
| 2177 | + "platforms": "Windows, Linux, MacOS", |
| 2178 | + "note": "Open-source CLI security scanner for agentic AI workflows. Scans your workflow’s source code, detects vulnerabilities, and generates an interactive visualization along with a detailed security report. Supports popular agentic frameworks like LangGraph, CrewAI, n8n, OpenAI Agents, and more.", |
| 2179 | + "type": "SAST" |
| 2180 | + }, |
| 2181 | + { |
| 2182 | + "title": "Kusari Inspector", |
| 2183 | + "url": "https://kusari.dev", |
| 2184 | + "owner": "Kusari", |
| 2185 | + "license": "Commercial or Free", |
| 2186 | + "platforms": "SaaS", |
| 2187 | + "note": "Kusari Inspector seamlessly integrates software supply chain security analysis into your pull requests.", |
| 2188 | + "type": "SAST" |
2135 | 2189 | } |
2136 | 2190 | ] |
0 commit comments