Black Duck Logo

Black Duck

0
Commercial
Visit Website

Black Duck is an application security platform focused on software supply chain security and software composition analysis (SCA). The platform helps organizations identify and manage risks in their software by providing comprehensive Software Bill of Materials (SBOM) management capabilities. Black Duck enables teams to scan applications for open source components, detect vulnerabilities, and ensure license compliance throughout the software development lifecycle. The solution integrates into CI/CD pipelines to automate security testing without impeding development velocity. Key capabilities include: - Software composition analysis to identify open source components and their associated risks - Vulnerability detection and management across the application portfolio - License compliance monitoring to prevent intellectual property issues - SBOM generation and management to meet regulatory requirements - Integration with DevSecOps workflows and CI/CD pipelines - Risk prioritization based on organizational policies The platform is designed to support various roles within an organization, from developers who need to secure code as they write it to security teams who need to manage risk at scale. Black Duck helps organizations address security concerns related to AI-generated code and maintain compliance with industry standards.

FEATURES

ALTERNATIVES

A lightweight web security auditing toolkit that simplifies security tasks and enhances productivity.

An agentless API security platform that discovers, tests, and secures APIs through source code analysis without requiring traffic monitoring.

A comprehensive web application security testing solution that offers built-in vulnerability assessment and management, as well as integration options with popular software development tools.

A technology lookup and lead generation tool that identifies the technology stack of any website and provides features for market research, competitor analysis, and data enrichment.

Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.

WPRecon is a tool for recognizing vulnerabilities and blackbox information for WordPress.

A tool for detecting capabilities in executable files, providing insights into a program's behavior and potential malicious activities.

A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.

PINNED