DerScanner is an application security testing platform that combines multiple security testing methodologies in a single solution. The platform integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Mobile Application Security Testing (MAST), Software Composition Analysis (SCA), and Binary Analysis capabilities. The tool supports 43 programming languages, including both modern and legacy codebases, making it suitable for organizations with diverse technology stacks. DerScanner can be deployed on-premises for organizations with strict data privacy requirements or accessed as a cloud service. Key features include: - SAST for detecting vulnerabilities in custom code during development - SCA for identifying security issues in dependencies and supply chain - DAST for testing live web applications from an attacker's perspective - MAST for securing mobile applications from code to deployment - Binary Analysis for securing legacy applications - Integration with CI/CD pipelines and development tools - Compliance reporting for standards like CWE/SANS Top 25, OWASP Top 10, OWASP MASVS, PCI DSS, and HIPAA DerScanner is designed to help development and security teams identify and remediate vulnerabilities throughout the application development lifecycle. The platform has been recognized by Forrester as a notable vendor in both SAST and SCA categories and is CWE-compatibility certified.
FEATURES
ALTERNATIVES
A web application security testing platform that helps you test your knowledge on web application security through realistic scenarios with known vulnerabilities.
Reformat and re-indent bookmarklets, ugly JavaScript, and unpack scripts with options available via UI.
A security feature to prevent unexpected manipulation of fetched resources.
DECAF++ is a fast whole-system dynamic taint analysis framework with improved performance and elasticity.
Emulates browser functionality to detect exploits targeting browser vulnerabilities.
A tool for building and installing PhoneyC with optional Python version configuration and root privileges.
SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.
An integrated security platform that provides API discovery, runtime protection, security testing, and incident response capabilities for web applications, APIs, and AI systems.
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

PTJunior
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

OSINTLeak
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.