DerScanner Logo

DerScanner

0
Commercial
Visit Website

DerScanner is an application security testing platform that combines multiple security testing methodologies in a single solution. The platform integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Mobile Application Security Testing (MAST), Software Composition Analysis (SCA), and Binary Analysis capabilities. The tool supports 43 programming languages, including both modern and legacy codebases, making it suitable for organizations with diverse technology stacks. DerScanner can be deployed on-premises for organizations with strict data privacy requirements or accessed as a cloud service. Key features include: - SAST for detecting vulnerabilities in custom code during development - SCA for identifying security issues in dependencies and supply chain - DAST for testing live web applications from an attacker's perspective - MAST for securing mobile applications from code to deployment - Binary Analysis for securing legacy applications - Integration with CI/CD pipelines and development tools - Compliance reporting for standards like CWE/SANS Top 25, OWASP Top 10, OWASP MASVS, PCI DSS, and HIPAA DerScanner is designed to help development and security teams identify and remediate vulnerabilities throughout the application development lifecycle. The platform has been recognized by Forrester as a notable vendor in both SAST and SCA categories and is CWE-compatibility certified.

FEATURES

ALTERNATIVES

Open Redirection Analyzer

A device security analysis platform that provides comprehensive vulnerability scanning, SBOM management, and supply chain security monitoring for connected devices and their components.

Statistical renaming, Type inference, and Deobfuscation tool for JavaScript code.

An Application Security Posture Management platform that provides visibility, security controls, and automated workflows across the software development lifecycle from code to cloud.

A DAST solution that performs automated security testing of APIs and web applications within development workflows and CI/CD pipelines.

A free book providing design and implementation guidelines for writing secure programs in various languages.

Automated framework for monitoring and tampering system API calls of native macOS, iOS, and Android apps.

cwe_checker is a suite of checks to detect common bug classes in ELF binaries using Ghidra for firmware analysis.