DerScanner is an application security testing platform that combines multiple security testing methodologies in a single solution. The platform integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Mobile Application Security Testing (MAST), Software Composition Analysis (SCA), and Binary Analysis capabilities. The tool supports 43 programming languages, including both modern and legacy codebases, making it suitable for organizations with diverse technology stacks. DerScanner can be deployed on-premises for organizations with strict data privacy requirements or accessed as a cloud service. Key features include: - SAST for detecting vulnerabilities in custom code during development - SCA for identifying security issues in dependencies and supply chain - DAST for testing live web applications from an attacker's perspective - MAST for securing mobile applications from code to deployment - Binary Analysis for securing legacy applications - Integration with CI/CD pipelines and development tools - Compliance reporting for standards like CWE/SANS Top 25, OWASP Top 10, OWASP MASVS, PCI DSS, and HIPAA DerScanner is designed to help development and security teams identify and remediate vulnerabilities throughout the application development lifecycle. The platform has been recognized by Forrester as a notable vendor in both SAST and SCA categories and is CWE-compatibility certified.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A static analysis tool for Android apps that detects malware and other malicious code
Emulates browser functionality to detect exploits targeting browser vulnerabilities.
An application security platform that combines SCA, SAST, container security, dependency management, and AI model risk analysis with integrated workflows for development and security teams.
Static code analysis tool for infrastructure as code (IaC) and software composition analysis (SCA) with over 1000 built-in policies for AWS, Azure, and Google Cloud.
A tool for detecting capabilities in executable files, providing insights into a program's behavior and potential malicious activities.
A free book providing design and implementation guidelines for writing secure programs in various languages.
An integrated application security platform that combines multiple security scanning tools with developer-focused workflows for automated code and infrastructure security testing.
A self-managed static code analysis platform that conducts continuous inspection of codebases to identify security vulnerabilities, bugs, and code quality issues.
Pint is a PIN tool that exposes the PIN API to lua scripts, allowing dynamic instrumentation of binaries.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.