All Scanners

Showing 31 results
security
Open source

Wazuh

An open-source security platform providing unified host-based intrusion detection, vulnerability assessment, compliance auditing, and threat detection across endpoints, servers, and cloud workloads.

Network Security Cloud Native
Popularity: 80%
security
Open source

Trivy

A comprehensive open-source security scanner for containers, filesystems, Git repositories, and Infrastructure as Code, detecting vulnerabilities, misconfigurations, and exposed secrets.

Cloud Native Compliance
Popularity: 88%
security
Open source

SonarQube

The most widely deployed platform for continuous code quality and security analysis, performing static analysis across 30+ languages to detect bugs, vulnerabilities, and code smells.

Web Security Compliance
Popularity: 92%
security
Commercial

Snyk

Developer security platform providing software composition analysis, static code analysis, container scanning, and IaC security testing integrated into the development workflow.

Web Security Cloud Native
Popularity: 90%
security
Open source

Semgrep

A fast, open-source static analysis tool that uses lightweight pattern matching to find bugs, security vulnerabilities, and anti-patterns across 30+ programming languages.

Web Security Cloud Native
Popularity: 82%
security
Open source

Prowler

An open-source cloud security assessment tool that performs automated auditing of AWS, Azure, GCP, and Kubernetes environments against hundreds of security best-practice checks.

Cloud Native Compliance
Popularity: 75%
security
Open source

MobSF

An automated, all-in-one mobile application security testing framework supporting static and dynamic analysis of Android, iOS, and Windows mobile apps.

Mobile Web Security
Popularity: 72%
security
Open source

Checkov

A static analysis tool for Infrastructure as Code that scans Terraform, CloudFormation, Kubernetes, Helm, ARM, and Serverless configurations for security misconfigurations and compliance violations.

Cloud Native Compliance
Popularity: 70%
security
Commercial

Nexpose

Rapid7's on-premise vulnerability management scanner with Active Risk scoring, continuous asset discovery, and compliance benchmarking across network infrastructure and endpoints.

Network Security Compliance
Popularity: 72%
security
Open source

Metasploit

The world's most widely used penetration testing framework, providing a modular library of 2,600+ exploits, 2,100+ payloads, and 1,300+ auxiliary tools for the full attack lifecycle.

Network Security Web Security
Popularity: 95%
security
Commercial

Invicti (Netsparker)

Enterprise-grade DAST platform using proof-based scanning to automatically confirm exploitable vulnerabilities in web applications and APIs with near-zero false positives.

Web Security Compliance
Popularity: 72%
security
Commercial

GFI LanGuard

Commercial network security scanner and patch management platform that audits, identifies, and remediates vulnerabilities across Windows, macOS, and Linux endpoints.

Network Security Compliance
Popularity: 50%
security
Open source

Angry IP Scanner

Fast, cross-platform IP address and port scanner with a simple GUI, supporting multithreaded scanning, NetBIOS resolution, and multi-format export across Windows, macOS, and Linux.

Network Security Reconnaissance
Popularity: 65%
security
Open source

Aircrack-ng

The de facto standard open-source suite for 802.11 wireless network security auditing, covering packet capture, traffic analysis, injection, and WEP/WPA/WPA2 key recovery.

Network Security Reconnaissance
Popularity: 82%
security
Commercial

Acunetix

Commercial DAST/IAST web application security scanner with proof-based scanning, DeepScan JavaScript rendering, and optional grey-box AcuSensor agent for code-level precision.

Web Security Compliance
Popularity: 78%
security
Open source

ZMap

Stateless single-packet network scanner engineered for Internet-wide surveys, capable of scanning the entire IPv4 space on a single port in under 45 minutes.

Network Security Reconnaissance
Popularity: 65%
security
Open source

ZGrab2

Modular application-layer network scanner that performs deep protocol handshakes and banner grabbing across 33+ protocols, outputting structured JSON transcripts at Internet scale.

Network Security Reconnaissance
Popularity: 40%
security
Open source

WPScan

The de facto WordPress security scanner, enumerating plugins, themes, and core versions against a curated database of 71,900+ known WordPress vulnerabilities.

Web Security Reconnaissance
Popularity: 70%
security
Commercial

Qualys

Cloud-native enterprise security platform delivering continuous vulnerability management, web application scanning, and compliance auditing across IT assets and cloud workloads.

Network Security Web Security
Popularity: 88%
security
Open source

OWASP Amass

Attack surface intelligence framework performing network mapping and external asset discovery using OSINT gathering and active reconnaissance across 50+ data sources.

Reconnaissance Network Security
Popularity: 75%
security
Open source

Nuclei

A fast, template-driven vulnerability scanner with 12,000+ community-maintained detection templates covering CVEs, misconfigurations, and exposures across web, network, and cloud.

Web Security Network Security
Popularity: 85%
security
Open source

Naabu

A fast, lightweight port scanner built for attack surface discovery with SYN, CONNECT, and UDP scanning plus native Nmap and ProjectDiscovery toolchain integration.

Network Security Reconnaissance
Popularity: 45%
security
Open source

Masscan

Internet-scale TCP port scanner capable of transmitting 10 million packets per second, scanning the entire IPv4 address space in under five minutes.

Network Security Reconnaissance
Popularity: 75%
security
Open source

sqlmap

The definitive open-source SQL injection detection and exploitation tool, supporting 30+ database management systems and six injection techniques.

Web Security
Popularity: 75%
security
Open source

Nmap

The industry-standard network mapper for host discovery, port scanning, OS detection, and security auditing across networks of any scale.

Network Security Reconnaissance
Popularity: 95%
security
Open source

Nikto

Open-source web server scanner that checks for dangerous files, outdated software, and misconfigurations across 6,700+ known vulnerability signatures.

Web Security Reconnaissance
Popularity: 55%
security
Commercial

Caido

A modern web application security proxy built in Rust, designed for penetration testers and bug bounty hunters as a fast alternative to legacy Java-based tools.

Web Security
Popularity: 35%
security
Commercial

Nessus

The industry standard for vulnerability assessment, providing deep scanning capabilities for IT assets and compliance.

Network Security Compliance
Popularity: 85%
security
Open source

OpenVAS

A full-featured vulnerability scanner with a large community and comprehensive vulnerability tests updated daily.

Network Security
Popularity: 60%
security
Commercial

Burp Suite

Professional tools for web application security testing, from scanning for vulnerabilities to exploiting them.

Web Security Reconnaissance
Popularity: 90%
security
Open source

OWASP ZAP

The world's most widely used web app scanner. Free and open source for both automation and manual testing.

Web Security Reconnaissance
Popularity: 80%