License & Deployment Mix: 29 tools – 13 OSS, 10 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)

What Is Vulnerability Management?

Vulnerability Management (VM) is the continuous process of identifying, classifying, prioritizing, remediating, and mitigating security vulnerabilities in an organization’s systems, applications, and infrastructure. Unlike point-in-time penetration testing, VM is an ongoing lifecycle that discovers weaknesses before attackers exploit them.

Vulnerability scanning is the automated discovery component – tools probe networks, hosts, web applications, containers, and cloud environments for known vulnerabilities (CVEs), misconfigurations, and security weaknesses. Scanning produces findings that must be prioritized, assigned to owners, tracked through remediation, and verified as resolved.

Enterprise vulnerability management platforms provide:

  • Asset discovery – identify all systems, services, and applications across on-premises, cloud, and hybrid environments; maintain an accurate asset inventory as the foundation for scanning coverage
  • Vulnerability scanning – automated detection of known CVEs, misconfigurations, default credentials, exposed services, and security weaknesses using authenticated and unauthenticated scan methods across network, web, container, and cloud targets
  • Risk prioritization – rank vulnerabilities using CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), CISA KEV (Known Exploited Vulnerabilities catalog), asset criticality, and business context to focus remediation on what matters most
  • Remediation tracking – assign vulnerabilities to owners, set SLA deadlines, track remediation progress, verify fixes through rescanning, and report on mean time to remediate (MTTR)
  • Compliance reporting – generate reports aligned to regulatory frameworks (PCI-DSS, HIPAA, SOC 2, CIS benchmarks, NIST, ISO 27001) with evidence of scanning coverage and remediation timelines
  • Integration with patch management – connect vulnerability findings to patching systems to automate or accelerate remediation of missing patches and outdated software
  • API security scanning – test REST, GraphQL, and SOAP APIs for injection flaws, broken authentication, excessive data exposure, and OWASP API Top 10 vulnerabilities
  • Container and cloud scanning – scan container images, Kubernetes manifests, Infrastructure as Code (IaC) templates, and cloud configurations for vulnerabilities and misconfigurations before and after deployment

Vulnerability management is foundational to security posture. Without it, organizations cannot answer basic questions: “What vulnerabilities exist in our environment?” and “Are we fixing them fast enough?” Every major compliance framework requires regular vulnerability scanning and documented remediation.

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

This evaluation covers the full vulnerability management landscape.


Overview Comparison

ToolTypeLicenseDeploymentLanguage / PlatformPricing
OpenVAS / GreenboneNetwork ScannerGPL-2.0Self-hostedCFree (CE); Greenbone Enterprise appliance (paid)
NucleiPen Test / ScannerApache-2.0CLI / Self-hostedGoFree; ProjectDiscovery Cloud (paid)
OWASP ZAPWeb App Scanner (DAST)LGPL-3.0Self-hosted / DesktopJavaFree
NiktoWeb App ScannerMITCLIPerlFree
TrivyContainer / CloudApache-2.0CLI / CIGoFree; Aqua Security platform (paid)
GrypeContainer / SCAApache-2.0CLI / CIGoFree; Anchore Enterprise (paid)
ClairContainer ScannerApache-2.0Self-hostedGoFree
Dependency-TrackSCA PlatformAGPL-3.0Self-hostedJavaFree
SonarQube CommunitySASTLGPL-3.0 (CE)Self-hostedJavaFree (CE); Developer/Enterprise (paid)
VulsNetwork ScannerApache-2.0Self-hosted / CLIGoFree
LynisHost AuditorApache-2.0CLIShellFree; Lynis Enterprise (paid)
OpenSCAPCompliance ScannerGPL-3.0CLICFree
ArcheryVM AggregatorApache-2.0Self-hostedPython (Django)Free
Nessus / TenableNetwork / VM PlatformProprietarySelf-hosted / CloudNessus Pro ~$3,990/yr; Tenable.io per-asset
Qualys VMDRVM PlatformProprietaryCloud (SaaS)Per-asset subscription
Rapid7 InsightVMVM PlatformProprietarySelf-hosted / CloudJavaPer-asset subscription
CrowdStrike SpotlightAgent-Based VMProprietarySaaSPer-endpoint (Falcon module)
Microsoft Defender VMAgent-Based VMProprietarySaaSIncluded with Defender for Endpoint P2 / M365 E5
Orca SecurityCloud / ContainerProprietarySaaS (agentless)Per-cloud-asset subscription
SnykSCA / SAST / ContainerProprietarySaaS / CLIFree tier; Team $25/dev/mo; Enterprise custom
VeracodeSAST / DAST / SCAProprietarySaaSPer-application subscription
AcunetixWeb App Scanner (DAST)ProprietarySelf-hosted / CloudPer-target subscription
Invicti (Netsparker)Web App Scanner (DAST)ProprietarySelf-hosted / CloudPer-target subscription
Burp Suite ProWeb App Scanner (DAST)ProprietaryDesktop / CIJava$2,199/user/yr (Pro); Enterprise per-target
HCL AppScanSAST / DASTProprietarySelf-hosted / CloudPer-application subscription
CheckmarxSAST / SCAProprietarySelf-hosted / CloudPer-developer / per-scan subscription
Black Duck (Synopsys)SCAProprietarySelf-hosted / CloudPer-application subscription
WizCloud / ContainerProprietarySaaS (agentless)Per-cloud-asset subscription
IntruderASM / Network ScannerProprietarySaaSPer-target; Essential $141/mo; Pro $196/mo

Scanning Capabilities

ToolNetworkWeb AppContainerCloud (CSPM)APIIaC
OpenVAS / GreenboneYes (primary)LimitedNoNoNoNo
NucleiYes (templates)Yes (templates)NoYes (templates)Yes (templates)No
OWASP ZAPNoYes (primary)NoNoYesNo
NiktoNoYes (primary)NoNoLimitedNo
TrivyNoNoYes (primary)Yes (AWS/Azure/GCP)NoYes (Terraform, CF, K8s)
GrypeNoNoYes (primary)NoNoNo
ClairNoNoYes (primary)NoNoNo
Dependency-TrackNoNoYes (SBOM)NoNoNo
SonarQube CommunityNoNoNoNoNoNo (source code only)
VulsYes (primary)NoYes (images)NoNoNo
LynisYes (local host)NoNoNoNoNo
OpenSCAPYes (local host)NoYes (limited)NoNoNo
ArcheryYes (aggregates)Yes (aggregates)NoNoNoNo
Nessus / TenableYes (primary)Yes (Tenable WAS)Yes (Tenable CS)Yes (Tenable CSPM)YesYes (IaC scanning)
Qualys VMDRYes (primary)Yes (Qualys WAS)Yes (Qualys CS)Yes (Qualys CSPM)YesYes (IaC scanning)
Rapid7 InsightVMYes (primary)Yes (InsightAppSec)Yes (container)Yes (InsightCloudSec)YesNo
CrowdStrike SpotlightYes (agent-based)NoYes (Falcon Cloud)Yes (Falcon Cloud)NoNo
Microsoft Defender VMYes (agent-based)NoYes (Defender for Cloud)Yes (Defender CSPM)NoNo
Orca SecurityNoNoYes (primary)Yes (primary)YesYes
SnykNoNoYes (container)Yes (Snyk IaC)NoYes (primary)
VeracodeNoYes (DAST)Yes (SCA)NoYesNo
AcunetixYes (limited)Yes (primary)NoNoYesNo
Invicti (Netsparker)Yes (limited)Yes (primary)NoNoYesNo
Burp Suite ProNoYes (primary)NoNoYesNo
HCL AppScanNoYes (DAST)NoNoYesNo
CheckmarxNoNoYes (SCA)NoYes (API security)Yes (IaC)
Black Duck (Synopsys)NoNoYes (SCA)NoNoNo
WizNoNoYes (primary)Yes (primary)YesYes
IntruderYes (primary)Yes (web scanning)NoYes (cloud connectors)YesNo

Broadest scanning: Nessus/Tenable, Qualys VMDR, Rapid7 InsightVM (all scan types from one platform)

Best container/cloud: Trivy (OSS leader), Wiz and Orca Security (commercial agentless leaders)

Best web app scanning: OWASP ZAP (OSS), Burp Suite Pro and Invicti (commercial)


Detection & Prioritization

ToolCVE DatabaseCVSSEPSSCISA KEVCustom ScoringFalse Positive Mgmt
OpenVAS / GreenboneNVD, vendor advisoriesYes (v2/v3)NoNoNoManual (notes/overrides)
NucleiCommunity templatesYesNoNoYes (template severity)Yes (template tuning)
OWASP ZAPCWE-basedYes (risk rating)NoNoYes (alert thresholds)Yes (false positive flags)
NiktoBuilt-in checksNo (info/warn)NoNoNoManual suppression
TrivyNVD, OSV, vendorYes (v3)NoNoYes (.trivyignore)Yes (ignore file)
GrypeNVD, OSV, vendorYes (v3)NoNoNoYes (ignore rules)
ClairNVD, vendorYes (v3)NoNoNoNo
Dependency-TrackNVD, OSV, GitHubYes (v2/v3/v4)YesYesYes (policy engine)Yes (analysis states)
SonarQube CommunityCWE, OWASPYes (severity)NoNoYes (quality profiles)Yes (won’t fix, FP)
VulsNVD, OVAL, vendorYes (v2/v3)NoNoNoManual suppression
LynisCIS, custom testsNo (hardening index)NoNoYes (custom profiles)Yes (skip tests)
OpenSCAPOVAL, XCCDFYes (v2/v3)NoNoYes (tailoring files)Yes (rule suppression)
ArcheryAggregated from scannersYes (from sources)NoNoYes (risk scoring)Yes (per-finding)
Nessus / TenableTenable ResearchYes (v2/v3/v4)YesYesYes (VPR / AES)Yes (accept risk, recast)
Qualys VMDRQualys KnowledgeBaseYes (v2/v3/v4)YesYesYes (TruRisk scoring)Yes (ignore, FP flags)
Rapid7 InsightVMRapid7 ResearchYes (v2/v3)YesYesYes (Real Risk scoring)Yes (exceptions, FP)
CrowdStrike SpotlightCrowdStrike IntelYes (v3)YesYesYes (ExPRT.AI scoring)Yes (exceptions)
Microsoft Defender VMMicrosoft TIYes (v3)YesYesYes (exposure score)Yes (exceptions)
Orca SecurityNVD, vendorYes (v3)YesYesYes (attack path scoring)Yes (exceptions)
SnykSnyk Intel DBYes (v3)YesYesYes (priority score)Yes (ignore, FP)
VeracodeVeracode DBYes (v3)NoNoYes (policy scoring)Yes (mitigations)
AcunetixAcunetix checksYes (v3)NoNoYes (severity tuning)Yes (FP marking)
Invicti (Netsparker)Invicti checksYes (v3)NoNoYes (confirmed/unconfirmed)Yes (proof-based – auto-confirms exploitable)
Burp Suite ProPortSwigger researchYes (severity)NoNoYes (scan config)Yes (FP marking)
HCL AppScanHCL DBYes (v3)NoNoYes (severity tuning)Yes (noise reduction)
CheckmarxCheckmarx DBYes (v3)NoNoYes (risk scoring)Yes (FP triage)
Black Duck (Synopsys)Black Duck KnowledgeBaseYes (v3)YesYesYes (risk scoring)Yes (triage workflows)
WizNVD, vendorYes (v3)YesYesYes (attack path scoring)Yes (exceptions)
IntruderNVD, IntruderYes (v3)YesYesYes (noise reduction)Yes (FP suppression)

Best prioritization: Tenable (VPR + EPSS + KEV), Qualys (TruRisk), CrowdStrike (ExPRT.AI), Rapid7 (Real Risk)

Best OSS prioritization: Dependency-Track (EPSS + KEV + policy engine)


Remediation & Reporting

ToolRemediation TrackingTicketing IntegrationSLA MgmtCompliance Reports
OpenVAS / GreenboneNo (rescan only)NoNoYes (PCI, CIS – Enterprise only)
NucleiNo (CLI output)No (external tools)NoNo
OWASP ZAPNo (rescan only)NoNoYes (OWASP Top 10)
NiktoNoNoNoNo
TrivyNo (CI gate only)NoNoNo (JSON/SARIF output)
GrypeNo (CI gate only)NoNoNo (JSON/SARIF output)
ClairNoNoNoNo
Dependency-TrackYes (analysis states)No (API-based)NoYes (OWASP risk)
SonarQube CommunityYes (issue lifecycle)Yes (Jira, Azure DevOps)No (Quality Gates)Yes (OWASP, SANS)
VulsNo (rescan only)NoNoNo
LynisNo (suggestions only)NoNoYes (CIS, ISO 27001)
OpenSCAPNo (rescan only)NoNoYes (SCAP, STIG, CIS)
ArcheryYes (finding workflow)Yes (Jira)Yes (basic)No
Nessus / TenableYes (Tenable.io workflows)Yes (Jira, ServiceNow)Yes (SLA policies)Yes (PCI, CIS, NIST, HIPAA, SOC 2)
Qualys VMDRYes (TruRisk workflows)Yes (Jira, ServiceNow, ITSM)Yes (SLA policies)Yes (PCI, CIS, NIST, HIPAA, SOC 2, ISO)
Rapid7 InsightVMYes (remediation projects)Yes (Jira, ServiceNow)Yes (SLA goals)Yes (PCI, CIS, NIST, HIPAA)
CrowdStrike SpotlightYes (via Falcon)Yes (ServiceNow, Jira)Yes (SLA via policy)Yes (PCI, CIS)
Microsoft Defender VMYes (security recommendations)Yes (Sentinel, ServiceNow)Yes (exposure score targets)Yes (CIS, NIST, PCI)
Orca SecurityYes (alert workflows)Yes (Jira, ServiceNow, Slack)Yes (SLA policies)Yes (PCI, CIS, SOC 2, HIPAA, NIST)
SnykYes (fix PRs, auto-remediate)Yes (Jira, Slack)Yes (SLA policies)Yes (license compliance)
VeracodeYes (flaw lifecycle)Yes (Jira, Azure DevOps)Yes (policy SLAs)Yes (OWASP, PCI, NIST)
AcunetixYes (issue tracking)Yes (Jira, GitHub, GitLab)NoYes (OWASP, PCI, HIPAA)
Invicti (Netsparker)Yes (issue lifecycle)Yes (Jira, Azure DevOps, GitHub)Yes (SLA rules)Yes (OWASP, PCI, HIPAA)
Burp Suite ProYes (Enterprise: issue tracking)Yes (Jira – Enterprise)Yes (Enterprise)Yes (OWASP – Enterprise)
HCL AppScanYes (issue management)Yes (Jira, Azure DevOps)Yes (policy SLAs)Yes (OWASP, PCI, HIPAA, NIST)
CheckmarxYes (issue lifecycle)Yes (Jira, Azure DevOps)Yes (policy SLAs)Yes (OWASP, PCI, HIPAA)
Black Duck (Synopsys)Yes (component governance)Yes (Jira)Yes (policy SLAs)Yes (license, OWASP)
WizYes (issue workflows)Yes (Jira, ServiceNow, Slack)Yes (SLA policies)Yes (PCI, CIS, SOC 2, HIPAA, NIST)
IntruderYes (issue tracking)Yes (Jira, Slack)Yes (SLA reminders)Yes (PCI, SOC 2, ISO 27001)

Best remediation workflows: Qualys VMDR, Tenable, Rapid7 InsightVM (full lifecycle with SLAs and ticketing)

Best auto-remediation: Snyk (auto-fix PRs for dependencies)


SSO / OIDC Comparison

OIDC is the preferred SSO protocol. The table notes each tool’s behaviour with Authentik as the IdP.

ToolOIDCSAMLSCIMAuthentik Notes
OpenVAS / GreenboneNoNoNoLDAP auth (Enterprise); reverse proxy SSO possible for OSS
NucleiN/AN/AN/ACLI tool – no web UI; ProjectDiscovery Cloud supports SSO
OWASP ZAPNoNoNoDesktop / CLI tool; no native SSO; ZAP automation framework is headless
NiktoN/AN/AN/ACLI tool – no web UI
TrivyN/AN/AN/ACLI tool – no web UI; Aqua platform supports SSO
GrypeN/AN/AN/ACLI tool – no web UI; Anchore Enterprise supports SSO
ClairNoNoNoAPI-only; no built-in web UI or SSO
Dependency-TrackYesNoNoNative OIDC support; Authentik as IdP; configure issuer URL
SonarQube CommunityNo*YesNoSAML in Developer Edition+; OIDC via plugin (community); Authentik as SAML IdP
VulsN/AN/AN/ACLI tool – no web UI; VulsRepo web UI has basic auth
LynisN/AN/AN/ACLI tool – no web UI; Enterprise has web console with SSO
OpenSCAPN/AN/AN/ACLI tool – no web UI
ArcheryNoNoNoDjango auth; LDAP plugin; reverse proxy SSO possible
Nessus / TenableYesYesYesTenable.io supports OIDC, SAML, SCIM; Nessus Pro has local auth only
Qualys VMDRNoYesYesSAML SSO; SCIM provisioning; no native OIDC; Authentik as SAML IdP
Rapid7 InsightVMNoYesYesSAML SSO via Insight Platform; SCIM provisioning; no native OIDC
CrowdStrike SpotlightYesYesYesNative OIDC and SAML via Falcon console; SCIM directory sync
Microsoft Defender VMYesYesYesEntra ID (Azure AD) SSO; OIDC/SAML; SCIM via Entra
Orca SecurityYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP
SnykYesYesYesNative OIDC and SAML; SCIM for Enterprise; Authentik as IdP
VeracodeNoYesYesSAML SSO; SCIM provisioning; no native OIDC
AcunetixNoYesNoSAML SSO; no OIDC; no SCIM
Invicti (Netsparker)NoYesYesSAML SSO; SCIM provisioning; no OIDC
Burp Suite ProNoYesNoSAML SSO (Enterprise only); no OIDC
HCL AppScanNoYesNoSAML SSO; LDAP; no OIDC
CheckmarxYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP
Black Duck (Synopsys)NoYesYesSAML SSO; SCIM provisioning (Polaris); no OIDC
WizYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP
IntruderNoNoNoEmail/password auth; Google SSO; no OIDC/SAML federation

* = requires extension, plugin, or specific configuration

Best SSO support: CrowdStrike Spotlight (OIDC, SAML, SCIM), Wiz (OIDC, SAML, SCIM), Snyk (OIDC, SAML, SCIM), Checkmarx (OIDC, SAML, SCIM)

No SSO applicable: Nuclei, Nikto, Trivy, Grype, Vuls, Lynis, OpenSCAP (CLI tools – no web UI)


Monitoring Integration

Integration with a monitoring stack of Telegraf, InfluxDB, Grafana, and AlertManager.

ToolTelegraf MetricsFluent Bit LogsGrafana Dashboards
OpenVAS / GreenboneAPI polling (scan stats, host counts)Syslog / log file collectionCustom (scan results, vulnerability trends)
NucleiParse JSON output (finding counts)JSON output to log pipelineCustom (template hits, severity distribution)
OWASP ZAPAPI polling (scan progress, alert counts)Log file / JSON report ingestionCustom (alert trends, scan coverage)
NiktoParse output (finding counts)Log file collectionCustom (finding trends)
TrivyParse JSON output (vuln counts by severity)JSON/SARIF output to pipelineCustom (image vuln trends, CI failures)
GrypeParse JSON output (vuln counts)JSON output to pipelineCustom (dependency vuln trends)
ClairAPI polling (vulnerability counts)Log file collectionCustom (image vulnerability status)
Dependency-TrackAPI polling (project metrics, findings)Webhook events to log pipelineCustom (component risk, policy violations)
SonarQube CommunityAPI polling (project metrics, issues)Log file / webhook eventsCommunity dashboards available
VulsParse JSON output (host vuln counts)JSON report to pipelineCustom (host vulnerability trends)
LynisParse report output (hardening score)Log file collectionCustom (hardening scores over time)
OpenSCAPParse XCCDF results (pass/fail counts)Report output to pipelineCustom (compliance pass rates)
ArcheryAPI polling (project/scan metrics)Log file collectionCustom (aggregated vuln trends)
Nessus / TenableAPI polling (scan stats, vuln counts)Syslog forwarding / API exportCommunity + Tenable dashboards
Qualys VMDRAPI polling (scan stats, TruRisk)API export / syslog forwardingCommunity dashboards available
Rapid7 InsightVMAPI polling (site stats, risk scores)Syslog forwarding / API exportCommunity dashboards available
CrowdStrike SpotlightAPI polling (vuln counts per host)Streaming API to log pipelineCustom (Falcon vuln posture)
Microsoft Defender VMGraph API polling (recommendations)Syslog (CEF) / Sentinel exportCustom (exposure score trends)
Orca SecurityAPI polling (alert counts, risk)Webhook / API alert exportCustom (cloud risk posture)
SnykAPI polling (project vuln counts)Webhook events to pipelineCustom (dependency risk trends)
VeracodeAPI polling (flaw counts, policy status)API exportCustom (application risk trends)
AcunetixAPI polling (scan stats, vuln counts)Webhook / log exportCustom (web app risk trends)
Invicti (Netsparker)API polling (scan stats, issue counts)Webhook / syslog exportCustom (web app vuln trends)
Burp Suite ProAPI polling (Enterprise: scan stats)Log file / API exportCustom (scan coverage)
HCL AppScanAPI polling (scan metrics)Log export / webhookCustom (app risk trends)
CheckmarxAPI polling (scan results, risk)Webhook / API exportCustom (code risk trends)
Black Duck (Synopsys)API polling (component risk)Webhook / API exportCustom (SCA risk dashboard)
WizAPI polling (issue counts, risk scores)Webhook / API alert exportCustom (cloud security posture)
IntruderAPI polling (scan stats, vuln counts)Webhook eventsCustom (external attack surface)

Easiest monitoring integration: OpenVAS (syslog + API), Dependency-Track (webhooks + API), SonarQube (webhooks + API) – all self-hosted with well- documented APIs

CLI tools (Nuclei, Trivy, Grype, Nikto, Vuls, Lynis, OpenSCAP) require parsing JSON/SARIF output via Telegraf exec or Fluent Bit pipelines


Deployment & Scale

ToolCloudOn-PremAgentsAgentlessMulti-TenancyAPI
OpenVAS / GreenboneNo (Enterprise appliance)YesNoYes (network scan)Yes (Enterprise)Yes (GMP XML, REST)
NucleiProjectDiscovery CloudYes (CLI)NoYes (network scan)Yes (Cloud)Yes (REST – Cloud)
OWASP ZAPNoYes (Desktop/Docker)NoYes (web scan)NoYes (REST)
NiktoNoYes (CLI)NoYes (web scan)NoNo
TrivyAqua platformYes (CLI/CI)NoYes (image/IaC scan)NoNo (CLI only)
GrypeAnchore EnterpriseYes (CLI/CI)NoYes (image scan)NoNo (CLI only)
ClairNoYes (Docker/K8s)NoYes (image scan)NoYes (REST)
Dependency-TrackNoYes (Docker/WAR)NoYes (SBOM analysis)Yes (teams/permissions)Yes (REST)
SonarQube CommunitySonarCloudYes (Docker/ZIP)NoYes (source scan)Yes (projects/orgs)Yes (REST)
VulsNoYes (CLI)NoYes (SSH-based scan)NoNo (CLI)
LynisLynis EnterpriseYes (CLI)Yes (local execution)NoYes (Enterprise)No (CLI)
OpenSCAPNoYes (CLI)Yes (local execution)NoNoNo (CLI)
ArcheryNoYes (Docker)NoYes (aggregator)Yes (projects)Yes (REST)
Nessus / TenableTenable.io (SaaS)Yes (Nessus Pro)Yes (Nessus Agent)Yes (network scan)Yes (Tenable.io)Yes (REST)
Qualys VMDRYes (SaaS primary)Yes (scanner appliance)Yes (Qualys Agent)Yes (network scan)Yes (subscriptions)Yes (REST)
Rapid7 InsightVMInsightVM CloudYes (console + engine)Yes (Insight Agent)Yes (network scan)Yes (sites/asset groups)Yes (REST)
CrowdStrike SpotlightYes (SaaS only)NoYes (Falcon sensor)No (agent-based)Yes (Flight Control)Yes (REST)
Microsoft Defender VMYes (SaaS only)NoYes (Defender agent)No (agent-based)Yes (multi-tenant mgmt)Yes (Graph API)
Orca SecurityYes (SaaS only)NoNoYes (agentless cloud)Yes (multi-account)Yes (REST)
SnykYes (SaaS primary)Yes (Snyk Broker)NoYes (SCM/CI scan)Yes (orgs/groups)Yes (REST)
VeracodeYes (SaaS only)NoNoYes (binary/source)Yes (teams/workspaces)Yes (REST)
AcunetixYes (SaaS option)Yes (on-prem)NoYes (web scan)Yes (targets/groups)Yes (REST)
Invicti (Netsparker)Yes (SaaS option)Yes (on-prem)NoYes (web scan)Yes (teams/websites)Yes (REST)
Burp Suite ProNo (Enterprise: yes)Yes (Desktop/CI)NoYes (web scan)Yes (Enterprise)Yes (REST – Enterprise)
HCL AppScanYes (SaaS option)Yes (on-prem)NoYes (source/web scan)Yes (apps/users)Yes (REST)
CheckmarxYes (Checkmarx One)Yes (on-prem)NoYes (source scan)Yes (teams/projects)Yes (REST)
Black Duck (Synopsys)Yes (Polaris SaaS)Yes (on-prem)NoYes (binary/source)Yes (projects/groups)Yes (REST)
WizYes (SaaS only)NoNoYes (agentless cloud)Yes (multi-tenant)Yes (REST + GraphQL)
IntruderYes (SaaS only)NoNoYes (external scan)Yes (teams/targets)Yes (REST)

Self-hosted OSS: OpenVAS, OWASP ZAP, Dependency-Track, SonarQube, Archery, Clair

Agentless scanning: Orca, Wiz (cloud-native SideScanning / snapshot analysis – no agents on workloads)

Agent-based VM: CrowdStrike Spotlight and Microsoft Defender VM leverage existing EDR agents for vulnerability assessment (no separate scanner)


Tools

29 tools.

Acunetix

Acunetix is a web application vulnerability scanner specializing in Dynamic Application Security Testing (DAST).

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Archery

Archery (ArcherySec) is an open-source vulnerability assessment and management platform that aggregates results from multiple security scanning tools into a centralized dashboard.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none

Website · Source

Black Duck

Black Duck (formerly Black Duck Software, now part of Synopsys / recently divested) is an enterprise Software Composition Analysis (SCA) platform specializing in open-source security, license compliance, and software supply chain risk manag…

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Burp Suite Pro

Burp Suite is the industry-standard web security testing toolkit developed by PortSwigger. It provides an intercepting proxy, automated scanner, and extensive manual testing tools for web application security professionals.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: none

Website

Checkmarx

Checkmarx is a leading application security testing platform providing SAST (Static Application Security Testing), SCA (Software Composition Analysis), DAST, API security testing, and supply chain security.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

Clair

Clair is an open-source container image vulnerability analysis tool originally developed by CoreOS (now Red Hat). It performs static analysis of container image layers to identify known vulnerabilities in OS packages.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none

Website · Source

CrowdStrike Falcon Spotlight

CrowdStrike Falcon Spotlight is a vulnerability assessment module within the CrowdStrike Falcon platform.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Dependency-Track

Dependency-Track is an open-source OWASP Software Composition Analysis platform that consumes SBOMs (CycloneDX, SPDX) and continuously monitors components for known vulnerabilities and license risks.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: none

Website · Source

Grype

Grype is an open-source vulnerability scanner for container images and filesystems, developed by Anchore.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

HCL AppScan

HCL AppScan is an enterprise application security testing platform providing DAST (Dynamic Analysis), SAST (Static Analysis), IAST (Interactive Analysis), and SCA (Software Composition Analysis).

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Intruder

Intruder is a cloud-based automated vulnerability scanning platform designed for small to mid-size businesses (SMBs) and development teams.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Invicti

Invicti (formerly Netsparker) is an enterprise web application security platform providing automated DAST and IAST scanning with a unique Proof-Based Scanning technology.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Lynis

Lynis is an open-source security auditing and hardening tool for Unix-based systems including Linux, macOS, and BSD.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management (MDVM), formerly Threat and Vulnerability Management (TVM), is a built-in vulnerability management capability within Microsoft Defender for Endpoint.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Nessus / Tenable

Nessus is the market-leading vulnerability scanner, originally created in 1998 by Renaud Deraison and now developed by Tenable.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Nikto

Nikto is an open-source web server scanner that performs comprehensive tests against web servers for dangerous files, outdated software versions, server misconfigurations, and CGI vulnerabilities.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Nuclei

Nuclei is a fast, open-source template-driven vulnerability scanner from ProjectDiscovery, using YAML templates across HTTP, DNS, TCP, and other protocols with a large community template library.

License: MIT (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

OpenSCAP

OpenSCAP is an open-source implementation of the Security Content Automation Protocol (SCAP) standards maintained by NIST.

License: LGPL-2.1-or-later (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

OpenVAS / Greenbone

OpenVAS (Open Vulnerability Assessment Scanner) is the open-source vulnerability scanning engine at the core of the Greenbone Vulnerability Management (GVM) framework.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Orca Security

Orca Security is an agentless cloud security platform (CNAPP) that provides vulnerability management, misconfiguration detection, malware scanning, lateral movement risk analysis, and compliance checking across AWS, Azure, GCP, and Alibaba…

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

OWASP ZAP

OWASP ZAP (Zed Attack Proxy) is the world’s most widely used open-source web application security scanner.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Qualys VMDR

Qualys VMDR (Vulnerability Management, Detection, and Response) is a cloud-based vulnerability management platform that provides asset discovery, vulnerability assessment, prioritization, and remediation tracking in a unified workflow.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Rapid7 InsightVM

Rapid7 InsightVM is a vulnerability management solution built on the Nexpose scan engine with cloud-based analytics and live dashboards via the Rapid7 Insight Platform.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Snyk

Snyk is a developer-first security platform providing Software Composition Analysis (SCA), Static Application Security Testing (SAST), container image scanning, and Infrastructure as Code (IaC) security testing.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

SonarQube Community

SonarQube Community Edition is an open-source platform for continuous code quality and security analysis.

License: LGPL-3.0-or-later (OSS) · Kind: web · Deploy: native, docker · SSO: SAML

Website · Source

Trivy

Trivy is a comprehensive open-source security scanner developed by Aqua Security. It detects vulnerabilities, misconfigurations, secrets, and license issues across container images, filesystems, Git repositories, Kubernetes clusters, and Ia…

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Veracode

Veracode is an enterprise application security testing platform providing SAST (Static Analysis), DAST (Dynamic Analysis), SCA (Software Composition Analysis), manual penetration testing, and compliance reporting.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Vuls

Vuls (VULnerability Scanner) is an open-source agentless vulnerability scanner for Linux and FreeBSD systems.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Wiz

Wiz is a cloud security platform (CNAPP) providing agentless vulnerability management, cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), container security, Kubernetes security posture management…

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

ResorsIT Tools Catalog Search