License & Deployment Mix: 29 tools – 13 OSS, 10 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
What Is Vulnerability Management?
Vulnerability Management (VM) is the continuous process of identifying, classifying, prioritizing, remediating, and mitigating security vulnerabilities in an organization’s systems, applications, and infrastructure. Unlike point-in-time penetration testing, VM is an ongoing lifecycle that discovers weaknesses before attackers exploit them.
Vulnerability scanning is the automated discovery component – tools probe networks, hosts, web applications, containers, and cloud environments for known vulnerabilities (CVEs), misconfigurations, and security weaknesses. Scanning produces findings that must be prioritized, assigned to owners, tracked through remediation, and verified as resolved.
Enterprise vulnerability management platforms provide:
- Asset discovery – identify all systems, services, and applications across on-premises, cloud, and hybrid environments; maintain an accurate asset inventory as the foundation for scanning coverage
- Vulnerability scanning – automated detection of known CVEs, misconfigurations, default credentials, exposed services, and security weaknesses using authenticated and unauthenticated scan methods across network, web, container, and cloud targets
- Risk prioritization – rank vulnerabilities using CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), CISA KEV (Known Exploited Vulnerabilities catalog), asset criticality, and business context to focus remediation on what matters most
- Remediation tracking – assign vulnerabilities to owners, set SLA deadlines, track remediation progress, verify fixes through rescanning, and report on mean time to remediate (MTTR)
- Compliance reporting – generate reports aligned to regulatory frameworks (PCI-DSS, HIPAA, SOC 2, CIS benchmarks, NIST, ISO 27001) with evidence of scanning coverage and remediation timelines
- Integration with patch management – connect vulnerability findings to patching systems to automate or accelerate remediation of missing patches and outdated software
- API security scanning – test REST, GraphQL, and SOAP APIs for injection flaws, broken authentication, excessive data exposure, and OWASP API Top 10 vulnerabilities
- Container and cloud scanning – scan container images, Kubernetes manifests, Infrastructure as Code (IaC) templates, and cloud configurations for vulnerabilities and misconfigurations before and after deployment
Vulnerability management is foundational to security posture. Without it, organizations cannot answer basic questions: “What vulnerabilities exist in our environment?” and “Are we fixing them fast enough?” Every major compliance framework requires regular vulnerability scanning and documented remediation.
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
This evaluation covers the full vulnerability management landscape.
Overview Comparison
| Tool | Type | License | Deployment | Language / Platform | Pricing |
|---|---|---|---|---|---|
| OpenVAS / Greenbone | Network Scanner | GPL-2.0 | Self-hosted | C | Free (CE); Greenbone Enterprise appliance (paid) |
| Nuclei | Pen Test / Scanner | Apache-2.0 | CLI / Self-hosted | Go | Free; ProjectDiscovery Cloud (paid) |
| OWASP ZAP | Web App Scanner (DAST) | LGPL-3.0 | Self-hosted / Desktop | Java | Free |
| Nikto | Web App Scanner | MIT | CLI | Perl | Free |
| Trivy | Container / Cloud | Apache-2.0 | CLI / CI | Go | Free; Aqua Security platform (paid) |
| Grype | Container / SCA | Apache-2.0 | CLI / CI | Go | Free; Anchore Enterprise (paid) |
| Clair | Container Scanner | Apache-2.0 | Self-hosted | Go | Free |
| Dependency-Track | SCA Platform | AGPL-3.0 | Self-hosted | Java | Free |
| SonarQube Community | SAST | LGPL-3.0 (CE) | Self-hosted | Java | Free (CE); Developer/Enterprise (paid) |
| Vuls | Network Scanner | Apache-2.0 | Self-hosted / CLI | Go | Free |
| Lynis | Host Auditor | Apache-2.0 | CLI | Shell | Free; Lynis Enterprise (paid) |
| OpenSCAP | Compliance Scanner | GPL-3.0 | CLI | C | Free |
| Archery | VM Aggregator | Apache-2.0 | Self-hosted | Python (Django) | Free |
| Nessus / Tenable | Network / VM Platform | Proprietary | Self-hosted / Cloud | – | Nessus Pro ~$3,990/yr; Tenable.io per-asset |
| Qualys VMDR | VM Platform | Proprietary | Cloud (SaaS) | – | Per-asset subscription |
| Rapid7 InsightVM | VM Platform | Proprietary | Self-hosted / Cloud | Java | Per-asset subscription |
| CrowdStrike Spotlight | Agent-Based VM | Proprietary | SaaS | – | Per-endpoint (Falcon module) |
| Microsoft Defender VM | Agent-Based VM | Proprietary | SaaS | – | Included with Defender for Endpoint P2 / M365 E5 |
| Orca Security | Cloud / Container | Proprietary | SaaS (agentless) | – | Per-cloud-asset subscription |
| Snyk | SCA / SAST / Container | Proprietary | SaaS / CLI | – | Free tier; Team $25/dev/mo; Enterprise custom |
| Veracode | SAST / DAST / SCA | Proprietary | SaaS | – | Per-application subscription |
| Acunetix | Web App Scanner (DAST) | Proprietary | Self-hosted / Cloud | – | Per-target subscription |
| Invicti (Netsparker) | Web App Scanner (DAST) | Proprietary | Self-hosted / Cloud | – | Per-target subscription |
| Burp Suite Pro | Web App Scanner (DAST) | Proprietary | Desktop / CI | Java | $2,199/user/yr (Pro); Enterprise per-target |
| HCL AppScan | SAST / DAST | Proprietary | Self-hosted / Cloud | – | Per-application subscription |
| Checkmarx | SAST / SCA | Proprietary | Self-hosted / Cloud | – | Per-developer / per-scan subscription |
| Black Duck (Synopsys) | SCA | Proprietary | Self-hosted / Cloud | – | Per-application subscription |
| Wiz | Cloud / Container | Proprietary | SaaS (agentless) | – | Per-cloud-asset subscription |
| Intruder | ASM / Network Scanner | Proprietary | SaaS | – | Per-target; Essential $141/mo; Pro $196/mo |
Scanning Capabilities
| Tool | Network | Web App | Container | Cloud (CSPM) | API | IaC |
|---|---|---|---|---|---|---|
| OpenVAS / Greenbone | Yes (primary) | Limited | No | No | No | No |
| Nuclei | Yes (templates) | Yes (templates) | No | Yes (templates) | Yes (templates) | No |
| OWASP ZAP | No | Yes (primary) | No | No | Yes | No |
| Nikto | No | Yes (primary) | No | No | Limited | No |
| Trivy | No | No | Yes (primary) | Yes (AWS/Azure/GCP) | No | Yes (Terraform, CF, K8s) |
| Grype | No | No | Yes (primary) | No | No | No |
| Clair | No | No | Yes (primary) | No | No | No |
| Dependency-Track | No | No | Yes (SBOM) | No | No | No |
| SonarQube Community | No | No | No | No | No | No (source code only) |
| Vuls | Yes (primary) | No | Yes (images) | No | No | No |
| Lynis | Yes (local host) | No | No | No | No | No |
| OpenSCAP | Yes (local host) | No | Yes (limited) | No | No | No |
| Archery | Yes (aggregates) | Yes (aggregates) | No | No | No | No |
| Nessus / Tenable | Yes (primary) | Yes (Tenable WAS) | Yes (Tenable CS) | Yes (Tenable CSPM) | Yes | Yes (IaC scanning) |
| Qualys VMDR | Yes (primary) | Yes (Qualys WAS) | Yes (Qualys CS) | Yes (Qualys CSPM) | Yes | Yes (IaC scanning) |
| Rapid7 InsightVM | Yes (primary) | Yes (InsightAppSec) | Yes (container) | Yes (InsightCloudSec) | Yes | No |
| CrowdStrike Spotlight | Yes (agent-based) | No | Yes (Falcon Cloud) | Yes (Falcon Cloud) | No | No |
| Microsoft Defender VM | Yes (agent-based) | No | Yes (Defender for Cloud) | Yes (Defender CSPM) | No | No |
| Orca Security | No | No | Yes (primary) | Yes (primary) | Yes | Yes |
| Snyk | No | No | Yes (container) | Yes (Snyk IaC) | No | Yes (primary) |
| Veracode | No | Yes (DAST) | Yes (SCA) | No | Yes | No |
| Acunetix | Yes (limited) | Yes (primary) | No | No | Yes | No |
| Invicti (Netsparker) | Yes (limited) | Yes (primary) | No | No | Yes | No |
| Burp Suite Pro | No | Yes (primary) | No | No | Yes | No |
| HCL AppScan | No | Yes (DAST) | No | No | Yes | No |
| Checkmarx | No | No | Yes (SCA) | No | Yes (API security) | Yes (IaC) |
| Black Duck (Synopsys) | No | No | Yes (SCA) | No | No | No |
| Wiz | No | No | Yes (primary) | Yes (primary) | Yes | Yes |
| Intruder | Yes (primary) | Yes (web scanning) | No | Yes (cloud connectors) | Yes | No |
Broadest scanning: Nessus/Tenable, Qualys VMDR, Rapid7 InsightVM (all scan types from one platform)
Best container/cloud: Trivy (OSS leader), Wiz and Orca Security (commercial agentless leaders)
Best web app scanning: OWASP ZAP (OSS), Burp Suite Pro and Invicti (commercial)
Detection & Prioritization
| Tool | CVE Database | CVSS | EPSS | CISA KEV | Custom Scoring | False Positive Mgmt |
|---|---|---|---|---|---|---|
| OpenVAS / Greenbone | NVD, vendor advisories | Yes (v2/v3) | No | No | No | Manual (notes/overrides) |
| Nuclei | Community templates | Yes | No | No | Yes (template severity) | Yes (template tuning) |
| OWASP ZAP | CWE-based | Yes (risk rating) | No | No | Yes (alert thresholds) | Yes (false positive flags) |
| Nikto | Built-in checks | No (info/warn) | No | No | No | Manual suppression |
| Trivy | NVD, OSV, vendor | Yes (v3) | No | No | Yes (.trivyignore) | Yes (ignore file) |
| Grype | NVD, OSV, vendor | Yes (v3) | No | No | No | Yes (ignore rules) |
| Clair | NVD, vendor | Yes (v3) | No | No | No | No |
| Dependency-Track | NVD, OSV, GitHub | Yes (v2/v3/v4) | Yes | Yes | Yes (policy engine) | Yes (analysis states) |
| SonarQube Community | CWE, OWASP | Yes (severity) | No | No | Yes (quality profiles) | Yes (won’t fix, FP) |
| Vuls | NVD, OVAL, vendor | Yes (v2/v3) | No | No | No | Manual suppression |
| Lynis | CIS, custom tests | No (hardening index) | No | No | Yes (custom profiles) | Yes (skip tests) |
| OpenSCAP | OVAL, XCCDF | Yes (v2/v3) | No | No | Yes (tailoring files) | Yes (rule suppression) |
| Archery | Aggregated from scanners | Yes (from sources) | No | No | Yes (risk scoring) | Yes (per-finding) |
| Nessus / Tenable | Tenable Research | Yes (v2/v3/v4) | Yes | Yes | Yes (VPR / AES) | Yes (accept risk, recast) |
| Qualys VMDR | Qualys KnowledgeBase | Yes (v2/v3/v4) | Yes | Yes | Yes (TruRisk scoring) | Yes (ignore, FP flags) |
| Rapid7 InsightVM | Rapid7 Research | Yes (v2/v3) | Yes | Yes | Yes (Real Risk scoring) | Yes (exceptions, FP) |
| CrowdStrike Spotlight | CrowdStrike Intel | Yes (v3) | Yes | Yes | Yes (ExPRT.AI scoring) | Yes (exceptions) |
| Microsoft Defender VM | Microsoft TI | Yes (v3) | Yes | Yes | Yes (exposure score) | Yes (exceptions) |
| Orca Security | NVD, vendor | Yes (v3) | Yes | Yes | Yes (attack path scoring) | Yes (exceptions) |
| Snyk | Snyk Intel DB | Yes (v3) | Yes | Yes | Yes (priority score) | Yes (ignore, FP) |
| Veracode | Veracode DB | Yes (v3) | No | No | Yes (policy scoring) | Yes (mitigations) |
| Acunetix | Acunetix checks | Yes (v3) | No | No | Yes (severity tuning) | Yes (FP marking) |
| Invicti (Netsparker) | Invicti checks | Yes (v3) | No | No | Yes (confirmed/unconfirmed) | Yes (proof-based – auto-confirms exploitable) |
| Burp Suite Pro | PortSwigger research | Yes (severity) | No | No | Yes (scan config) | Yes (FP marking) |
| HCL AppScan | HCL DB | Yes (v3) | No | No | Yes (severity tuning) | Yes (noise reduction) |
| Checkmarx | Checkmarx DB | Yes (v3) | No | No | Yes (risk scoring) | Yes (FP triage) |
| Black Duck (Synopsys) | Black Duck KnowledgeBase | Yes (v3) | Yes | Yes | Yes (risk scoring) | Yes (triage workflows) |
| Wiz | NVD, vendor | Yes (v3) | Yes | Yes | Yes (attack path scoring) | Yes (exceptions) |
| Intruder | NVD, Intruder | Yes (v3) | Yes | Yes | Yes (noise reduction) | Yes (FP suppression) |
Best prioritization: Tenable (VPR + EPSS + KEV), Qualys (TruRisk), CrowdStrike (ExPRT.AI), Rapid7 (Real Risk)
Best OSS prioritization: Dependency-Track (EPSS + KEV + policy engine)
Remediation & Reporting
| Tool | Remediation Tracking | Ticketing Integration | SLA Mgmt | Compliance Reports |
|---|---|---|---|---|
| OpenVAS / Greenbone | No (rescan only) | No | No | Yes (PCI, CIS – Enterprise only) |
| Nuclei | No (CLI output) | No (external tools) | No | No |
| OWASP ZAP | No (rescan only) | No | No | Yes (OWASP Top 10) |
| Nikto | No | No | No | No |
| Trivy | No (CI gate only) | No | No | No (JSON/SARIF output) |
| Grype | No (CI gate only) | No | No | No (JSON/SARIF output) |
| Clair | No | No | No | No |
| Dependency-Track | Yes (analysis states) | No (API-based) | No | Yes (OWASP risk) |
| SonarQube Community | Yes (issue lifecycle) | Yes (Jira, Azure DevOps) | No (Quality Gates) | Yes (OWASP, SANS) |
| Vuls | No (rescan only) | No | No | No |
| Lynis | No (suggestions only) | No | No | Yes (CIS, ISO 27001) |
| OpenSCAP | No (rescan only) | No | No | Yes (SCAP, STIG, CIS) |
| Archery | Yes (finding workflow) | Yes (Jira) | Yes (basic) | No |
| Nessus / Tenable | Yes (Tenable.io workflows) | Yes (Jira, ServiceNow) | Yes (SLA policies) | Yes (PCI, CIS, NIST, HIPAA, SOC 2) |
| Qualys VMDR | Yes (TruRisk workflows) | Yes (Jira, ServiceNow, ITSM) | Yes (SLA policies) | Yes (PCI, CIS, NIST, HIPAA, SOC 2, ISO) |
| Rapid7 InsightVM | Yes (remediation projects) | Yes (Jira, ServiceNow) | Yes (SLA goals) | Yes (PCI, CIS, NIST, HIPAA) |
| CrowdStrike Spotlight | Yes (via Falcon) | Yes (ServiceNow, Jira) | Yes (SLA via policy) | Yes (PCI, CIS) |
| Microsoft Defender VM | Yes (security recommendations) | Yes (Sentinel, ServiceNow) | Yes (exposure score targets) | Yes (CIS, NIST, PCI) |
| Orca Security | Yes (alert workflows) | Yes (Jira, ServiceNow, Slack) | Yes (SLA policies) | Yes (PCI, CIS, SOC 2, HIPAA, NIST) |
| Snyk | Yes (fix PRs, auto-remediate) | Yes (Jira, Slack) | Yes (SLA policies) | Yes (license compliance) |
| Veracode | Yes (flaw lifecycle) | Yes (Jira, Azure DevOps) | Yes (policy SLAs) | Yes (OWASP, PCI, NIST) |
| Acunetix | Yes (issue tracking) | Yes (Jira, GitHub, GitLab) | No | Yes (OWASP, PCI, HIPAA) |
| Invicti (Netsparker) | Yes (issue lifecycle) | Yes (Jira, Azure DevOps, GitHub) | Yes (SLA rules) | Yes (OWASP, PCI, HIPAA) |
| Burp Suite Pro | Yes (Enterprise: issue tracking) | Yes (Jira – Enterprise) | Yes (Enterprise) | Yes (OWASP – Enterprise) |
| HCL AppScan | Yes (issue management) | Yes (Jira, Azure DevOps) | Yes (policy SLAs) | Yes (OWASP, PCI, HIPAA, NIST) |
| Checkmarx | Yes (issue lifecycle) | Yes (Jira, Azure DevOps) | Yes (policy SLAs) | Yes (OWASP, PCI, HIPAA) |
| Black Duck (Synopsys) | Yes (component governance) | Yes (Jira) | Yes (policy SLAs) | Yes (license, OWASP) |
| Wiz | Yes (issue workflows) | Yes (Jira, ServiceNow, Slack) | Yes (SLA policies) | Yes (PCI, CIS, SOC 2, HIPAA, NIST) |
| Intruder | Yes (issue tracking) | Yes (Jira, Slack) | Yes (SLA reminders) | Yes (PCI, SOC 2, ISO 27001) |
Best remediation workflows: Qualys VMDR, Tenable, Rapid7 InsightVM (full lifecycle with SLAs and ticketing)
Best auto-remediation: Snyk (auto-fix PRs for dependencies)
SSO / OIDC Comparison
OIDC is the preferred SSO protocol. The table notes each tool’s behaviour with Authentik as the IdP.
| Tool | OIDC | SAML | SCIM | Authentik Notes |
|---|---|---|---|---|
| OpenVAS / Greenbone | No | No | No | LDAP auth (Enterprise); reverse proxy SSO possible for OSS |
| Nuclei | N/A | N/A | N/A | CLI tool – no web UI; ProjectDiscovery Cloud supports SSO |
| OWASP ZAP | No | No | No | Desktop / CLI tool; no native SSO; ZAP automation framework is headless |
| Nikto | N/A | N/A | N/A | CLI tool – no web UI |
| Trivy | N/A | N/A | N/A | CLI tool – no web UI; Aqua platform supports SSO |
| Grype | N/A | N/A | N/A | CLI tool – no web UI; Anchore Enterprise supports SSO |
| Clair | No | No | No | API-only; no built-in web UI or SSO |
| Dependency-Track | Yes | No | No | Native OIDC support; Authentik as IdP; configure issuer URL |
| SonarQube Community | No* | Yes | No | SAML in Developer Edition+; OIDC via plugin (community); Authentik as SAML IdP |
| Vuls | N/A | N/A | N/A | CLI tool – no web UI; VulsRepo web UI has basic auth |
| Lynis | N/A | N/A | N/A | CLI tool – no web UI; Enterprise has web console with SSO |
| OpenSCAP | N/A | N/A | N/A | CLI tool – no web UI |
| Archery | No | No | No | Django auth; LDAP plugin; reverse proxy SSO possible |
| Nessus / Tenable | Yes | Yes | Yes | Tenable.io supports OIDC, SAML, SCIM; Nessus Pro has local auth only |
| Qualys VMDR | No | Yes | Yes | SAML SSO; SCIM provisioning; no native OIDC; Authentik as SAML IdP |
| Rapid7 InsightVM | No | Yes | Yes | SAML SSO via Insight Platform; SCIM provisioning; no native OIDC |
| CrowdStrike Spotlight | Yes | Yes | Yes | Native OIDC and SAML via Falcon console; SCIM directory sync |
| Microsoft Defender VM | Yes | Yes | Yes | Entra ID (Azure AD) SSO; OIDC/SAML; SCIM via Entra |
| Orca Security | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
| Snyk | Yes | Yes | Yes | Native OIDC and SAML; SCIM for Enterprise; Authentik as IdP |
| Veracode | No | Yes | Yes | SAML SSO; SCIM provisioning; no native OIDC |
| Acunetix | No | Yes | No | SAML SSO; no OIDC; no SCIM |
| Invicti (Netsparker) | No | Yes | Yes | SAML SSO; SCIM provisioning; no OIDC |
| Burp Suite Pro | No | Yes | No | SAML SSO (Enterprise only); no OIDC |
| HCL AppScan | No | Yes | No | SAML SSO; LDAP; no OIDC |
| Checkmarx | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
| Black Duck (Synopsys) | No | Yes | Yes | SAML SSO; SCIM provisioning (Polaris); no OIDC |
| Wiz | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
| Intruder | No | No | No | Email/password auth; Google SSO; no OIDC/SAML federation |
* = requires extension, plugin, or specific configuration
Best SSO support: CrowdStrike Spotlight (OIDC, SAML, SCIM), Wiz (OIDC, SAML, SCIM), Snyk (OIDC, SAML, SCIM), Checkmarx (OIDC, SAML, SCIM)
No SSO applicable: Nuclei, Nikto, Trivy, Grype, Vuls, Lynis, OpenSCAP (CLI tools – no web UI)
Monitoring Integration
Integration with a monitoring stack of Telegraf, InfluxDB, Grafana, and AlertManager.
| Tool | Telegraf Metrics | Fluent Bit Logs | Grafana Dashboards |
|---|---|---|---|
| OpenVAS / Greenbone | API polling (scan stats, host counts) | Syslog / log file collection | Custom (scan results, vulnerability trends) |
| Nuclei | Parse JSON output (finding counts) | JSON output to log pipeline | Custom (template hits, severity distribution) |
| OWASP ZAP | API polling (scan progress, alert counts) | Log file / JSON report ingestion | Custom (alert trends, scan coverage) |
| Nikto | Parse output (finding counts) | Log file collection | Custom (finding trends) |
| Trivy | Parse JSON output (vuln counts by severity) | JSON/SARIF output to pipeline | Custom (image vuln trends, CI failures) |
| Grype | Parse JSON output (vuln counts) | JSON output to pipeline | Custom (dependency vuln trends) |
| Clair | API polling (vulnerability counts) | Log file collection | Custom (image vulnerability status) |
| Dependency-Track | API polling (project metrics, findings) | Webhook events to log pipeline | Custom (component risk, policy violations) |
| SonarQube Community | API polling (project metrics, issues) | Log file / webhook events | Community dashboards available |
| Vuls | Parse JSON output (host vuln counts) | JSON report to pipeline | Custom (host vulnerability trends) |
| Lynis | Parse report output (hardening score) | Log file collection | Custom (hardening scores over time) |
| OpenSCAP | Parse XCCDF results (pass/fail counts) | Report output to pipeline | Custom (compliance pass rates) |
| Archery | API polling (project/scan metrics) | Log file collection | Custom (aggregated vuln trends) |
| Nessus / Tenable | API polling (scan stats, vuln counts) | Syslog forwarding / API export | Community + Tenable dashboards |
| Qualys VMDR | API polling (scan stats, TruRisk) | API export / syslog forwarding | Community dashboards available |
| Rapid7 InsightVM | API polling (site stats, risk scores) | Syslog forwarding / API export | Community dashboards available |
| CrowdStrike Spotlight | API polling (vuln counts per host) | Streaming API to log pipeline | Custom (Falcon vuln posture) |
| Microsoft Defender VM | Graph API polling (recommendations) | Syslog (CEF) / Sentinel export | Custom (exposure score trends) |
| Orca Security | API polling (alert counts, risk) | Webhook / API alert export | Custom (cloud risk posture) |
| Snyk | API polling (project vuln counts) | Webhook events to pipeline | Custom (dependency risk trends) |
| Veracode | API polling (flaw counts, policy status) | API export | Custom (application risk trends) |
| Acunetix | API polling (scan stats, vuln counts) | Webhook / log export | Custom (web app risk trends) |
| Invicti (Netsparker) | API polling (scan stats, issue counts) | Webhook / syslog export | Custom (web app vuln trends) |
| Burp Suite Pro | API polling (Enterprise: scan stats) | Log file / API export | Custom (scan coverage) |
| HCL AppScan | API polling (scan metrics) | Log export / webhook | Custom (app risk trends) |
| Checkmarx | API polling (scan results, risk) | Webhook / API export | Custom (code risk trends) |
| Black Duck (Synopsys) | API polling (component risk) | Webhook / API export | Custom (SCA risk dashboard) |
| Wiz | API polling (issue counts, risk scores) | Webhook / API alert export | Custom (cloud security posture) |
| Intruder | API polling (scan stats, vuln counts) | Webhook events | Custom (external attack surface) |
Easiest monitoring integration: OpenVAS (syslog + API), Dependency-Track (webhooks + API), SonarQube (webhooks + API) – all self-hosted with well- documented APIs
CLI tools (Nuclei, Trivy, Grype, Nikto, Vuls, Lynis, OpenSCAP) require parsing JSON/SARIF output via Telegraf exec or Fluent Bit pipelines
Deployment & Scale
| Tool | Cloud | On-Prem | Agents | Agentless | Multi-Tenancy | API |
|---|---|---|---|---|---|---|
| OpenVAS / Greenbone | No (Enterprise appliance) | Yes | No | Yes (network scan) | Yes (Enterprise) | Yes (GMP XML, REST) |
| Nuclei | ProjectDiscovery Cloud | Yes (CLI) | No | Yes (network scan) | Yes (Cloud) | Yes (REST – Cloud) |
| OWASP ZAP | No | Yes (Desktop/Docker) | No | Yes (web scan) | No | Yes (REST) |
| Nikto | No | Yes (CLI) | No | Yes (web scan) | No | No |
| Trivy | Aqua platform | Yes (CLI/CI) | No | Yes (image/IaC scan) | No | No (CLI only) |
| Grype | Anchore Enterprise | Yes (CLI/CI) | No | Yes (image scan) | No | No (CLI only) |
| Clair | No | Yes (Docker/K8s) | No | Yes (image scan) | No | Yes (REST) |
| Dependency-Track | No | Yes (Docker/WAR) | No | Yes (SBOM analysis) | Yes (teams/permissions) | Yes (REST) |
| SonarQube Community | SonarCloud | Yes (Docker/ZIP) | No | Yes (source scan) | Yes (projects/orgs) | Yes (REST) |
| Vuls | No | Yes (CLI) | No | Yes (SSH-based scan) | No | No (CLI) |
| Lynis | Lynis Enterprise | Yes (CLI) | Yes (local execution) | No | Yes (Enterprise) | No (CLI) |
| OpenSCAP | No | Yes (CLI) | Yes (local execution) | No | No | No (CLI) |
| Archery | No | Yes (Docker) | No | Yes (aggregator) | Yes (projects) | Yes (REST) |
| Nessus / Tenable | Tenable.io (SaaS) | Yes (Nessus Pro) | Yes (Nessus Agent) | Yes (network scan) | Yes (Tenable.io) | Yes (REST) |
| Qualys VMDR | Yes (SaaS primary) | Yes (scanner appliance) | Yes (Qualys Agent) | Yes (network scan) | Yes (subscriptions) | Yes (REST) |
| Rapid7 InsightVM | InsightVM Cloud | Yes (console + engine) | Yes (Insight Agent) | Yes (network scan) | Yes (sites/asset groups) | Yes (REST) |
| CrowdStrike Spotlight | Yes (SaaS only) | No | Yes (Falcon sensor) | No (agent-based) | Yes (Flight Control) | Yes (REST) |
| Microsoft Defender VM | Yes (SaaS only) | No | Yes (Defender agent) | No (agent-based) | Yes (multi-tenant mgmt) | Yes (Graph API) |
| Orca Security | Yes (SaaS only) | No | No | Yes (agentless cloud) | Yes (multi-account) | Yes (REST) |
| Snyk | Yes (SaaS primary) | Yes (Snyk Broker) | No | Yes (SCM/CI scan) | Yes (orgs/groups) | Yes (REST) |
| Veracode | Yes (SaaS only) | No | No | Yes (binary/source) | Yes (teams/workspaces) | Yes (REST) |
| Acunetix | Yes (SaaS option) | Yes (on-prem) | No | Yes (web scan) | Yes (targets/groups) | Yes (REST) |
| Invicti (Netsparker) | Yes (SaaS option) | Yes (on-prem) | No | Yes (web scan) | Yes (teams/websites) | Yes (REST) |
| Burp Suite Pro | No (Enterprise: yes) | Yes (Desktop/CI) | No | Yes (web scan) | Yes (Enterprise) | Yes (REST – Enterprise) |
| HCL AppScan | Yes (SaaS option) | Yes (on-prem) | No | Yes (source/web scan) | Yes (apps/users) | Yes (REST) |
| Checkmarx | Yes (Checkmarx One) | Yes (on-prem) | No | Yes (source scan) | Yes (teams/projects) | Yes (REST) |
| Black Duck (Synopsys) | Yes (Polaris SaaS) | Yes (on-prem) | No | Yes (binary/source) | Yes (projects/groups) | Yes (REST) |
| Wiz | Yes (SaaS only) | No | No | Yes (agentless cloud) | Yes (multi-tenant) | Yes (REST + GraphQL) |
| Intruder | Yes (SaaS only) | No | No | Yes (external scan) | Yes (teams/targets) | Yes (REST) |
Self-hosted OSS: OpenVAS, OWASP ZAP, Dependency-Track, SonarQube, Archery, Clair
Agentless scanning: Orca, Wiz (cloud-native SideScanning / snapshot analysis – no agents on workloads)
Agent-based VM: CrowdStrike Spotlight and Microsoft Defender VM leverage existing EDR agents for vulnerability assessment (no separate scanner)
Tools
29 tools.
Acunetix
Acunetix is a web application vulnerability scanner specializing in Dynamic Application Security Testing (DAST).
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Archery
Archery (ArcherySec) is an open-source vulnerability assessment and management platform that aggregates results from multiple security scanning tools into a centralized dashboard.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none
Black Duck
Black Duck (formerly Black Duck Software, now part of Synopsys / recently divested) is an enterprise Software Composition Analysis (SCA) platform specializing in open-source security, license compliance, and software supply chain risk manag…
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Burp Suite Pro
Burp Suite is the industry-standard web security testing toolkit developed by PortSwigger. It provides an intercepting proxy, automated scanner, and extensive manual testing tools for web application security professionals.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: none
Checkmarx
Checkmarx is a leading application security testing platform providing SAST (Static Application Security Testing), SCA (Software Composition Analysis), DAST, API security testing, and supply chain security.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
Clair
Clair is an open-source container image vulnerability analysis tool originally developed by CoreOS (now Red Hat). It performs static analysis of container image layers to identify known vulnerabilities in OS packages.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none
CrowdStrike Falcon Spotlight
CrowdStrike Falcon Spotlight is a vulnerability assessment module within the CrowdStrike Falcon platform.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Dependency-Track
Dependency-Track is an open-source OWASP Software Composition Analysis platform that consumes SBOMs (CycloneDX, SPDX) and continuously monitors components for known vulnerabilities and license risks.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: none
Grype
Grype is an open-source vulnerability scanner for container images and filesystems, developed by Anchore.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
HCL AppScan
HCL AppScan is an enterprise application security testing platform providing DAST (Dynamic Analysis), SAST (Static Analysis), IAST (Interactive Analysis), and SCA (Software Composition Analysis).
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Intruder
Intruder is a cloud-based automated vulnerability scanning platform designed for small to mid-size businesses (SMBs) and development teams.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Invicti
Invicti (formerly Netsparker) is an enterprise web application security platform providing automated DAST and IAST scanning with a unique Proof-Based Scanning technology.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Lynis
Lynis is an open-source security auditing and hardening tool for Unix-based systems including Linux, macOS, and BSD.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management (MDVM), formerly Threat and Vulnerability Management (TVM), is a built-in vulnerability management capability within Microsoft Defender for Endpoint.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Nessus / Tenable
Nessus is the market-leading vulnerability scanner, originally created in 1998 by Renaud Deraison and now developed by Tenable.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Nikto
Nikto is an open-source web server scanner that performs comprehensive tests against web servers for dangerous files, outdated software versions, server misconfigurations, and CGI vulnerabilities.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Nuclei
Nuclei is a fast, open-source template-driven vulnerability scanner from ProjectDiscovery, using YAML templates across HTTP, DNS, TCP, and other protocols with a large community template library.
License: MIT (OSS) · Kind: web · Deploy: native · SSO: none
OpenSCAP
OpenSCAP is an open-source implementation of the Security Content Automation Protocol (SCAP) standards maintained by NIST.
License: LGPL-2.1-or-later (OSS) · Kind: web · Deploy: native · SSO: none
OpenVAS / Greenbone
OpenVAS (Open Vulnerability Assessment Scanner) is the open-source vulnerability scanning engine at the core of the Greenbone Vulnerability Management (GVM) framework.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Orca Security
Orca Security is an agentless cloud security platform (CNAPP) that provides vulnerability management, misconfiguration detection, malware scanning, lateral movement risk analysis, and compliance checking across AWS, Azure, GCP, and Alibaba…
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
OWASP ZAP
OWASP ZAP (Zed Attack Proxy) is the world’s most widely used open-source web application security scanner.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
Qualys VMDR
Qualys VMDR (Vulnerability Management, Detection, and Response) is a cloud-based vulnerability management platform that provides asset discovery, vulnerability assessment, prioritization, and remediation tracking in a unified workflow.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Rapid7 InsightVM
Rapid7 InsightVM is a vulnerability management solution built on the Nexpose scan engine with cloud-based analytics and live dashboards via the Rapid7 Insight Platform.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Snyk
Snyk is a developer-first security platform providing Software Composition Analysis (SCA), Static Application Security Testing (SAST), container image scanning, and Infrastructure as Code (IaC) security testing.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
SonarQube Community
SonarQube Community Edition is an open-source platform for continuous code quality and security analysis.
License: LGPL-3.0-or-later (OSS) · Kind: web · Deploy: native, docker · SSO: SAML
Trivy
Trivy is a comprehensive open-source security scanner developed by Aqua Security. It detects vulnerabilities, misconfigurations, secrets, and license issues across container images, filesystems, Git repositories, Kubernetes clusters, and Ia…
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
Veracode
Veracode is an enterprise application security testing platform providing SAST (Static Analysis), DAST (Dynamic Analysis), SCA (Software Composition Analysis), manual penetration testing, and compliance reporting.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Vuls
Vuls (VULnerability Scanner) is an open-source agentless vulnerability scanner for Linux and FreeBSD systems.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Wiz
Wiz is a cloud security platform (CNAPP) providing agentless vulnerability management, cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), container security, Kubernetes security posture management…
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC