Skip to main content

Tools Used

DeepTraQ integrates multiple open-source security tools and proprietary scanners across its security modules to detect vulnerabilities, misconfigurations, and security risks.


Network Perimeter Scanning

ToolPurposeReferences
NmapNetwork discovery and port/service detectionhttps://github.com/nmap/nmap
https://nmap.org/docs.html
OpenVASVulnerability scanning for network services and systemshttps://www.openvas.org/
https://github.com/greenbone/openvas-scanner
NucleiTemplate-based vulnerability detectionhttps://docs.projectdiscovery.io/opensource/nuclei/overview
https://github.com/projectdiscovery/nuclei

Web Application Scanning

ToolPurposeReferences
OWASP ZAPDynamic web application security testinghttps://www.zaproxy.org/docs/
https://github.com/zaproxy/zaproxy
NucleiTemplate-based vulnerability detectionhttps://docs.projectdiscovery.io/opensource/nuclei/overview
https://github.com/projectdiscovery/nuclei
OpenAPI FuzzerAPI fuzz testing for OpenAPI/Swagger endpointshttps://github.com/zaproxy/community-scripts
SSLyze / SSL TestingSSL/TLS configuration analysishttps://github.com/testssl/testssl.sh

Code Scanning

ToolPurposeReferences
OSV ScannerDetects vulnerable open-source dependencieshttps://github.com/google/osv-scanner
DeepTraQ Proprietary ScannerStatic code analysis and security checksDeepTraQ internal engine
GitleaksDetects exposed secrets in repositorieshttps://github.com/gitleaks/gitleaks
KICSInfrastructure-as-Code security scanninghttps://github.com/Checkmarx/kics

Cloud Workload Scanning

ToolPurposeReferences
OpenVASDetect vulnerabilities in workload operating systemshttps://www.openvas.org/
https://github.com/greenbone/openvas-scanner
NmapDiscover services and exposed ports on workloadshttps://github.com/nmap/nmap
https://nmap.org/docs.html
NucleiTemplate-based vulnerability detectionhttps://docs.projectdiscovery.io/opensource/nuclei/overview
https://github.com/projectdiscovery/nuclei

Cloud Security Posture Management (CSPM)

ToolPurposeReferences
ProwlerCloud configuration and compliance auditinghttps://docs.prowler.com/introduction
https://github.com/prowler-cloud/prowler