Skip to main content

Supported Scans

DeepTraQ supports multiple security scanning modules designed to identify vulnerabilities across infrastructure, applications, source code, and cloud environments. Each module integrates specialized security engines to provide comprehensive coverage.

Network Perimeter Scanning

Network perimeter scanning identifies exposed services, open ports, and infrastructure vulnerabilities on publicly accessible assets.

Capabilities

  • Port discovery
  • Service detection
  • Vulnerability identification on exposed services
  • Detection of misconfigured or outdated network services

Scanning Engines

EnginePurpose
OpenVASInfrastructure vulnerability scanning
NmapPort scanning and service detection
NucleiTemplate-based vulnerability scanning

Supported Targets

  • Public IP addresses
  • Public hostnames

Web Application Scanning

Web application scanning detects vulnerabilities in web applications, APIs, and web services.

Capabilities

  • Authenticated web application scanning
  • Unauthenticated web application scanning
  • API testing
  • Automated vulnerability detection

Scanning Engines

EnginePurpose
ZAPAuthenticated and unauthenticated web application scanning
OpenAPI FuzzerAPI fuzzing and endpoint testing
NucleiWeb vulnerability detection using security templates

Supported Targets

  • Web applications
  • REST APIs
  • OpenAPI-based services

Code Scanning

Code scanning analyzes application source code and dependencies to identify security issues, secrets, and vulnerable libraries.

Capabilities

  • Secret detection in source code
  • Infrastructure as Code (IaC) security checks
  • Dependency vulnerability scanning
  • Static code vulnerability analysis

Scanning Engines

EnginePurpose
GitleaksSecret scanning
KICSInfrastructure as Code security scanning
OSV ScannerOpen-source dependency vulnerability detection
DeepTraQ Code EngineProprietary code vulnerability detection

CSPM (Cloud Security Posture Management)

CSPM scans cloud environments to identify security misconfigurations and compliance violations.

Capabilities

  • Cloud configuration auditing
  • Security posture assessment
  • Detection of insecure cloud settings

Scanning Engine

EnginePurpose
ProwlerCloud configuration auditing and security checks

Supported Cloud Providers

  • AWS
  • Microsoft Azure
  • Google Cloud Platform
  • Oracle Cloud

Cloud Workload Scanning

Cloud workload scanning identifies vulnerabilities in virtual machines running in cloud environments.

DeepTraQ synchronizes virtual machine inventories from cloud providers and performs vulnerability scanning as part of infrastructure assessments.

Capabilities

  • Automatic virtual machine discovery
  • Infrastructure vulnerability scanning
  • Unified vulnerability reporting

Supported Cloud Providers

  • AWS
  • Azure
  • Google Cloud Platform

Limitations

AreaLimitation
Cloud workload syncCurrently only virtual machines can be synchronized from cloud providers.
Web application scanningHAR file support for deep API discovery in SPA applications is not available yet.
Code scanningC++ is not currently supported.
CI/CD integrationDirect CI/CD pipeline integrations are not available yet.
Local scanningLocal agents for scanning internal networks or development environments are not available yet.