DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture.
Principalele funcționalități ale defectdojo/django-defectdojo sunt: Vulnerability Management, Vulnerability Management Systems, Relational Inventory Schemas, Scan Data Importers, External Security Tool Integrations, REST APIs, Security Posture Dashboards, Security Metrics Dashboards.
Alternativele open-source pentru defectdojo/django-defectdojo includ: infobyte/faraday — Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… dependencytrack/dependency-track — Dependency-Track is a software composition analysis tool and vulnerability management system designed to track… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… keygraphhq/shannon — Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis,…
Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag
Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc