IT tool directory

Explore IT tools

Filter by deployment, source model and use case.

Refine results
Refine resultsClear all
Category
Deployment
Source model
Pricing model

7 results

Contrast Security, founded by OWASP co-creator Jeff Williams, instruments applications with in-app sensors: Contrast Assess (IAST) and Scan (SAST) find vulnerabilities, Contrast SCA flags risky dependencies, and its ADR/RASP layer detects and blocks attacks in production.

Application SecuritySelf-hostedOther license
Detectify

Detectify combines automated DAST scanning with crowdsourced vulnerability research to monitor internet-facing assets and web apps for exploitable issues.

Application SecurityOther license
ImmuniWeb

ImmuniWeb offers AI-assisted penetration testing, continuous application testing, attack surface discovery and dark web monitoring, plus free Community Edition tools.

Application SecurityOther license
Mend.io

Mend.io (formerly WhiteSource) pioneered software composition analysis and now covers SCA, SAST, container scanning, dependency updates (Mend Renovate), and AI security — red-teaming and runtime guardrails for LLM-based applications.

Application SecuritySelf-hostedOther license
Rapid7

Rapid7 helps security teams find vulnerabilities, assess exposure and investigate threats across its distinct products.

Application SecurityOther license
Snyk

Snyk scans open-source dependencies, code, containers and infrastructure-as-code for vulnerabilities, built into IDEs, CLI and CI/CD pipelines.

Application SecurityWebOther license
Veracode

Veracode supplies application security testing for proprietary code and open-source components.

Application SecurityOther license
CompareTool and summaryCategoryDeploymentSource model
Contrast SecurityContrast Security, founded by OWASP co-creator Jeff Williams, instruments applications with in-app sensors: Contrast Assess (IAST) and Scan (SAST) find vulnerabilities, Contrast SCA flags risky dependencies, and its ADR/RASP layer detects and blocks attacks in production.Application SecuritySelf-hostedOther license
DetectifyDetectify combines automated DAST scanning with crowdsourced vulnerability research to monitor internet-facing assets and web apps for exploitable issues.Application SecurityOther license
ImmuniWebImmuniWeb offers AI-assisted penetration testing, continuous application testing, attack surface discovery and dark web monitoring, plus free Community Edition tools.Application SecurityOther license
Mend.ioMend.io (formerly WhiteSource) pioneered software composition analysis and now covers SCA, SAST, container scanning, dependency updates (Mend Renovate), and AI security — red-teaming and runtime guardrails for LLM-based applications.Application SecuritySelf-hostedOther license
Rapid7Rapid7 helps security teams find vulnerabilities, assess exposure and investigate threats across its distinct products.Application SecurityOther license
SnykSnyk scans open-source dependencies, code, containers and infrastructure-as-code for vulnerabilities, built into IDEs, CLI and CI/CD pipelines.Application SecurityWebOther license
VeracodeVeracode supplies application security testing for proprietary code and open-source components.Application SecurityOther license