# Security Scanners

At AquilaX, we believe a top-notch Application Security and DevSecOps program should leverage the best of today’s trusted, mature open-source scanners. We openly showcase each scanner we use, allowing our clients to see exactly how we’re protecting their code. And for those needing more, we also integrate and offer a full range of both private and open-source scanners to cover all bases in application security.

<table><thead><tr><th>Logo</th><th width="163" data-type="content-ref"></th><th width="119">License</th><th>Used for</th></tr></thead><tbody><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-caecbb45ced44b8cc6612c007952fd27ed242999%2Fcheckov_blue_logo.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/bridgecrewio/checkov">https://github.com/bridgecrewio/checkov</a></td><td>Apache 2.0</td><td>Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-71514762c41418813a0881042343e8d3ad9f9a5b%2Fgosec.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/securego/gosec">https://github.com/securego/gosec</a></td><td>Apache 2.0</td><td>Go security checker</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-08943b5accaaddbf584857f8e146cd16a9ab839a%2Flogo%20(1)%20(2).png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/aquasecurity/trivy">https://github.com/aquasecurity/trivy</a></td><td>Apache 2.0</td><td>Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-d455910f403b78970af07896c0cf7ea7c6d6b245%2Fcatchit-logo.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/finos/CatchIT">https://github.com/finos/CatchIT</a></td><td>Apache 2.0</td><td>Source code secret scanner by Goldman Sachs and FINOS</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-0bbcd2b22d83695d0616e2b1099fa52b9cbe8972%2F136844524-1527b09f-c5cb-4aa9-be54-5aa92a6086c1.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/anchore/syft">https://github.com/anchore/syft</a></td><td>Apache 2.0</td><td>CLI tool and library for generating a Software Bill of Materials from container images and filesystems</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-ea396b784be8fb8cc8917a3b92b09e5d6eb2349f%2F6641b54f4d44572dd06bad9d_npm.png?alt=media" alt="" data-size="original"></td><td><a href="https://docs.npmjs.com/cli/v9/commands/npm-audit">https://docs.npmjs.com/cli/v9/commands/npm-audit</a></td><td></td><td>The audit command submits a description of the dependencies configured in your project to your default registry and asks for a report of known vulnerabilities.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-c15006c16c77911882d19b82f5937fdc53851687%2F1_1d9SUqEtHUGx7IJ-ZWp2fg.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/gitleaks/gitleaks">https://github.com/gitleaks/gitleaks</a></td><td>MIT</td><td>Protect and discover secrets using Gitleaks 🔑</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-7d339a950b02c5136b0c1a17f570b38832ce9119%2F49071.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/Yelp/detect-secrets">https://github.com/Yelp/detect-secrets</a></td><td>Apache 2.0</td><td>An enterprise friendly way of detecting and preventing secrets in code.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-5670dc629ae0cf2cf226d1e8482e4ee6ff1b8634%2FScreenshot%202024-11-02%20at%2000.28.14.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></td><td>Apache 2.0</td><td>Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-9ae6f598fc49229cb7d7ac4f2be5216f74af08a4%2FScreenshot%202024-11-02%20at%2000.30.21.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/aquasecurity/chain-bench">https://github.com/aquasecurity/chain-bench</a></td><td>Apache 2.0</td><td>An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-105dd0970ebefc59fb2c217d04227766562b6e1c%2Fkics_new_logo_2022_dark.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/Checkmarx/kics">https://github.com/Checkmarx/kics</a></td><td>Apache 2.0</td><td>Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-85f1d2273fa87220135e3c5abc84b8fe2a092680%2Flogotype-sm.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/PyCQA/bandit">https://github.com/PyCQA/bandit</a></td><td>Apache 2.0</td><td>Bandit is a tool designed to find common security issues in Python code.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-01db89d88483082bfa6f888ae0b6707c0458b09c%2Flogo.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/facebook/pyre-check">https://github.com/facebook/pyre-check</a></td><td>MIT</td><td>Performant and security type-checking for python.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-ca95181e0053aa10915d936dd740a3f1df754dea%2F68747470733a2f2f63617375616c2d686f7374696e672e73332e616d617a6f6e6177732e636f6d2f6b7562657365632d6c6f676f2e706e67.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/controlplaneio/kubesec">https://github.com/controlplaneio/kubesec</a></td><td>Apache 2.0</td><td>Security risk analysis for Kubernetes resources</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-b8f752b21dcc64c468f98212b7e4f6feabdb7fab%2Fdc.svg?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/jeremylong/DependencyCheck">https://github.com/jeremylong/DependencyCheck</a></td><td>Apache 2.0</td><td>OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-e865ace9e24af8206880d2bf29fcbbb6e3332a26%2Fhorusec_logo.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/ZupIT/horusec">https://github.com/ZupIT/horusec</a></td><td>Apache 2.0</td><td>Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-b562cdb2626131b145fbe1ca8854c68a2c0eb273%2FScreenshot%202024-11-02%20at%2001.08.54.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/nccgroup/sobelow">https://github.com/nccgroup/sobelow</a></td><td>Apache 2.0</td><td>Sobelow is a security-focused static analysis tool for Elixir &#x26; the Phoenix framework.</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-bdbb3fadd41df53c3bb50346050edf246eb09417%2F68747470733a2f2f75706c6f6164732d73736c2e776562666c6f772e636f6d2f3634393264623836643533663834663339366236363233642f3634646164366331326239386465653035656230383038385f6e756c6c6966792532306c6f676f2e706e67.png?alt=media" alt="" data-size="original"></td><td><a href="https://github.com/Nullify-Platform/attack-surface-scanner">https://github.com/Nullify-Platform/attack-surface-scanner</a></td><td>MIT</td><td>Web application attack surface scanner by Nullify</td></tr><tr><td><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fgit-blob-4182e2c586c999713d5dec6d87daa70dc2764f44%2FScreenshot%202024-11-20%20at%2012.34.57.png?alt=media" alt="" data-size="original"></td><td><a href="https://google.github.io/osv-scanner/">https://google.github.io/osv-scanner/</a></td><td>Apache 2.0</td><td>Vulnerability scanner written in Go which uses the data provided by <a href="https://osv.dev/">https://osv.dev</a><br></td></tr><tr><td><div><figure><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2Fne7bcA1zC0fsmwKKemTO%2FScreenshot%202025-12-30%20at%2016.00.19.png?alt=media&#x26;token=b5b196aa-0cd2-421a-aa88-8a4911da51e0" alt=""><figcaption></figcaption></figure></div><p></p></td><td><a href="https://vulnix0.com/">https://vulnix0.com/</a></td><td>Proprietary </td><td>Offensive Security Platform<br><a href="https://vulnix0.com/">https://vulnix0.com/</a></td></tr><tr><td><div><figure><img src="https://53914109-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjAmSnvnfbHl4EDK56iDo%2Fuploads%2FlqYnahHeLdyH059Dg1iL%2FScreenshot%202025-12-30%20at%2016.01.20.png?alt=media&#x26;token=ee9d6483-8fa3-47e1-a55d-83844e8291e9" alt=""><figcaption></figcaption></figure></div><p></p></td><td><a href="https://github.com/opengrep/opengrep">https://github.com/opengrep/opengrep</a></td><td>LGPL-2.1 license</td><td>Static code analysis engine to find security issues in code.</td></tr></tbody></table>
