OpenSCAP alternatives

Looking for a better tool, or simply want to learn about alternatives? There is typically more than one option.

Alternatives (by tag)

64

Alternative: JShielder

JShielder is a security tool for Linux systems to make them more secure by adding system hardening measures.

Project details

JShielder is written in Python, shell script.

Strengths

  • + Used language is shell script
  • + The source code of this software is available

Typical usage

  • system hardening

JShielder project page

64

Alternative: LUNAR

LUNAR is a security scanner that runs on a Linux system or other flavors of Unix. It provides insights on what can be done to harden the system.

LUNAR is short for Lockdown UNix Auditing and Reporting and runs on the system itself.

Project details

LUNAR is written in shell script.

Strengths

  • + The source code of this software is available

Typical usage

  • security assessment
  • self-assessment
  • system hardening

LUNAR project page

100

Alternative: Lynis

Security auditing tool for systems running Linux or Unix-based to perform an in-depth health check.

Lynis is an open source security auditing tool that is available since 2007 and created by Michael Boelen. Its primary goal is to evaluate the security defenses of systems running Linux or other flavors of Unix. It provides suggestions to install, configure, or correct any security measures.

Project details

Lynis is written in shell script.

Strengths

  • + Commercial support available
  • + More than 50 contributors
  • + More than 3000 GitHub stars
  • + Used language is shell script
  • + Very low number of dependencies
  • + Project is mature (5+ years)
  • + The source code of this software is available

Typical usage

  • IT audit
  • penetration test
  • security assessment
  • system hardening

Lynis project page

76

Alternative: Nix-Auditor

Nix-Auditor is a tool to help with scanning Linux systems and test them against CIS benchmarks.

This fairly new tool is written in shell script to scan Linux systems with the focus on security auditing.

Project details

Nix-Auditor is written in shell script.

Strengths

  • + Used language is shell script

Weaknesses

  • - Full name of author is unknown
  • - Unknown project license

Nix-Auditor project page

64

Alternative: seccheck

Seccheck is a security scanner for Linux systems. It is originally written for SuSE Linux by Marc Heuse.

Project details

seccheck is written in shell script.

Strengths

  • + The source code of this software is available

Weaknesses

  • - Project looks outdated (old code or documentation)

Typical usage

  • security assessment
  • system hardening

seccheck project page

100

Alternative: Anchore

Anchore is a security tool to perform container analysis, inspect and control them.

Project details

Anchore is written in Python.

Strengths

  • + Commercial support available
  • + The source code of this software is available

Anchore project page

64

Alternative: AutoNessus (autonessus)

The AutoNessus tool helps with automating vulnerability scans via the Nessus API. It lists policies and can configure the state of scans.

This tool is useful to time scans, for example by having it run outside of business hours, and stop when the day starts.

Note: originally another tool was named AutoNessus. That is now Seccubus.

Project details

AutoNessus is written in Python.

Strengths

  • + The source code of this software is available

Weaknesses

  • - No releases on GitHub available

Typical usage

  • vulnerability scanning

AutoNessus project page

64

Alternative: CMSmap

CMSmap is a security tool to perform reconnaissance on a web target. It helps with the detection of several popular content management systems (CMS).

Project details

CMSmap is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • application testing
  • information gathering
  • vulnerability scanning
  • web application analysis

CMSmap project page

64

Alternative: Damn Small FI Scanner (DSFS)

Project details

Damn Small FI Scanner is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • security assessment
  • vulnerability scanning

Damn Small FI Scanner project page

64

Alternative: Damn Small JS Scanner (DSJS)

Project details

Damn Small JS Scanner is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • penetration test
  • security assessment

Damn Small JS Scanner project page

64

Alternative: Jackhammer

Jackhammer is a collaboration tool to get security and developer teams together. Focus is on static code analysis and dynamic analysis vulnerability discovery.

The tool uses RBAC (Role Based Access Control) with different levels of access. Jackhammer uses several tools to do dynamic and static code analysis (e.g. for Java, Ruby, Python, and Nodejs). It checks also for vulnerabilities in libraries. Due to its modular architecture, it can use several scanners out of the box, with options to add your own.

The Jackhammer project was initially added to GitHub on the 8th of May, 2017.

Project details

Jackhammer is written in Ruby.

Strengths

  • + The source code of this software is available

Typical usage

  • collaboration
  • information sharing

Jackhammer project page

74

Alternative: Nikto

Nikto is an open source security scanner which tests web servers for potential vulnerabilities.

Nikto helps with performing security scans against web servers and to search for vulnerabilities in web applications.

Note: the data files of Nikto are not released under GPL. Embedding them in your projects may require permission of the author.

Project details

Nikto is written in Perl.

Strengths

  • + The source code of this software is available
  • + Well-known tool

Typical usage

  • penetration test
  • security assessment
  • web application analysis

Nikto project page

93

Alternative: Nmap

Nmap is a security scanner that can perform a port scan, network exploration, and determine vulnerabilities

Nmap is short for "Network Mapper". It is a free and open source utility for network discovery and security auditing. It was release in September of 1997 by Gordon Lyon, commonly known under his pseudonym "Fyodor".

Project details

Nmap is written in C, C++, Lua, Python.

Strengths

  • + Project is mature (10+ years)
  • + Project is mature (5+ years)
  • + The source code of this software is available

Nmap project page

85

Alternative: OpenVAS

OpenVAS is a framework of several services and tools offering a vulnerability scanning and vulnerability management solution.

OpenVAS is an open source vulnerability scanner that emerged from when Nessus became closed source in October of 2005.

Project details

OpenVAS is written in C.

Strengths

  • + The source code of this software is available
  • + Well-known tool

Typical usage

  • penetration test
  • security assessment
  • vulnerability scanning

OpenVAS project page

97

Alternative: Seccubus

Seccubus automates vulnerability scanning with support for Nessus, OpenVAS, NMap, SSLyze, Medusa, SkipFish, OWASP ZAP, and SSLlabs.

Supported engines and tools:

  • Nessus
  • OpenVAS
  • Nmap
  • Nikto
  • Medusa
  • Qualys SSL labs
  • SkipFish
  • SSLyze
  • testssl.sh
  • ZAP

96

Alternative: sqlmap

The sqlmap performs automatic SQL injection and can take over a database. It is a valued tool for pentesters and those who want to test their web applications.

85

Alternative: ssh_scan

The ssh_scan utility is a SSH configuration and policy scanner maintained by the Mozilla Foundation. It helps to secure Linux systems running the OpenSSH.

This tool is light on its dependencies, as it only uses Ruby and BinData. The scanner is simple to use, as it is limited in the number of parameters and options. There is also the ability to show the results on the screen or export the data to a JSON file. The latter is great if you want to do further processing of the details, or simply store them for later comparison.

Project details

ssh_scan is written in Ruby.

Strengths

  • + The source code of this software is available
  • + Supported by a large company

Weaknesses

  • - More than 10 contributors

Typical usage

  • penetration test
  • security assessment
  • system hardening
  • vulnerability scanning

ssh_scan project page

76

Alternative: testssl.sh

testssl.sh is a command line tool which checks a system on any port for the support of TLS/SSL ciphers, protocols, as well as some cryptographic flaws.

Key features of testssl.sh include:

  • Clear output: you can tell easily whether anything is good or bad
  • Ease of installation: It works for Linux, Darwin, FreeBSD, NetBSD and MSYS2/Cygwin out of the box: no need to install or configure something, no gems, CPAN, pip or the like.
  • Flexibility: You can test any SSL/TLS enabled and STARTTLS service, not only webservers at port 443
  • Toolbox: Several command line options help you to run YOUR test and configure YOUR output
  • Reliability: features are tested thoroughly
  • Verbosity: If a particular check cannot be performed because of a missing capability on your client side, you'll get a warning
  • Privacy: It's only you who sees the result, not a third party
  • Freedom: It's 100% open source. You can look at the code, see what's going on and you can change it.

Project details

testssl.sh is written in shell script.

Strengths

  • + Used language is shell script
  • + Well-known tool

testssl.sh project page

64

Alternative: Vane

Vane is a forked project of the now non-free popular WordPress vulnerability scanner WPScan.

Project details

Vane is written in Ruby.

Strengths

  • + More than 25 contributors
  • + The source code of this software is available

Typical usage

  • application security
  • web application analysis

Vane project page

64

Alternative: vulnix

Vulnix is a security scanner for NixOS. It specifically looks for vulnerabilities in available packages and comes with a command line interface (CLI).

Project details

vulnix is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • vulnerability scanning

vulnix project page

88

Alternative: Vuls

Vuls is a vulnerability scanner for Linux and FreeBSD. It is written in Go, agentless, and does a remote login to find any software vulnerabilities.

Project details

Vuls is written in Golang.

Strengths

  • + More than 50 contributors
  • + More than 4000 GitHub stars
  • + The source code of this software is available

Typical usage

  • system hardening
  • vulnerability scanning

Vuls project page

100

Alternative: WPScan

WPScan is a security tool to perform black box WordPress vulnerability scans, including enumeration of used plugins

Project details

WPScan is written in Ruby.

Strengths

  • + More than 25 contributors
  • + More than 2000 GitHub stars
  • + The source code of this software is available

Weaknesses

  • - Software usage is restricted (e.g. commercially)

Typical usage

  • penetration test
  • security assessment
  • vulnerability scanning

WPScan project page

78

Alternative: WPSeku

WPSeku is a WordPress vulnerability scanner that can be used to scan remote WordPress installations.

With WPSeku a WordPress installation can be tested for the presence of security issues. Some examples are cross-site scripting (XSS), sql injection, and local file inclusion. The tool also tests for the presence of default configuration files. These files may reveal version numbers, used themes and plugins.

Project details

WPSeku is written in Python.

Strengths

  • + The source code of this software is available

Weaknesses

  • - Unknown project license

Typical usage

  • penetration test
  • security assessment
  • vulnerability scanning

WPSeku project page

64

Alternative: wpvulndb_cmd

wpvulndb_cmd is a command-line security tool to perform a vulnerability scan on WordPress installations. It uses WP-CLI and the WPScan vulnerability database.

Project details

wpvulndb_cmd is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • penetration test
  • security assessment
  • web application analysis

wpvulndb_cmd project page

78

Alternative: XSS Hunter

XSS Hunter helps with finding XSS attacks and trigger a warning when one is succesful. It exists as an online service, or self-hosted installation.

By using a specific link, XSS Hunter can see when some attack successfully is triggered. It will then store information like the vulnerable page's URI, referer, HTML DOM, the screenshot of page, and cookies. Regarding the victim, it stores the IP address and the user agent.

67

Alternative: YASAT

YASAT describes itself as another simple stupid audit tool to test Linux systems. It has many tests for checking the security configuration of the system.

The YASAT tool performs a system scan to detect configuration issues and possible improvements for hardening the system.

Project details

YASAT is written in shell script.

Strengths

  • + Used language is shell script

Weaknesses

  • - No updates for a while

Typical usage

  • IT audit
  • security assessment

YASAT project page

78

Alternative: Zenmap

The graphical user interface for the well-known network and vulnerability scanner nmap.

Zenmap is a graphical user interface (GUI) for Nmap. It can be of great help to start a network scan by simply selecting the options you want. Besides Linux, it also runs on Microsoft Windows, macOS, BSD, and other flavors of Unix.

One of the strengths of Zenmap is the ability to store profiles, which can be reused for later scans. The command creator is another one, which helps interactively create the right nmap commands. Recent scans are stored in a searchable database and scan results can be saved and compared.

Project details

Zenmap is written in Python.

Strengths

  • + The source code of this software is available
  • + Well-known tool

Typical usage

  • penetration test
  • security assessment

Zenmap project page