vulnerable-node alternatives

Looking for a better tool, or simply want to learn about alternatives? There is typically more than one option.

Alternatives (by tag)

64

Alternative: Susanoo

Susanoo is a security tool to test the security of a REST API. With this focus, it goes beyond the typical attack surface of a web application.

Project details

Susanoo is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • API testing
  • application testing

Susanoo project page

68

Alternative: arch-audit

Utility like pkg-audit for Arch Linux to find vulnerable packages on the system

The arch-audit utility scans the system for known vulnerabilities. It does so by looking at the version of installed packages and compare them with a database of known vulnerable versions.

Project details

arch-audit is written in Rust.

Strengths

  • + The source code of this software is available

Typical usage

  • vulnerability scanning

arch-audit project page

64

Alternative: CMSmap

CMSmap is a security tool to perform reconnaissance on a web target. It helps with the detection of several popular content management systems (CMS).

Project details

CMSmap is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • application testing
  • information gathering
  • vulnerability scanning
  • web application analysis

CMSmap project page

97

Alternative: detectem

Detectem can scan web applications and detect used software components like jQuery, Apache middleware, and others.

Project details

detectem is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • application security
  • application testing
  • reconnaissance
  • vulnerability scanning

detectem project page

52

Alternative: Glastopf

Glastopf is a honeypot for web applications. It is written in Python and collects all kind of attacks against it for further analysis.

Glastopf emulates vulnerabilities in a generic way. Instead of emulating specific vulnerabilities, it mimics being vulnerable for more attacks within that area (e.g. Remote File Inclusion). The tool is modular and allows to be extended with different logging capabilities.

This project is replaced by SNARE.

52

Alternative: graudit

Graudit is a security tool to perform static code analysis by using the grep tool. It is a lightweight solution to find common issues in code.

Project details

graudit is written in shell script.

Strengths

  • + Used language is shell script
  • + The source code of this software is available

Typical usage

  • code analysis

graudit project page

64

Alternative: Jackhammer

Jackhammer is a collaboration tool to get security and developer teams together. Focus is on static code analysis and dynamic analysis vulnerability discovery.

The tool uses RBAC (Role Based Access Control) with different levels of access. Jackhammer uses several tools to do dynamic and static code analysis (e.g. for Java, Ruby, Python, and Nodejs). It checks also for vulnerabilities in libraries. Due to its modular architecture, it can use several scanners out of the box, with options to add your own.

The Jackhammer project was initially added to GitHub on the 8th of May, 2017.

Project details

Jackhammer is written in Ruby.

Strengths

  • + The source code of this software is available

Typical usage

  • collaboration
  • information sharing

Jackhammer project page

64

Alternative: Pompem

Pompem is an open source security tool to automate the search for exploits and vulnerabilities in public databases.

Pompem is written in Python and helps pentesters to search public sources for vulnerability information and a related exploit.

Sources

  • CXSecurity
  • National Vulnerability Database
  • PacketStorm security
  • Vulners
  • WPScan Vulnerability Database
  • ZeroDay

Project details

Pompem is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • vulnerability scanning

Pompem project page

64

Alternative: Spaghetti

Spaghetti is a web vulnerability scanner to find flaws in common web applications and frameworks. It can perform fingerprinting and vulnerability discovery.

Project details

Spaghetti is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • penetration test
  • vulnerability scanning
  • vulnerability testing

Spaghetti project page

100

Alternative: vFeed

vFeed is a set of tools around correlated vulnerability and threat intelligence. It provides a database, API, and supporting tools to store vulnerability data.

vFeed consists of a database and utilities to store vulnerability data. It uses third-party references and data, which then can be used to see if a software component has a known vulnerability. The data itself is enriched by cross-checking it and store additional details about the vulnerabilities.

The vFeed tooling has an API available with JSON output. It can be used by security researchers and practitioners to validate vulnerabilities and retrieve all available details.

Project details

vFeed is written in Python.

Strengths

  • + Commercial support available

Typical usage

  • security assessment
  • vulnerability scanning

vFeed project page

64

Alternative: vulnix

Vulnix is a security scanner for NixOS. It specifically looks for vulnerabilities in available packages and comes with a command line interface (CLI).

Project details

vulnix is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • vulnerability scanning

vulnix project page

89

Alternative: Vuls

Vuls is a vulnerability scanner for Linux and FreeBSD. It is written in Go, agentless, and does a remote login to find any software vulnerabilities.

Project details

Vuls is written in Golang.

Strengths

  • + More than 50 contributors
  • + More than 4000 GitHub stars
  • + The source code of this software is available

Typical usage

  • system hardening
  • vulnerability scanning

Vuls project page

64

Alternative: Damn Small Vulnerable Web (DSVW)

Project details

Damn Small Vulnerable Web is written in Python.

Strengths

  • + The source code of this software is available

Typical usage

  • learning

Damn Small Vulnerable Web project page

64

Alternative: Wordstress

Wordstress is a security scanner for WordPress installations. It uses a white-box approach in scanning, which makes it different than most other scanners.

Project details

Wordstress is written in Ruby.

Strengths

  • + The source code of this software is available

Typical usage

  • application security
  • vulnerability scanning
  • web application analysis

Wordstress project page