Scanner Integrations

Integrate Your Scanners with ThreadFix


Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits web applications by checking for vulnerabilities accessible via web browser.


Arachni is a Ruby framework that helps penetration testers and administrators gauge web application security.


Barracuda Vulnerability Manager is a free service that detects web application vulnerabilities and helps you remediate them automatically.

Image result for black duck logo

Black Duck integrates with ThreadFix to automatically scan, identify and inventory open source software, allowing you to understand license obligations, conflicts and risks.


Brakeman is an open source static analysis vulnerability scanner tailored for Ruby on Rails applications designed to spot security vulnerabilities.

Logo_Horizontal__RGB no tagline_no shadow

Checkmarx’s CxSAST is a tool that discovers and documents application layer security vulnerabilities.


Contrast IAST Scanner Integration uses sensors to passively monitor the behavior of applications and discover vulnerabilities quickly and accurately.


FindBugs is a static analysis open source program that detects bugs in Java code.

IBM Application Security on Cloud (ASoC) is a cloud app security offering that helps secure your organization’s Web, cloud, mobile, and other applications.

IBM AppScan Enterprise mitigates application security risk, strengthen application security program management initiatives and achieve regulatory compliance.

IBM AppScan Source identifies web-based and mobile application source code vulnerabilities early in the software development cycle, so they can be fixed before deployment.

IBM AppScan Standard Integration ThreadFix allows IBM AppScan users to import and track AppScan DAST results and merge DAST and SAST scan results. LEARN MORE

Image result for microfocus logo

Micro Focus Fortify SCA Integration Maximize your investment in HP Fortify by integrating with ThreadFix to import and merge scan results and schedule regular scans. LEARN MORE

Image result for microfocus logo

Micro Focus WebInspect Integration Use HP WebInspect with ThreadFix to merge and track SAST and DAST scan results. LEARN MORE


Netsparker Integration Import and track Netsparker DAST results and merge DAST and SAST scan results with the ThreadFix NetSparker integration. LEARN MORE


OWASP Dependency Check identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities.


OWASP ZAP Integration Import scan results, merge them with other scanning results and track the results of scans over time using ThreadFix’s OWASP ZAP integration. LEARN MORE


Portswigger BurpSuite Pro is a testing platform that maps and analyzes an applications attack surface then discovers and exploits security vulnerabilities.


Qualys Web Application Scanning (WAS) is an automated service that performs regular testing of web applications with automated crawling that scales and minimizes false positives.


Rapid7 AppSpider creates custom attacks based on the architecture of your specific application to provide the most accurate testing results.


Skipfish is a web application security tool that prepares interactive sitemaps of targeted sites.


Sonatype Nexus help organizations improve the quality, security, and speed of their software supply chains.


Tenable Nessus identifies network vulnerabilities and configurations, then prevents attacks on the network.


Trustwave App Scanner Enterprise (Cenzic Hailstorm) automates the detection of security vulnerabilities in web applications and services with an emulated browser and mock attacks within its patented Hailstorm™ scanning engine.

Related image

Veracode Binary Static Analysis (SAST) platform performs analysis of code and third party components without the upload of source code.

Related image

Veracode Dynamic Analysis (DAST) platform employs DynamicDS (Deep Scan) and Virtual Scan Appliance (VSA) to perform scans of web applications with and without authentication and behind the firewall.


Virtual Forge CodeProfiler is an ABAP virtual firewall enforcing security, speed and quality from development, quality assurance and production.


W3AF detects web application vulnerabilities and provides tools for penetration testing efforts with specially crafted HTTP requests.


WhiteHat Security Sentinel Dynamic Analysis accurately identifies and verifies vulnerabilities in your websites and web applications. 


WhiteHat Security Sentinel Static Analysis scans your entire source code, identifies vulnerabilities and provides detailed vulnerability descriptions and remediation advice.

Are You Ready?

Get Started