ZAP vs Nuclei: Deep App Scanning or Fast Known-Issue Sweeps
ZAP explores one web app deeply through crawling and a proxy; Nuclei sweeps many hosts for known issues. How to choose, and when to run both.
7 min read
Guides and comparisons for choosing tools, written to the same editorial standard as the profiles.
ZAP explores one web app deeply through crawling and a proxy; Nuclei sweeps many hosts for known issues. How to choose, and when to run both.
7 min read
Semgrep matches code shapes without a build; CodeQL queries a semantic database of your program. How that choice plays out in ownership, noise and depth.
7 min read
OSV-Scanner and Anchore Grype compared on the axis that decides it: scanning resolved lockfiles against open advisories, or cataloging built images.
7 min read
Gitleaks digs through git history with TOML rules; detect-secrets gates new commits against a baseline. How each fits pre-commit, CI and legacy repos.
7 min read
Garak scans a model endpoint with a probe library; PyRIT builds multi turn red team campaigns. Who runs each and how results feed a release call.
7 min read
Checkov and KICS both gate IaC in pull requests. The choice turns on how you write policy: Python and graph checks, or Rego queries.
7 min read
Ten secret scanning tools compared by where they sit in the lifecycle, whether they verify credentials, and whether they carry a leak through to rotation.
12 min read
Ten software composition analysis tools picked for distinct jobs: reachability triage, license compliance, SBOM monitoring, malicious package detection and patching.
12 min read
A practitioner's guide to ten static analysis tools, chosen for distinct scenarios rather than ranked, with the trade-offs each one brings.
12 min read
A practitioner's guide to runtime application self-protection: true in-process agents, mobile hardening libraries, and the WAF-adjacent tools often filed alongside them.
12 min read
Ten mobile application security tools chosen for distinct scenarios, from automated binary scanning to runtime instrumentation, with honest caveats.
12 min read
A practitioner's guide to interactive application security testing tools, picked for distinct scenarios rather than ranked, with an honest caveat on each.
12 min read