Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Seeker® is an advanced interactive application security testing (IAST) tool that offers exceptional insights into the security status of your web applications. It detects trends in vulnerabilities relative to compliance benchmarks such as OWASP Top 10, PCI DSS, GDPR, CAPEC, and CWE/SANS Top 25. Moreover, Seeker allows security teams to monitor sensitive information, ensuring it is adequately protected and not inadvertently recorded in logs or databases without the necessary encryption. Its smooth integration with DevOps CI/CD workflows facilitates ongoing application security assessments and validations. Unlike many other IAST tools, Seeker not only uncovers security weaknesses but also confirms their potential for exploitation, equipping developers with a prioritized list of verified issues that need attention. Utilizing its patented techniques, Seeker efficiently processes a vast number of HTTP(S) requests, nearly eliminating false positives and fostering increased productivity while reducing business risks. In essence, Seeker stands out as a comprehensive solution that not only identifies but also mitigates security threats effectively.
Description
A novel approach to security tailored to modern software development processes has emerged. By embedding security directly into the development toolchain, issues can be addressed within minutes of installation. Contrast agents actively monitor the code and provide insights from within the application, empowering developers to identify and resolve vulnerabilities without the need for specialized security personnel. This shift allows security teams to concentrate on governance and oversight. Additionally, Contrast Assess features an advanced agent that equips the application with intelligent sensors for real-time code analysis. This internal monitoring significantly reduces false positives, which often hinder both developers and security teams. By integrating seamlessly into existing software life cycles and aligning with the tools that development and operations teams currently utilize, including direct compatibility with ChatOps, ticketing platforms, and CI/CD pipelines, Contrast Assess simplifies the security process and enhances team efficiency. As a result, organizations can maintain a robust security posture while streamlining their development efforts.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
Amazon Web Services (AWS)
Yes
Apache Maven
Yes
Azure DevOps Server
Yes
Bamboo
Yes
Brinqa
Yes
CircleCI
Yes
Cisco Vulnerability Management
Yes
Eclipse IDE
Yes
GitHub
Yes
Gradle
Yes
Integrations
Amazon Web Services (AWS)
Yes
Apache Maven
Yes
Azure DevOps Server
Yes
Bamboo
Yes
Brinqa
Yes
CircleCI
Yes
Cisco Vulnerability Management
Yes
Eclipse IDE
Yes
GitHub
Yes
Gradle
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Black Duck
Founded
2002
Country
United States
Website
www.blackduck.com/interactive-application-security-testing.html
Vendor Details
Company Name
Contrast Security
Founded
2014
Country
United States
Website
www.contrastsecurity.com/interactive-application-security-testing-iast
Product Features
Application Security
Analytics / Reporting
No
Open Source Component Monitoring
No
Source Code Analysis
No
Third-Party Tools Integration
No
Training Resources
No
Vulnerability Detection
No
Vulnerability Remediation
No
Static Application Security Testing (SAST)
Application Security
No
Dashboard
No
Debugging
No
Deployment Management
No
IDE
No
Multi-Language Scanning
No
Real-Time Analytics
No
Source Code Scanning
No
Vulnerability Scanning
No
Product Features
Application Security
Analytics / Reporting
No
Open Source Component Monitoring
No
Source Code Analysis
No
Third-Party Tools Integration
No
Training Resources
No
Vulnerability Detection
No
Vulnerability Remediation
No
Static Application Security Testing (SAST)
Application Security
No
Dashboard
No
Debugging
No
Deployment Management
No
IDE
No
Multi-Language Scanning
No
Real-Time Analytics
No
Source Code Scanning
No
Vulnerability Scanning
No