Coverage Features Comparison - Web Application Scanners:

The current information is based on the results of the *2011* benchmark (excpet for entries marked as updated or new )

Note: The content in this page is *incomplete* since the research is still in progress - the various scanners might support additional features.

Last updated: 27/08/2012
Sorted in a descending order according to the amount of technologies the scanner can "crawl" and according to the scanner name .
Hint: hover over the marks and titles to get additional information on the various features.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
1
Acunetix WVS Free Edition5
2
Netsparker Community Edition5
3
sqlmap5
4
W3AF5
5
Grendel Scan4
6
IronWASP4
7
XSSer4
8
Grabber3
9
N-Stalker 2009 Free Edition3
10
N-Stalker 2012 Free Edition3
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
11
safe3wvs (limited free edition)3
12
Sandcat Free Edition3
13
Syhunt Mini (Sandcat Mini)3
14
ZAP3
15
Andiparos2
16
arachni2
17
LoverBoy2
18
Oedipus2
19
Paros Proxy2
20
ProxyStrike2
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
21
SkipFish2
22
SQID (SQL Injection Digger)2
23
SQLiX2
24
Vega2
25
Watobo2
26
WebCruiser Free Edition2
27
WebScarab2
28
XSSS2
29
aidSQL1
30
crawlfish1
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
31
Damn Small SQLi Scanner (DSSS)1
32
Gamja1
33
iScan1
34
JSky Free Edition1
35
Mini MySqlat0r1
36
openAcunetix1
37
PowerFuzzer1
38
Priamos1
39
Scrawlr1
40
ScreamingCSS1
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
41
Secubat1
42
Uber Web Security Scanner1
43
VulnDetector1
44
Wapiti1
45
Web Injection Scanner (WIS)1
46
WebSecurify (Opensource Version)1
47
WSTool1
48
Xcobra1
49
XSSploit1


Statistics
#
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
Scanners:179477000005042011



Glossary
AliasGeneral FeatureDescriptionReferences
Manual CrawlManual Crawling SupportSupport for manually "teaching" the application structure to the scanner
URL FileURL File Parsing SupportSupport for loading the list of target entry points from a file
Html CrawlerHTML Form/Link CrawlerThe ability to automatically crawl HTML forms/links (a.k.a Spider)1
Ajax CrawlerJS/VBS/Ajax CrawlerThe ability to automatically crawl entry points that are accessed via JS/VBS/Ajax code
Flash CrawlerFlash CrawlerThe ability to automatically crawl Flash applications
Applet CrawlerApplet CrawlerThe ability to automatically crawl Applet applications (Java)
Silverlight CrawlerSilverlight CrawlerThe ability to automatically crawl Silverlight applications
WSDL CrawlerWebService WSDL CrawlerThe ability to automatically identify, analyze and crawl web service WSDL files1
REST CrawlerREST WSDL CrawlerThe ability to automatically identify, analyze and crawl RESTful web service WSDL files
Field AutoFillField Value AutoFillThe ability to fill fields with default values while automatically crawling the application (param-name based)
Smart AutoFillSmart Field Value AutoFillThe ability to fill fields with default values while automatically crawling the application (GUI based)
AntiCSRF SupportAntiCSRF Token SupportSupport for replaying & updating AntiCSRF tokens (GET/POST)
Viewstate SupportEvenet & Viewstate SupportSupport for replaying & updating various viewstate and event fields
CAPTCHA BypassCAPTCHA Cracking/Bypass FeaturesCrack/Bypass CAPTCHA fields while scanning the application
WAF BypassWAF Evasion TechniquesUse WAF evasion techniques while scanning the application



Copyright © 2012 by Shay Chen (sectooladdict). All rights reserved.
Click here to learn how this information may be published or reused.