Crawling Method, Coverage and Scan Barrier Support of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Note: The content in this page is *incomplete* since the research is still in progress - the various scanners might support additional features.

Last updated: 18/09/2016
Sorted in a descending order according to the amount of technologies the scanner can "crawl" and according to the scanner name .
Hint: hover over the marks and titles to get additional information on the various features.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
1
arachni7
2
W3AF6
3
Acunetix WVS Free Edition5
4
Netsparker Community Edition5
5
sqlmap5
6
ZAP5
7
Grendel Scan4
8
IronWASP4
9
XSSer4
10
Grabber3
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
11
N-Stalker 2009 Free Edition3
12
N-Stalker 2012 Free Edition3
13
safe3wvs (limited free edition)3
14
Sandcat Free Edition3
15
Syhunt Mini (Sandcat Mini)3
16
Vega3
17
WATOBO3
18
Andiparos2
19
LoverBoy2
20
Oedipus2
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
21
Paros Proxy2
22
ProxyStrike2
23
SkipFish2
24
SQID (SQL Injection Digger)2
25
SQLiX2
26
Wapiti2
27
WebCruiser Free Edition2
28
WebScarab2
29
XSSS2
30
aidSQL1
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
31
crawlfish1
32
Damn Small SQLi Scanner (DSSS)1
33
Gamja1
34
iScan1
35
JSky Free Edition1
36
Mini MySqlat0r1
37
openAcunetix1
38
PowerFuzzer1
39
Priamos1
40
Scrawlr1
#
LogoVulnerability Scanner
C
O
U
N
T
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
41
ScreamingCSS1
42
Secubat1
43
Uber Web Security Scanner1
44
VulnDetector1
45
Web Injection Scanner (WIS)1
46
WebSecurify (Opensource Version)1
47
WSTool1
48
Xcobra1
49
XSSploit1


Statistics
#
Manual
Crawl
URL
File
Html
Crawler
Ajax
Crawler
Flash
Crawler
Applet
Crawler
Silverlight
Crawler
WSDL
Crawler
REST
Crawler
Field
Autofill
Smart
Autofill
Anti
CSRF
Support
Viewstate
Support
CAPTCHA
Bypass
WAF
Bypass
Scanners:1711489100008053011



Glossary
AliasGeneral FeatureDescriptionReferences
Manual CrawlManual Crawling SupportSupport for manually "teaching" the application structure to the scanner
URL FileURL File Parsing SupportSupport for loading the list of target entry points from a file
Html CrawlerHTML Form/Link CrawlerThe ability to automatically crawl HTML forms/links (a.k.a Spider)1
Ajax CrawlerJS/VBS/Ajax CrawlerThe ability to automatically crawl entry points that are accessed via JS/VBS/Ajax code
Flash CrawlerFlash CrawlerThe ability to automatically crawl Flash applications
Applet CrawlerApplet CrawlerThe ability to automatically crawl Applet applications (Java)
Silverlight CrawlerSilverlight CrawlerThe ability to automatically crawl Silverlight applications
WSDL CrawlerWebService WSDL CrawlerThe ability to automatically identify, analyze and crawl web service WSDL files1
REST CrawlerREST WSDL CrawlerThe ability to automatically identify, analyze and crawl RESTful web service WSDL files
Field AutoFillField Value AutoFillThe ability to fill fields with default values while automatically crawling the application (param-name based)
Smart AutoFillSmart Field Value AutoFillThe ability to fill fields with default values while automatically crawling the application (GUI based)
AntiCSRF SupportAntiCSRF Token SupportSupport for replaying & updating AntiCSRF tokens (GET/POST)
Viewstate SupportEvenet & Viewstate SupportSupport for replaying & updating various viewstate and event fields
CAPTCHA BypassCAPTCHA Cracking/Bypass FeaturesCrack/Bypass CAPTCHA fields while scanning the application
WAF BypassWAF Evasion TechniquesUse WAF evasion techniques while scanning the application



Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.