
Detectify
Intruder
Pentest-Tools
Probe.ly
Acunetix
Nessus
Burp Suite
Snyk
Sensagraph
Pentest-Tools
HostedScan.com
Acunetix
Intruder
SecScanner.app
Sensagraph covers the surface an attacker probes first, across five focused capabilities:
Detectify
SensagraphNo Sensagraph videos yet. You could help us improve this page by suggesting one.
Sensagraph's answer:
Sensagraph shows you your live web applications the way an attacker sees them, from the public internet, with nothing to install.
What sets us apart:
Sensagraph's answer:
Most external scanners are built for large security teams: heavy to set up, priced for the enterprise, and noisy enough that you need an analyst to read the output. Sensagraph is built for the teams those tools overlook.
Sensagraph's answer:
Sensagraph started with a simple, uncomfortable realization: you can write clean code, pass every test, and still be exposed the moment your application goes live.
As developers, we spent our time validating requests, keeping dependencies current, and shipping with confidence. But a passing test suite says nothing about the server the code lands on: the TLS configuration a load balancer negotiates, the admin panel that quietly became reachable, the forgotten open port, or the header advertising a version with a known vulnerability. That outside-in layer is exactly the one attackers probe first, and it stays invisible from inside your own codebase.
The tools that could show us that view were built for large security teams. They were heavy to deploy, expensive, and noisy. Agencies, SaaS startups, and solo developers were left with no practical way to see what the public internet already knew about their infrastructure.
So we built Sensagraph: an agentless platform that scans your live web presence the way an attacker would, ranks what it finds by severity, and turns it into a clear report anyone can act on. No agents, no code changes, and no security team required. Just point it at a domain, verify it once, and see exactly what is exposed, before someone else does.
Sensagraph's answer:
Sensagraph is built for teams that run internet-facing web applications but do not have a dedicated security team watching over them.
Our primary audiences are:
Typical users are developers, DevOps and infrastructure engineers, technical founders, CTOs, and IT or security managers, most often in software, IT services, digital agencies, e-commerce, and other businesses that depend on their web presence.
Based on our record, Detectify seems to be more popular. It has been mentiond 4 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
Detectify once made an offer of making free scans which I took them up on. There are plenty of free Content Security Policy (CSP) and other vulnerability checkers around such as Observatory or Pentest. Shields UP!! Will identify which ports you have open. Source: almost 3 years ago
Detectify | Community Manager, Crowdsource | REMOTE (Offices in Boston, US & Stockholm, Sweden. We help with relocation if wanted) https://detectify.com/ We are a cyber security company in the industry, and more specifically the EASM (External Attack Surface Monitoring) space by automating and scaling the knowledge of hundreds of ethical hackers through our SaaS platform. Currently through our unique to Detectify... - Source: Hacker News / over 4 years ago
A concept-level idea would be this: 1) For your staging/UAT environment pipeline stages, add a "DAST scan" step, eg. With Detectify (which also has an API accommodating this need) 2) I'd assume, independently from the DAST scan, you ran some tests on UAT. Allow the scan to complete during the time it takes to run your UAT tests. After that, you'll get a report (automated or not) from your scanner. 3) When... Source: about 5 years ago
Subdomain takeover was pioneered by ethical hacker Frans Rosén and popularized by Detectify in a seminal blogpost as early as 2014. However, it remains an underestimated (or outright overlooked) and widespread vulnerability. The rise of cloud solutions certainly hasn't helped curb the spread. - Source: dev.to / over 5 years ago
Intruder - Intruder is a security monitoring platform for internet-facing systems.
Pentest-Tools - Pentest-Tools.com is your ready-to-use setup for security testing
HostedScan.com - Online vulnerability scanner for servers, networks, and web applications.
Probe.ly - Intuitive and easy-to-use webapp vulnerability scanner
Acunetix - Audit your website security and web applications for SQL injection, Cross site scripting and other...
Nessus - Nessus Professional is a security platform designed for businesses who want to protect the security of themselves, their clients, and their customers.