Supported Security Scanners
Supported scanners in STO
Harness STO supports over 40 security scanners, they are categorized as follows:
Harness Security Scanners: Scanners developed, maintained, and fully supported by Harness
Third-Party Scanners: External commercial or open-source scanners integrated with the Harness platform, not developed or directly maintained by Harness.
Open-Source Scanners: A subset of third-party scanners that are open-source.
Built-in Scanner Steps: Harness-provided scanner steps using pre-configured open-source scanners. These are ready-to-use within Harness pipelines and do not require additional commercial licenses. For a complete guide, refer to Built-in Scanners.
For a comprehensive list of all scanners, you can view them by Scan Type or Target Type further down this page.
Harness Security Scanners
Harness is expanding its native security scanning capabilities. These scanners are developed and maintained directly by Harness.
API DAST (previously Traceable): A Dynamic Application Security Testing scanner for your APIs. This was formerly known as the Traceable API DAST scanner.
SAST: A Static Application Security Testing scanner for your Code Repositories.
SCA: A Software Composition Analysis scanner for your Container Images.
Third-Party Scanners
The following are the list of third-party scanners that are categorized by Scan Type and Target Type. The list includes both commercial and open-source scanners.
Here are the list of scanners supported by STO by scan type.
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Static Application Security Testing - SAST Scanners
Static Application Security Testing (SAST) is a security testing practice that analyzes source code for potential vulnerabilities without executing the application. To configure and run SAST scans, refer Static Application Security Testing documentation.
Bandit - open-source
Black Duck (by Synopsys)
Brakeman - open-source
Coverity - open-source
Mend (formerly known as WhiteSource)
Semgrep - open-source option
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Secret Detection Scanners
Secret Detection is a security testing practice that scans code repositories for exposed credentials, API keys, tokens, and other sensitive information. To configure and run secret detection scans, refer Secret Detection documentation.
Aqua Trivy - open-source
Gitleaks - open-source
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Software Composition Analysis - SCA Scanners
Software Composition Analysis (SCA) is a security testing practice that identifies vulnerabilities in open-source dependencies and third-party libraries used in your applications. To configure and run SCA scans, refer Software Composition Analysis documentation.
Aqua Trivy - open-source
OSV Scanner - open-source
OWASP Dependency-Check - open-source
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Container Scanners
Container Scanning is a security testing practice that analyzes your container images for potential vulnerabilities. To configure and run container scans, refer Container Scanning documentation.
Aqua Trivy - open-source
Grype - open-source
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Dynamic Application Security Testing - DAST Scanners
Dynamic Application Security Testing (DAST) is a security testing practice that identifies vulnerabilities in running applications by simulating real-world attacks. To configure and run DAST scans, refer Dynamic Application Security Testing documentation.
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Infrastructure as Code - IaC Scanners
Infrastructure as Code (IaC) scanning is a security testing practice that analyzes IaC configurations to identify misconfigurations, security vulnerabilities, and compliance issues before deployment. To configure and run IaC scans, refer Infrastructure as Code documentation.
Checkov - open-source
AI Scanners
AI Scanners are helps you to identify vulnerabilities in your ML models. To configure and run AI scanners, refer to ModelScan step documentation.
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
The following sections describe the scanners supported by Harness STO, based on the target type:
In addition to the listed supported scanners, the Custom Scan step allows the use of various other scanners. For a complete list of supported scanners, refer to Scanners Supported with Custom Scan Step.
Code repo scanners
A code scanner can detect one or more of the following issue types in your source code. For information about the specific vulnerabilities detected by each scanner, go to the scanner provider's documentation.
SAST (Static Application Security Testing): Known vulnerabilities in open-source and proprietary code.
SCA (Software Composition Analysis): Known vulnerabilities in open-source libraries and packages used by the code.
Secrets: Hard-coded secrets such as access keys and passwords.
IaC: Known vulnerabilities in Infrastructure-as-Code files such as Terraform configurations.
Misconfigurations: Known vulnerabilities in software configurations.
Aqua Trivy Orchestration, Ingestion
Bandit Orchestration, Ingestion
Brakeman Orchestration, Ingestion
Coverity Ingestion
Gitleaks Orchestration, Ingestion
Grype Orchestration, Ingestion
ModelScan Orchestration, Ingestion
Open Source Vulnerabilities (OSV) Orchestration, Ingestion
OWASP Dependency Check Orchestration, Ingestion
Reapsaw Ingestion
Semgrep Code (open-source option) Orchestration, Ingestion
SonarQube/SonarCloud (free option) Orchestration, Extraction, Ingestion
Checkov Orchestration, Ingestion
Harness Code Orchestration
Black Duck Hub Orchestration, Extraction, Ingestion
Checkmarx Orchestration, Extraction, Ingestion
Checkmarx One Orchestration, Extraction, Ingestion
CodeQL Ingestion
Data Theorem Extraction, Ingestion
Fortify on Demand Orchestration, Extraction, Ingestion
Fortify Static Code Analyzer Ingestion
Fossa Ingestion
GitHub Advanced Security Orchestration, Extraction, Ingestion
Mend (formerly WhiteSource) Orchestration, Extraction, Ingestion
Nexus IQ Orchestration, Extraction, Ingestion
Semgrep Code (paid option) Orchestration, Ingestion
Snyk Code Orchestration, Ingestion
Snyk Infrastructure as Code Orchestration, Ingestion
Snyk Open Source Orchestration, Ingestion
SonarQube/SonarCloud Orchestration, Extraction, Ingestion
Veracode Orchestration, Extraction, Ingestion
Wiz Orchestration, Ingestion
Artifact scanners
An artifact scanner can detect one or more of the following issue types in your container images and other artifacts. For information about the specific vulnerabilities detected by each scanner, go to the scanner provider's documentation.
SCA (Software Composition Analysis): Known vulnerabilities in open-source libraries and packages used by the code.
Container Scanning: Identify vulnerabilities in container images.
Grype Orchestration, Ingestion
Aqua Trivy Orchestration, Ingestion
Clair Orchestration, Ingestion
Harness Container Orchestration
Anchore Enterprise Orchestration, Extraction, Ingestion
Aqua Security Orchestration, Ingestion
AWS ECR Extraction
Black Duck Hub Orchestration, Extraction, Ingestion
Docker Content Trust (DCT) Orchestration, Ingestion
Mend (formerly WhiteSource) Orchestration, Extraction, Ingestion
Prisma Cloud (formerly Twistlock) Orchestration, Extraction, Ingestion
Snyk Container Orchestration, Ingestion
Sysdig Orchestration, Ingestion
Tenable.io Orchestration, Ingestion
Wiz Orchestration, Ingestion
JFrog Xray Ingestion
Instance scanners
An instance scanner scans a running application for vulnerabilities by simulating a malicious external actor exploiting known vulnerabilities. This is also known as a DAST (Dynamic Application Security Testing) scan.
For information about the specific vulnerabilities detected by each scanner, go to the scanner provider's documentation.
Metasploit Framework Orchestration, Ingestion
Nikto Orchestration, Ingestion
Nmap ("Network Mapper") Orchestration, Ingestion
OpenVAS Orchestration, Ingestion
ZAP Orchestration, Ingestion
Burp Enterprise Orchestration, Extraction, Ingestion
Traceable Orchestration, Extraction, Ingestion
Fortify on Demand Extraction, Ingestion
HCL AppScan Ingestion
Qualys Web Application Scanning (WAS) Ingestion
Tenable.io Nessus vulnerability scan Orchestration, Ingestion
Tenable.io Nessus web app scan Orchestration, Ingestion
Configuration scanners
The following scanners detect misconfigurations in your cloud environment that can result in vulnerabilities. For information about the specific vulnerabilities detected by each scanner, go to the scanner provider's documentation.
ScoutSuite Ingestion
Prowler Orchestration, Ingestion
AWS Security Hub Extraction, Ingestion
Other scanners
If you use a scanner that isn't listed above, you can still ingest your scan results into STO.
If your scanner can publish to SARIF format, go to Ingest SARIF scan results into STO.
For other scanners, go to Ingest results from unsupported scanners.
Scanners supported with Custom Scan step
The following scanners do not have a dedicated step in STO, but they can be used through the Custom Scan step.
Metasploit - open-source
OpenVAS - open-source
Reapsaw - open-source
ScoutSuite - open-source
If you are looking for scanners that are not available as steps or are not supported through the Custom Scan step, you can use the Custom Ingest step to import scan results into STO. For detailed instructions, see Ingest results from unsupported scanners
Supported ingestion formats
Here are the scanners that support ingestion scan mode in STO and the data format each scanner expects for ingestion into STO.
Anchore Enterprise — JSON
Aqua Security — JSON
Aqua Trivy — JSON (recommended), SARIF
AWS ECR — JSON
AWS Security Hub — JSON
Bandit — JSON (recommended), SARIF
Black Duck Hub — JSON
Brakeman — JSON
Burp — XML
Traceable — JSON
Checkmarx — XML, SARIF
CheckmarxOne — JSON
CodeQL — SARIF
Coverity — XML
Data Theorem — JSON
Docker Content Trust — JSON
Fortify — JSON
Fortify on Demand — JSON
Fossa — JSON
Gitleaks — JSON (recommended), SARIF
GitHub Advanced Security — SARIF
HQL AppScan — XML
Grype — JSON
Mend (formerly Whitesource) — JSON
ModelScan — JSON
Nessus — XML
Nexus — JSON
Nikto — XML
Nmap — XML
OpenVAS — JSON
OWASP Dependency Check — JSON
Prisma Cloud — JSON
Prowler — JSON
Qualys — XML
Reapsaw — JSON
Semgrep — SARIF
Snyk — JSON (recommended), SARIF
SonarQube — JSON
Sysdig — JSON
Tenable — JSON
Veracode — XML
JFrog Xray — JSON
Wiz - JSON (recommended), SARIF
Zed Attack Proxy (ZAP) — JSON
Checkov - JSON, SARIF
Last updated
Was this helpful?