Usage
Everything you can do with a running ScanSuite deployment.
Everything below assumes a working installation. If you have not got one yet, start with Installation.
Before the first scan
Create a product. Every scan result and every discovered asset is filed under one, and the name is what you will search for later.
Scanning
Static Code Analysis
Analyse a repository or an archive: AI Native SAST, secrets, dependencies and the classic scanners.
Web App Scanning
Authenticated and unauthenticated web scanning, including the AI DAST engine.
AI Pentest
An agent that plans an engagement, runs the tools, and proves what it finds.
Infrastructure Checks
Vulnerability scans, network discovery, patching checks, OSINT and container images.
While a scan runs, and afterwards
Managing scan execution
Scan History: rerunning, resuming, stopping and downloading scans.
Vulnerability Management
One record per issue: triaged with a reason, tracked through its history, and closed on evidence.
Working with scan results
Reading findings in DefectDojo and exporting them.
Reports and exports
Where every report format comes from and where findings can be sent.
The data the platform accumulates
Exploitable Vulnerabilities Database
The local CVE database with real exploitation evidence, and everything that queries it.
Credentials
Secrets and leaked credentials found by scans, and verifying whether they still work.
Assets
Hosts discovered by scans, with alerting on changes.
Custom Rules
Your own Semgrep and Nuclei rules, generating a Nuclei rule with AI, and the suppression rules triage creates.
Configuration that affects every scan
Last reviewed 2026-08-16