Usage
Everything you can do with a running ScanSuite deployment.
Everything below assumes a working installation. If you have not got one yet, start with Installation.
Before your first scan
Create a product. Every scan result and every discovered asset is filed under one, and the name is what you will search for later.
Scanning
Static Code Analysis
Analyse a repository or an archive: AI Native SAST, secrets, dependencies and the classic scanners.
Web App Scanning
Authenticated and unauthenticated web scanning, including the AI DAST engine.
AI Pentest
An agent that plans an engagement, runs the tools, and proves what it finds.
Infrastructure Checks
Vulnerability scans, network discovery, patching checks, OSINT and container images.
While a scan runs, and afterwards
Managing scan execution
Watching, stopping, restarting and searching scans in Scan History.
Vulnerability Management
One record per issue: ingested, correlated, validated, owned and closed.
Working with scan results
Reading findings in DefectDojo and exporting them.
Reports and exports
Where every report format comes from and where findings can be sent.
The data the platform accumulates
Exploitable Vulnerabilities Database
The local CVE database with real exploitation evidence, and everything that queries it.
Credentials
Secrets and leaked credentials found by scans, and verifying whether they still work.
Assets
Hosts discovered by scans, with alerting on changes.
Custom Rules
Your own Semgrep and Nuclei rules, including generating a Nuclei rule with AI.
Configuration that affects every scan
Last reviewed 2026-08-16