Software Composition Analysis (SCA) Tools
Compare the best SCA tools for software composition analysis. Find open source vulnerability scanners with licensing analysis, SBOM generation, and more.
Oligo Security offers application layer insights as part of a CADR platform. They baseline application library activities at a function level, and can detect either malicious deviation, or the execution of known vulnerable functions. This extends into AI, allowing them to see, detect, and respond to AI applications.
Raven has built a comprehensive runtime oriented ADR solution that can detect function executions from packages being exploited. This empowers them to detect application layer attacks, create prioritization based on what functions are being used, as well as virtual patching to prevent vulnerability exploitation.
Kodem offers runtime first code security solutions - from runtime function execution SCA to runtime detection for prioritizing SAST findings. They're also one of the few to offer ADR solutions.
Via their oneagent, Dynatrace provides highly competitive ADR capabilities with function level reachability, RASP style blocking, and the ability to query most logs. Their agent also extends into processes and hosts. Their CADR offering has the complete offering from a feature perspective, but the UX struggles to tie it together for security.
Miggo is maximizing the value of your existing application performance monitoring, or offers an instrumentation of their own, that excels at building maps of distributed systems and real time attack detection and prevention. Miggo has no-code as well integration based implementations.
Konvu provides robust AI prioritization and autofixing, currently for SCA vulnerabilities but expanding to others as well. These are some of the strongest prioritization and fixing capabilities I've seen within the SCA category, and it's a great help for teams struggling to burn down their backlog.
Netrise has created rich dependency analysis specializing in firmware on hardware devices like Cisco Switches. They also detect hard-coded credentials, and other vulnerabilities. They've expanded this technology into containers to provide in depth analysis.
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
Contrast wraps commonly exploited functions at runtime to detect and prevent application exploits, i.e. they scan the application once it's actually built and running for vulnerabilities, and preventing exploits. This makes Contrast a strong choice for enterprise application protection.
Reversing Labs has very robust malware detection capabilities when picking apart binaries. They're expanding this binary analysis into also creating SBOMs and SCA results. Some platform strengths are supporting traditional Windows packages and having robust approval workflows for stringent enterprise support. I wouldn't say developer workflows or ease of integrations are as good as other tools.
Acquired and subsequently shutdown by Cisco. Deep Factor differentiates their SCA tool with deep runtime insights on the open source package and its state of being loaded or not in the application - a good way to prioritize fixing.