Utilizes runtime intelligence from container, kernel, and memory to enhance source code scanning. It monitors and analyzes the application's runtime environment to identify vulnerabilities present and potentially exploitable during runtime. The feature contextualizes vulnerabilities' relevance and potential impact by examining the application's codebase to identify accessible functions or components during runtime.
02
Dynamic Software Composition Analysis
Analyzes open-source and third-party components using runtime intelligence. It identifies reachable vulnerabilities at the function level in dependencies without intrusive runtime agents. The feature scans direct, indirect, and phantom dependencies, providing early feedback as new dependencies are evaluated and enforcing policies in CI pipelines.
03
Container And Infrastructure As Code (Iac) Security
Embeds sensors at the container and cluster level to analyze configuration files for vulnerabilities and risk exposures. It performs base and running image scanning to determine code reachability and identify container-specific and IaC issues. The feature examines Dockerfiles, Kubernetes manifests, and other IaC scripts for misconfigurations and insecure practices.
04
Attack Path Analysis
Maps vulnerabilities as they would be exploited in a real attack, analyzing their role within an entire attack chain. This feature provides an attacker's perspective on the application's security posture, enabling prioritization and remediation of threats based on their potential to be part of a full attack chain.
05
Exploitability Confirmation
Uses a multifaceted approach to confirm the exploitability of vulnerabilities, combining fine-tuned Large Language Models (LLMs) with real-time intelligence from memory, kernel (using eBPF), and container environments. It simulates attack scenarios and analyzes runtime behavior to validate whether detected vulnerabilities can be exploited in practice.
Your plan caps how many capabilities are shown — upgrade to see the full list