SATraits is an application security planning tool designed to analyze and determine the expected defect coverage and accuracy of Application Security Testing (AST) tools for specific applications. It utilizes a knowledge base built on curated defects and code behavior statistics to evaluate AST tools based on source code language, environment, and context.
The tool assists organizations in identifying false negatives and mapping their scanning coverage against known vulnerabilities. By quantifying the overlap and limitations of various open-source and commercial AST tools, SATraits allows security teams to select appropriate combinations of scanning solutions to meet specific risk thresholds and architectural requirements.