Xygeni Detectors

Open Source Security Open Source Security

Bad Components

The Suspect Dependencies Scanner finds suspect dependencies (suspect deps for short) that may be the target of supply-chain attacks.

The aim is to detect potential flaws in the dependencies, direct or indirect, in the software project and DevOps tools around, so supply-chain attacks can be prevented.

Open Source Security Open Source Security

Malware Scanner

This service proactively protects your software supply chain and supports the implementation of security gates to block malware threats before they infiltrate your application.

Secrets Security Secrets Security

Hardcoded Secrets

Xygeni Secrets detects hardcoded secrets. Xygeni Secrets performs thorough scans of code, text files and docker images to identify exposed secrets (API keys, passwords, and other sensitive credentials). Such exposures can be exploited by malicious actors to leak data or gain unauthorized access to critical systems.

Anomaly Detection Anomaly Detection

Code Tampering

A Code Tampering flaw is a security vulnerability that occurs when an attacker is able to perform an unauthorized malicious modification of the code of a program or system in a way that allows them to gain unauthorized access or control.

Anomaly Detection Anomaly Detection

Unusual Activity

Xygeni detects anomalies that indicate unauthorized modifications, access, or exploitations in real time. This proactive approach ensures that potential security breaches are addressed before they can escalate into serious threats.

Software Supply Chain Security - SSCS Software Supply Chain Security - SSCS

Misconfigurations

A CI/CD misconfiguration in any element of the software pipeline, like a package manager, a build file, or a CI job, might open the door to attacks targeted at the organization’s DevOps chain.

Software Supply Chain Security - SSCS Software Supply Chain Security - SSCS

Compliance Assessment

Compliance Assessment checks compliance with Software Supply-Chain Security standards and guidelines.

Infrastructure as Code (IaC) Security Infrastructure as Code (IaC) Security

IaC Flaws

An IaC Flaw represents a "flaw" or "defect" (a non-compliance) for a certain policy, found in an Infrastructure-as-Code (IaC) template. Most flaws represent a security-related issue that adds significant risk.

Code Security Code Security

SAST Scanner

Detects vulnerabilities in software code and configurations that could be exploited by threat actors. Scans code using static analysis to uncover flaws that open the software to attack.

Code Security Code Security

API Security

Xygeni API Security discovers the API surface of an application (endpoints, parameters, request and response shapes) and analyses it for the OWASP API Security Top 10 (2023) risks — broken authentication, broken object- and function-level authorization, excessive data exposure, PII leak in response, mass assignment, JWT misconfiguration, SSRF, CORS misconfiguration, rate-limit absence, and zombie / orphan endpoints. The inventory is also the join key linking SAST findings to DAST findings in the Xygeni risk graph.

Code Quality Code Quality

Code Quality

Xygeni Code Quality analyses source code for maintainability and reliability problems — code smells, naming and complexity issues, dead code, inefficiencies, and framework misuse — across many languages, classified by kind. Code Quality is a separately-licensed feature (the codeQuality entitlement).