Overview
The most advanced fault-injection testing tool for web applications.
Our in-depth understanding of security issues, emerging Web 2.0 technologies such as AJAX, traditional Web technologies, and Web programming languages such as PHP, enabled us to deliver exactly what we set out to provide - the most feature-rich and advanced web application security scanner available to date.
Sandcat combines Syhunt's state-of-the-art, multi-process scanning technologies with the incredibly fast Lua language to perform remote web application security scans. While spidering a web site and hunting vulnerabilities, Sandcat emulates a modern, HTML 5-aware web browser.
Key Features
Filter Evasion - Sandcat's fast engine interacts with a truly unique, up-to-date and extremely extensive database of checks and uses sophisticated techniques such as the newly introduced filter evasion and false positive reduction to give you stunning results. Sandcat's database is the culmination of years of research by Syhunt and includes checks for a extremely wide array of different web application security threats.
Web security scanning the way you want it - Sandcat is highly customizable and extensible, its options screen contains several checkboxes and fields which controls Sandcat's behavior. Additionally, almost any element of the tool can be molded to your liking - you can create and use your own scripts, exploits, GUI extensions and mods.
Web 2.0 compatible - Sandcat offers the degree of flexibility and versatility required to support any web environment, anywhere. It has been designed to intelligently handle complex, large web sites and automatically adapt to different web environments and technologies.
Sandcat + Sandcat for PHP - What could be better than combining blackbox testing and whitebox testing capabilities? Our newest tool, Sandcat for PHP, offers you the possibility to check the source code of your web applications for multiple classes of application vulnerabilities.