Cortex
Application scanning
Points real offensive tooling at one application and writes up what it finds, with the evidence attached. It takes more than a URL:
- Web app URL
- Android / iOS build
- Source ZIP
- API spec — OpenAPI, Postman, HAR
- Cloud account — AWS, GCP, Azure
- Linux host over SSH