# Import from 202 security tools

This list is generated directly from Tandera’s parser registry. If a tool is named here, a parser exists for it in the codebase.

215 import formats across 202 tools. Several tools publish more than one report format.

- Acunetix Scan
- Alert Logic Scan
- Anchore Engine Scan
- Anchore Enterprise Policy Check
- Anchore Grype
- Anchore Grype detailed
- AnchoreCTL Policies Report
- AnchoreCTL Vuln Report
- AppCheck Web Application Scanner
- AppSpider Scan
- Aqua Scan
- Arachni Scan
- AuditJS Scan
- AWS Inspector2 Scan
- AWS Prowler Scan
- AWS Prowler V3
- AWS Security Finding Format (ASFF) Scan
- AWS Security Hub Scan
- Azure Security Center Recommendations Scan
- Bandit Scan
- Bearer CLI
- Blackduck Binary Analysis
- Blackduck Component Risk
- Blackduck Hub Scan
- Brakeman Scan
- BugCrowd Scan
- Bundler-Audit Scan
- Burp Dastardly Scan
- Burp Enterprise Scan
- Burp GraphQL API
- Burp REST API
- Burp Scan
- Burp Suite DAST Scan
- CargoAudit Scan
- Checkmarx CxFlow SAST
- Checkmarx One Scan
- Checkmarx OSA
- Checkmarx Scan
- Checkmarx Scan detailed
- Checkov Scan
- Chef Inspect Log
- Choctaw Hog Scan
- Clair Scan
- Cloudflare Insights
- Cloudsploit Scan
- Cobalt.io Scan
- Codechecker Report native
- Contrast Scan
- Coverity API
- Coverity Scan JSON Report
- Crashtest Security JSON File
- Crashtest Security XML File
- CredScan Scan
- Crunch42 Scan
- Cyberwatch scan (Galeax)
- CycloneDX Scan
- Cycognito Scan
- DawnScanner Scan
- Deepfence Threatmapper Report
- Dependency Check Scan
- Dependency Track Finding Packaging Format (FPF) Export
- Detect-secrets Scan
- docker-bench-security Scan
- Dockle Scan
- DrHeader JSON Importer
- DSOP Scan
- Duroc Hog Scan
- ESLint Scan
- Essex Hog Scan
- Fortify Scan
- Generic Findings Import
- Ggshield Scan
- Github SAST Scan
- Github Secrets Detection Report Scan
- Github Vulnerability Scan
- GitLab API Fuzzing Report Scan
- GitLab Container Scan
- GitLab DAST Report
- GitLab Dependency Scanning Report
- GitLab SAST Report
- GitLab Secret Detection Report
- Gitleaks Scan
- Google Cloud Artifact Vulnerability Scan
- Gosec Scanner
- Gottingen Hog Scan
- Govulncheck Scanner
- Govulncheck Scanner V2
- HackerOne Cases
- Hadolint Dockerfile check
- Harbor Vulnerability Scan
- HCL AppScan on Cloud SAST XML
- HCLAppScan XML
- Horusec Scan
- Humble Json Importer
- HuskyCI Report
- Hydra Scan
- IBM AppScan DAST
- Immuniweb Scan
- IntSights Report
- Invicti Scan
- IriusRisk Threats Scan
- JFrog Xray API Summary Artifact Scan
- JFrog Xray On Demand Binary Scan
- JFrog Xray Scan
- JFrog Xray Unified Scan
- KICS Scan
- Kiuwan SCA Scan
- Kiuwan Scan
- KrakenD Audit Scan
- kube-bench Scan
- Kubeaudit Scan
- KubeHunter Scan
- Kubescape JSON Importer
- Legitify Scan
- Mayhem SARIF Report
- Mend Scan
- Meterian Scan
- Microfocus Webinspect Scan
- MobSF Scan
- MobSF Scorecard Scan
- Mobsfscan Scan
- Mozilla Observatory Scan
- MSDefender Parser
- n0s1 Scanner
- Nancy Scan
- Netsparker Scan
- NeuVector (compliance)
- NeuVector (REST)
- Nexpose Scan
- Nikto Scan
- Nmap Scan
- Node Security Platform Scan
- Nosey Parker Scan
- NPM Audit Scan
- NPM Audit v7+ Scan
- Nuclei Scan
- OpenReports
- Openscap Vulnerability Scan
- OpenVAS Parser
- OpenVAS Parser v2
- Orca Security Alerts
- ORT evaluated model Importer
- OssIndex Devaudit SCA Scan Importer
- OSV Scan
- Outpost24 Scan
- PHP Security Audit v2
- PHP Symfony Security Check
- PICUS Scan
- PingCastle
- pip-audit Scan
- PMD Scan
- Popeye Scan
- Progpilot Scan
- Prowler Scan
- PTART Report
- PWN SAST
- Qualys Hacker Guardian Scan
- Qualys Infrastructure Scan (WebGUI XML)
- Qualys Scan
- Qualys VMDR
- Qualys Webapp Scan
- Rapplex Scan
- Red Hat Satellite
- Retire.js Scan
- ReversingLabs Spectra Assure
- Risk Recon API Importer
- Rubocop Scan
- Rusty Hog Scan
- SARIF
- Scantist Scan
- Scout Suite Scan
- Semgrep JSON Report
- Semgrep Pro JSON Report
- SKF Scan
- Snyk Code Scan
- Snyk Issue API Scan
- Snyk Scan
- Solar Appscreener Scan
- SonarQube Scan
- SonarQube Scan detailed
- Sonatype Application Scan
- SpotBugs Scan
- SSH Audit Importer
- SSL Labs Scan
- Sslscan
- Sslyze Scan
- SSLyze Scan (JSON)
- StackHawk HawkScan
- Sysdig CLI Report
- Sysdig Vulnerability Report
- Talisman Scan
- Tenable Scan
- Terrascan Scan
- Testssl Scan
- TFSec Scan
- Threagile risks report
- ThreatComposer Scan
- Trivy Operator Scan
- Trivy Scan
- Trufflehog Scan
- Trufflehog3 Scan
- Trustwave Fusion API Scan
- Trustwave Scan (CSV)
- Twistlock Image Scan
- VCG Scan
- Veracode Scan
- Veracode SourceClear Scan
- Wapiti Scan
- Wazuh
- WFuzz JSON report
- Whispers Scan
- WhiteHat Sentinel
- Wiz Scan
- Wpscan
- ZAP Scan

## More from Tandera

- [Tandera](https://tandera.io/): Pentest operations platform — scope to retest
- [About](https://tandera.io/about)
- [Attack chains](https://tandera.io/attack): Chain findings into attack narratives
- [Blog](https://tandera.io/blog)
- [Changelog](https://tandera.io/changelog)
- [Compare](https://tandera.io/compare)
- [Contact](https://tandera.io/contact)
- [Docs](https://tandera.io/docs)
- [Findings](https://tandera.io/findings): Consistent, reviewed vulnerability findings
- [Client portal](https://tandera.io/portal): Share results with clients
- [Privacy policy](https://tandera.io/privacy)
- [Recon](https://tandera.io/recon): Automated attack-surface discovery
- [Reports](https://tandera.io/reports): White-label pentest report generation
- [Security](https://tandera.io/security)
- [Solutions](https://tandera.io/solutions)
- [Terms](https://tandera.io/terms)
- [Tools](https://tandera.io/tools)

---

Canonical: https://tandera.io/integrations
This page as markdown: https://tandera.io/integrations.md
Index for agents: https://tandera.io/llms.txt

Every page here is also available as markdown: append `.md` to the path (e.g. `/recon.md`, `/index.md` for this homepage, `/blog/<slug>.md`), or request the canonical path with `Accept: text/markdown`.
