ThreadFix Open Source Software Vulnerability Management Tool

Efficiently Identify and Remediate Application Vulnerabilities


Finding vulnerabilities is only the first step to remediation. Making sense of the endless reports from dynamic and static scanners can be a daunting task, and when you add in results from manual testing, looking for trends and benchmarks can be like searching for a needle in a haystack.

Denim Group has created ThreadFix, a tool designed to give security practitioners the ability to understand the security of their applications and efficiently conduct remediation.

ThreadFix can help with your reporting issues. The open source software vulnerability management tool provides security managers and professionals a central location to store and track software vulnerabilities. Trending reports empower users to give up-to-date security statuses of their web applications. ThreadFix also creates web application firewall virtual patches, protecting applications during remediation. Download ThreadFix Brochure >>

ThreadFix Features and Benefits

Simplified View of Application Test Results
Consolidate and de-duplicate imported results from open source, commercial dynamic and static scanning tools, as well as the results of manual testing and threat modeling to get a complete view of the state of your applications.
Reports
Get the latest security status of your applications while providing an eagle’s-eye view of your organization’s progress over time to pinpoint any process problems.
Defect Tracker Integration
Help security professionals translate application vulnerabilities into software defects and push tasks to developers in the tools and systems they are already using.
Virtual Patching
Create virtual Web Application Firewall (WAF) rules to help block malicious traffic while vulnerabilities are being resolved. While your organization takes on remediation of your applications, virtual patching helps guard against common vulnerabilities such as Cross-Site Scripting (XSS) and SQL Injections.
Compatible with Open Source and Commercial Products
ThreadFix is compatible with a number of commercial and freely available dynamic and static scanning technologies, SaaS testing platforms, IDS/IPS and WAFs and defect trackers.

 

Download ThreadFix Now

Visit the ThreadFix Google code repository to download ThreadFix now.

Need more information about ThreadFix?

If you would like more information about ThreadFix or would like to schedule a demo, please contact us through the following form.

( * Denotes Required Field)

First Name: *

Last Name: *

Title:

Company: *

Website:

Email: *

Phone:

Message:

From the Denim Group Blog

Go to blog >>

Webinar Recording Online: Running a Web Security Testing Program with OWASP ZAP and ThreadFix
Friday, April 26th, 2013

By Dan Cornell Simon Bennetts (@psiinon) and I did a webinar last Wednesday talking about how to set up web application testing programs witih the freely-available tools OWASP Zed Attack Proxy (ZAP) and ThreadFix. The webinar was titled "Running a...
Read More >>

Denim Group at SANS AppSec 2013 in Austin
Tuesday, April 9th, 2013

By Dan Cornell SANS AppSec 2013 will be held from April 22nd through April 27th in Austin, TX. Monday April 22nd, John Dickson will be moderating a panel titled "AppSec 2.0: Strategies for Moving the Needle on Application Security" The...
Read More >>

Webinar: Running a Web Security Testing Program with OWASP ZAP and ThreadFix
Monday, April 8th, 2013

By Dan Cornell Simon Bennetts (@psiinon) and I will be doing a webinar Wednesday April 24th, 2013 at 10:30am Central Daylight Time to talk about how organizations can set up a web security testing program using the freely available tools...
Read More >>

ThreadFix 1.1 Released
Monday, March 25th, 2013

By Dan Cornell ThreadFix 1.1 (final) is now available for download! You can pick up the ZIP (demonstration) install from the Google Code downloads site or you can pick up the VM image (for production use). There were a whole...
Read More >>

Uncommon Sense Security Looks at ThreadFix
Tuesday, March 19th, 2013

By Dan Cornell John Dickson and I had a chance to catch up with Jack Daniel from the Uncommon Sense Security blog while we were at RSA a couple of weeks ago to talk about what we've been doing with...
Read More >>