v0.4.0 / 2026-10-04

See the report.直接看報告。

See the same example with identifying details hidden or included.同一份範例,你可以選擇隱藏或保留系統名稱等資訊。

These reports show 62 findings and 42 inventory observations from all 25 tools, using simulated data. They show how the app presents results, not the security of a real company.範例使用模擬資料,呈現 25 個工具的 62 筆發現與 42 筆盤點紀錄。你可以看到程式怎麼整理結果;這些內容不代表真實公司的安全狀況。

01 / REDACTED

Redacted遮蔽版

Read the findings and next steps with system names and other identifying details hidden. You can still see which tool found each problem.隱藏系統名稱等識別資訊,保留問題、處理順序與下一步,也看得到是哪個工具發現的。

02 / FULL

Fully disclosed完整揭露版

Read the example with system names, addresses and account details included. All names are fictional. Passwords and keys stay hidden.保留範例裡的系統名稱、網址與帳號資訊,看看內部報告的樣子。這些資料都是虛構的,密碼與金鑰仍會隱藏。

Open the HTML file in a browser, save it or print it. Use the language switch for English or Traditional Chinese. Both versions show the same findings and unfinished checks; passwords, keys and raw logs are excluded. The examples add a sample label and a source appendix to the app’s report.HTML 檔可以直接用瀏覽器閱讀、儲存或列印,也能切換中英文。兩個版本都有相同的發現與未完成項目,不顯示密碼、金鑰或原始紀錄。範例另加了標記與來源附錄。

25 / 25

Where each result comes from每筆結果從哪裡來

Several findings may point to the same problem. This table counts each original finding before the report groups related ones. Inventory is separate from vulnerabilities. Select a tool to read about its uses and limits.不同工具可能發現同一個問題。這張表計算的是整理前的原始筆數;報告會把相關發現放在一起。盤點與漏洞分開計算。點選工具名稱,可以了解用途與限制。

Scanner掃描器Purpose用途Findings發現Inventory盤點Input format輸入格式
CloudQueryCloudQueryLists selected AWS identities and permission policies. This inventory is kept separate from security findings.整理部分 AWS 身分與權限政策,作為盤點資料,和安全問題分開列出。01NDJSON · per-table outputNDJSON · 各資料表輸出
SteampipeSteampipeLists AWS users and selected account settings so you can review who has access.列出 AWS 使用者與部分帳號設定,方便了解哪些人可以存取。02JSONJSON
ProwlerProwlerChecks selected identity and permission settings in an approved AWS account, Azure subscription or GCP project.檢查核准的 AWS 帳號、Azure 訂用帳戶或 GCP 專案中的部分身分與權限設定。10OCSF-JSONOCSF-JSON
ScoutSuiteScoutSuiteChecks selected AWS identity and access settings. This app uses a limited part of ScoutSuite.檢查部分 AWS 身分與存取設定。本程式使用的是 ScoutSuite 的部分功能。30JSONJSON
CloudsplainingCloudsplainingReviews collected AWS permission policies for access that may be broader than needed.分析收集到的 AWS 權限政策,找出可能給得太多的權限。180JSONJSON
ScubaGearScubaGearCompares supported Microsoft 365 settings with CISA security guidance.依照美國 CISA 的安全建議,檢查支援的 Microsoft 365 設定。10JSON · managed envelope of native verdictsJSON · 包含原生判定的受管外層格式
MaesterMaesterTests supported Microsoft 365 security settings and explains which checks need attention.檢查支援的 Microsoft 365 安全設定,列出需要注意的項目。10JSON · managed envelope of native verdictsJSON · 包含原生判定的受管外層格式
NaabuNaabuShows which approved ports accept connections. An open port is information to investigate, not proof of a vulnerability.查看核准的連接埠是否接受連線。連接埠開著值得了解,但不代表有漏洞。02JSONLJSONL
httpxhttpxChecks whether a selected web service responds and records basic response information. It does not assess vulnerabilities.確認選定的網站服務是否回應,並記錄基本資訊;這不是漏洞檢查。02JSONLJSONL
NucleiNucleiIdentifies website technologies, then runs suitable read-only checks within the approved address and limits.先辨識網站使用的技術,再於核准的網址與限制內執行適用的唯讀檢查。20JSONL / SARIFJSONL / SARIF
Greenbone Community EditionGreenbone Community EditionIdentifies services on approved hosts and ports, then runs the security checks that apply.辨識核准主機與連接埠上的服務,再執行適合的安全檢查。10XMLXML
ZAPZAPVisits pages on one approved website and checks the responses. It does not submit forms or send attack payloads.瀏覽一個核准網站的頁面並檢查回應,不會送出表單或攻擊內容。50JSONJSON
SemgrepSemgrepFinds risky patterns in code, using the rule set included with this version.依照本版提供的規則,找出程式碼中可能不安全的寫法。10JSON / SARIFJSON / SARIF
GitleaksGitleaksLooks for passwords and keys left in project files. Values are hidden in the report.找出專案檔案裡可能留下的密碼與金鑰,報告會隱藏它們的內容。10JSONJSON
TruffleHogTruffleHogLooks for exposed secrets in local files. It does not try the credentials against a live service.在本機檔案裡找出可能外洩的密碼與金鑰,不會拿它們登入服務。20JSONLJSONL
CheckovCheckovChecks supported deployment and infrastructure files for unsafe settings.檢查支援的部署與基礎設施設定檔,找出不安全的設定。20JSON / SARIF / CYCLONEDXJSON / SARIF / CYCLONEDX
KICSKICSLooks for unsafe settings in files that describe how your systems are deployed.檢查用來部署系統的設定檔,找出可能造成風險的設定。10JSON / SARIFJSON / SARIF
TrivyTrivyChecks supported project and container packages against the included vulnerability database.用內附的漏洞資料庫,檢查支援的專案與容器套件。40JSON / SARIF / CYCLONEDX / SPDX-JSONJSON / SARIF / CYCLONEDX / SPDX-JSON
GrypeGrypeFinds known vulnerabilities in supported project and container packages using the included database.使用內附資料庫,找出支援的專案與容器套件是否有已知漏洞。40JSON / CYCLONEDX / SARIFJSON / CYCLONEDX / SARIF
SyftSyftLists the software components in your project or container. The list helps you track what is installed.列出專案或容器裡的軟體元件,幫你掌握用了哪些東西;清單本身不是漏洞報告。02SYFT-JSON / CYCLONEDX-JSON / SPDX-JSONSYFT-JSON / CYCLONEDX-JSON / SPDX-JSON
KubescapeKubescapeChecks the Kubernetes configuration files you select, without connecting to a running cluster.檢查你選好的 Kubernetes 設定檔,不會連到正在運作的叢集。30JSONJSON
kube-benchkube-benchChecks a saved copy of node settings against CIS guidance. It does not inspect a live host with administrator access.依照 CIS 建議檢查節點設定的副本,不會取得管理員權限來檢查運作中的主機。60JSONJSON
garakgarakSends 54 fixed test prompts to one approved model service. Review the request limits and provider charges before starting.對一個核准的模型服務送出 54 個固定測試提示。開始前請確認請求限制與服務商費用。40JSONLJSONL
Agentic RadarAgentic RadarMaps agents, tools and connections in supported AI workflows without running them.整理支援的 AI 工作流程,讓你看懂有哪些代理、工具與連線,不會執行那些流程。033JSON · native parser graph via output patchJSON · 透過輸出修改取得原生解析圖形
MCP ArmorMCP ArmorChecks a selected MCP configuration for exposed keys and overly broad tool permissions. It does not start or contact MCP servers.檢查選定的 MCP 設定是否留下金鑰,或給了工具過大的權限;不會啟動或連線 MCP 伺服器。20JSON · configuration-only output patchJSON · 僅限設定模式的輸出修改