Black Duck Polaris Platform Features
Administration (5)
API
Application programming interface that allows for integration with other systems/databases
Extensibility
Provides the ability to extend the platform to include additional features and functionalities
Reporting and Analytics
Tools to visualize and analyze data.
-
API / Integrations
Application Programming Interface Specification for how the application communicates with other software. APIs typically enable integration of data, logic, objects, etc. with other software applications.
-
Extensibility
Provides the ability to extend the platform to include additional features and functionalities
Analysis (14)
Issue Tracking
Track issues and manage resolutions.
Reconnaissance
Gathers information about the system and potential exploits to be tested.
Vulnerability Scan
Scans applications and networks for known vulnerabilities, holes and exploits.
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Automatic Scans
Setup recurring or automatic scans
SPA Scans
Security assessments specifically designed to identify vulnerabilities in single-page web applications.
-
Real-Time Analytics
Analyze and gain insights into data in real-time
-
Issue Tracking
Track issues as vulnerabilities are discovered. Documents activity throughout the resolution process.
-
Static Code Analysis
Examines application source code for security flaws without executing it.
-
Code Analysis
Scans application source code for security flaws without executing it.
Integrated Development Environment
An application for source code editing, compiling, and debugging
Reporting
Provides analytics tools that reveal important business metrics and track progress.
Baselining
Assess current state of user security training, prior to training, which can be used to track performance and improvement.
Real-Time Code Analysis
Continuously scans application source code for security flaws without executing it.
Testing (12)
Command-Line Tools
Allows users to access a terminal host system and input command sequences.
Manual Testing
Allows users to perfrom hands-on live simulations and penetration tests.
Test Automation
Runs pre-scripted security tests without requiring manual work.
Performance and Reliability
Software is consistently available (uptime) and allows users to complete tasks quickly because they are not waiting for the software to respond to an action they took.
-
Command-Line Tools
Allows users to access a terminal host system and input command sequences.
-
Manual Testing
Allows users to perfrom hands-on live simulations and penetration tests.
-
Test Automation
Runs pre-scripted security tests without requiring manual work.
-
Compliance Testing
Allows users to test applications for specific compliance requirements.
-
Source-Code Scanning
Scan the initial code written for application development
-
Detection Rate
The rate at which scans accurately detect all vulnerabilities associated with the target.
-
False Positives
The rate at which scans falsely indicate detection of a vulnerability when no vulnerabilitiy legitimately exists.
Multi-Language Scanning
Scan for security vulnerabilities in multiple coding languages
Functionality - Software Composition Analysis (3)
Language Support
Supports a useful and wide variety of programming languages.
Integration
Integrates seamlessly with the build environment and development tools like repositories, package managers, etc.
Transparency
Grants comprehensive user-friendly insight into all open source components.
Effectiveness - Software Composition Analysis (3)
Remediation Suggestions
Provides relevant and helpful suggestions for vulnerability remediation upon detection.
Continuous Monitoring
Monitors open source components proactively and continuously.
Thorough Detection
Comprehensively identifies all open source version updates, vulnerabilities, and compliance issues.
Extensibility (3)
Customization
Customizable solution so administers can adjust content to industry, position, etc.
White-Labeling
Allows users to implement their own branding throughout the platform.
Content Library
Provides users with a pre-built library of useable security-related informational content.
Assessment (4)
Integrated Learning
Provides educational resources for developers as security issues are detected.
Gamification
Contains gamification tools, including but not limited to badges, leaderboards, and point scoring.
Continuous Assesment
The abillity to automate secure code assesment or have assesments scheduled and delivered continuously.
Developer Assesment
Provides challenges, simulations or other assesment features to test developers for common security mistakes
Documentation (3)
Feedback
Provides thorough, actionable feedback regarding security vulnerabilities, or allows collaborators to do the same.
Prioritization
Prioritizes detected vulnerabilities by potential risk, or allows collaborators to do the same.
Remediation Suggestions
Provides suggestions for remediating vulnerable code, or allows collaborators to do the same.
Security (3)
False Positives
Does not falsely indicate vulnerable code when no vulnerabilitiy legitimately exists.
Custom Compliance
Allows users to set custom code standards to meet specific compliances.
Agility
Detects vulnerabilities at a rate suitable to maintain security, or allows collaborators to do the same.
Agentic AI - Static Code Analysis (3)
Adaptive Learning
Improves performance based on feedback and experience
Natural Language Interaction
Engages in human-like conversation for task delegation
Proactive Assistance
Anticipates needs and offers suggestions without prompting
Agentic AI - Static Application Security Testing (SAST) (1)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Agentic AI - Interactive Application Security Testing (IAST) (1)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Performance - AI AppSec Assistants (3)
Remediation
Automatically remediates or suggests remediation that meets internal and external code security best practices.
Real-time Vulnerability Detection
Automatically detects all security flaws in code as it's being written.
Accuracy
Does not flag false positives.
Integration - AI AppSec Assistants (3)
Stack Integration
Integrates with existing security tools to fully contextualize remediation suggestions.
Workflow Integration
Seamlessly integrates into developers' existing workflows and environments to provide code security assistance.
Codebase Contextual Awareness
Considers the entire codebase to detect existing and emerging security flaws.
Additional Functionality (33)
Network Mapping
Network topology maps providing infrastructure visualization for devices, connections, configurations, etc.
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
SQL Injections
Protect against code driven website security attack techniques
Audit Management
Plan, schedule, and execute organization's accounts and assets to ensure compliance with policies and laws
Threat Intelligence
Information to prevent, understand and identify cyber threats
Assignment Management
Assign issues and tasks based on availability or required skills
Integration Management
Identify which applications need to exchange data and enable these data connections
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Asset Discovery
Remediation Management
Identify and orchestrate execution of actions needed to restore systems to optimal conditions
Vulnerability Scanning
Discover patch statuses and vulnerabilities
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Multi-User Collaboration
Two-way actions and communication between multiple users in real time
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Web-Application Security
Identify and respond to security threats to web applications
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing the vulnerabilities in a system.
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
Runtime Container Security
Continuously vetting activities within the container application environment including hosts, open ports, protocols and payloads.
Network Scanning
Scanning networks to identify security threats
Password Cracking
Tools for testing the strength of passwords through brute force, dictionary attacks, or other methods.
Simulated Threat Attacks
Controlled, realistic exercises that mimic real cyber threats to test an organization/user's security measures and preparedness.
Certificates
Create and distribute custom certificates for achievements or assessments.
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
Real-Time Data
Receive data and information in real time
Cross-Site Scripting
Security vulnerability that allows attackers to inject malicious scripts into web pages
Exploit Frameworks
Specialized tools and modules to exploit identified vulnerabilities in systems and applications.
Debugging
Detect and remove errors
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
For Developers
For the intention to be used by developers
Deployment Management
Manage the processes involved when making the application ready for use
Application Security
Identify and respond to security threats to developed applications
Dashboard
Assembly of graphs and charts for visualizing and tracking statistics/metrics



