Code Analysis (White Box)
These tools require a GitHub connection to access your source code. They run in addition to all black box tools.
📝 Code Scanner (SAST)
Static Application Security Testing - finds vulnerabilities in your source code. Code Scanner is a license-clean SAST engine, run with IntegSec's own rule pack (CWE Top 25 / OWASP Code Review Guide) rather than a public rule registry - so every check is one our operators wrote, reviewed, and own.
What it finds:
- Injection vulnerabilities (SQL, command, XSS)
- Insecure cryptography usage
- Hardcoded secrets
- Authentication bypass patterns
- Framework-specific anti-patterns (React, Django, Express, etc.)
Languages supported: Python, JavaScript/TypeScript, Java, Go, Ruby, PHP, C#, and more.
Rules: IntegSec's owned rule pack, aligned to CWE Top 25 and the OWASP Code Review Guide, bundled at /rules.
📦 Dep Scanner (SCA)
Software Composition Analysis - checks your dependency files for known vulnerabilities.
What it finds:
- Vulnerable npm/pip/Maven/Go dependencies
- Outdated packages with known CVEs (only vulnerabilities with available fixes are reported)
- Transitive dependency vulnerabilities
Files checked: package-lock.json, requirements.txt, go.sum, pom.xml, Gemfile.lock, etc.
🔑 Secret Scanner (Secret Detection)
Checks your repository's source tree for accidentally committed secrets.
What it finds:
- API keys (AWS, GCP, Azure, Stripe, etc.)
- Database connection strings
- OAuth tokens
- Private keys
- Passwords in configuration files
Enabling white box analysis
- Go to Dashboard > Account > GitHub
- Connect via OAuth or install the TurboPentest GitHub App
- Grant access to the repositories you want to test
- When starting a pentest, provide the
repoUrlparameter
The GitHub App is recommended as it provides fine-grained repository access without exposing your personal token.
Web Application Tools
TurboPentest's web application testing tools - the DAST scanners that probe your app for OWASP Top 10 and other vulnerabilities.
Paladin AI
Paladin is TurboPentest's autonomous agentic pentester - it runs its own security tools, navigates apps in a real browser, and validates live exploits.