OWASP Top 10 Coverage

Coverage matrix

#OWASP Top 10 (2021)Tools
A01Broken Access ControlZAP, Nuclei, Shannon AI
A02Cryptographic FailuresTestSSL, ZAP, Nuclei
A03InjectionZAP, Nuclei, Nikto, Semgrep
A04Insecure DesignShannon AI, Semgrep
A05Security MisconfigurationNuclei, Nikto, Nmap, ZAP, FFUF
A06Vulnerable ComponentsTrivy, Nuclei
A07Authentication FailuresZAP, Nuclei, Nikto
A08Software and Data IntegrityTrivy, Gitleaks, Semgrep
A09Security Logging FailuresShannon AI
A10Server-Side Request ForgeryZAP, Nuclei, Semgrep

Notes

  • Shannon AI provides coverage for design-level issues (A04, A09) through its threat modeling and STRIDE analysis capabilities
  • White box tools (Semgrep, Trivy, Gitleaks) significantly improve coverage for A03, A04, A06, A08, and A10
  • All findings include the OWASP category when applicable

On this page