What’s New in 2012 Edition
Mature Security Inspection Techniques
Since “N-Stealth HTTP Security Scanner” debut in 2000, N-Stalker is providing security assessment technology for over a decade. It is founded upon its own “Component-oriented Web Application Security Analysis” patent-pending technology, allowing for an independent and cost-effective solution for either SOHO and Corporate markets.
New Attack Engine
N-Stalker 2012 introduces a new attack engine based on LUA language. It provides a flexible integration and allow for a fast introduction of new attack patterns. From OWASP Top 10 to CWE Top 25, N-Stalker 2012 provides way to integrate your own signatures into his own inspection engine.
Mature Spider Engine for AJAX requests
N-Stalker Scanner 2012 debuts a new Spider Engine that will enhance your scan experience by crawling straight through modern Web Applications. By integrating a modern and stable open-source Javascript engine, N-Stalker will interpret scripts and integrates your HTML’s DOM (Document Object Model) just like if a human-guided web browser was navigating through your application. Proprietary objects such as Shockwave/Flash applications will be easily processed allowing for a transparent crawling process.
Integrate Web Proxy for “drive-thru” attacks
A new web proxy is fully integrated into N-Stalker’s spider engine to allow for a drive-thru navigation and security testing for restricted and well-defined scopes. Just open your favorite browser, run your test cases and record well-known application transactions that can be used for an extended security assessment.
Support for Manual Security Analysis
Do you need to run restricted tests against your application? Manual security tests allows you to control which and where the security tests can be applied within your web application. Just point the resource and click to initiate a very specific assessment.
Improved Security Tools
A wide range of security tools is now available to assist your assessment, including Web Proxy, Web Server Discovery, HTTP Brute Force, HTTP Encoder, HTTP Load Tester and featuring the exclusive “Google Hacking Database” Tool, that allows you to search for “Google-like” patterns against Web Application’s site tree.


