Back to all tools

Micro Focus Fortify
Enterprise-grade static and dynamic application security testing.
Licensed
Security Static Application Security Testing (SAST)
Overview
A comprehensive SAST tool to identify security vulnerabilities in source code and third-party libraries.
Key Features
- SAST for 27+ programming languages with deep taint analysis
- Fortify Software Security Center (SSC) for centralised issue management
- ScanCentral for distributed, scalable scan execution
- IDE plugins for Visual Studio, Eclipse, and IntelliJ IDEA
- On-Demand DAST via Fortify on Demand
- Issue correlation and deduplication across multiple scan types
Real-World Workflows
Enterprise secure SDLC integration
- 1Integrate the Fortify Jenkins plugin to trigger scans on every build
- 2SAST scan analyses the compiled code and produces an FPR report
- 3Upload results to SSC for centralised triage and audit trail
- 4Assign critical findings to developers with remediation guidance
- 5Dashboard tracks open vulnerabilities and time-to-remediation KPIs
Getting Started
# Fortify requires a commercial license. # Basic scan with Fortify SCA: sourceanalyzer -b myapp mvn compile sourceanalyzer -b myapp -scan -f myapp.fpr
Compare Alternatives
See how Micro Focus Fortify stacks up against similar tools.