Scanners & Frameworks
Beacon Standards integrates with industry-leading security tools and aligns with established penetration testing frameworks.
Supported Scanners
Nmap
Network DiscoveryIndustry-standard network reconnaissance tool for port scanning, service detection, and OS fingerprinting. Essential for Tier 1 network findings.
Nessus Professional
Vulnerability ScanningComprehensive vulnerability scanner for network assets, cloud infrastructure, and web applications. Provides CVE-based findings with CVSS scoring.
Burp Suite Professional
Web Application TestingThe de facto standard for web application penetration testing. Identifies OWASP Top 10 vulnerabilities through automated and manual testing.
PROWLER
Cloud SecurityOpen-source cloud security tool for AWS, Azure, and GCP. Performs CIS Benchmark checks and identifies cloud misconfigurations.
Cloudsploit
Cloud SecurityMulti-cloud security scanning for AWS, Azure, GCP, and Oracle Cloud. Focuses on configuration issues and compliance violations.
Nuclei
Vulnerability ScanningFast, template-based vulnerability scanner. Community-maintained templates for CVE detection and misconfiguration identification.
Testing Frameworks
OWASP Testing Guide
v4.2Comprehensive web application security testing methodology. The definitive guide for manual and automated web security assessments.
MITRE ATT&CK
v14Adversary tactics and techniques knowledge base. Beacon Tier 1 findings map directly to ATT&CK techniques for threat-informed defense.
PTES
1.0Penetration Testing Execution Standard. Provides a common language and methodology for penetration testing engagements.
NIST CSF
2.0Cybersecurity Framework for risk management. Beacon tiers align with NIST CSF functions for organizational context.
Integration Strategy
Configure Scanners
Deploy selected scanners with Beacon-aligned policies. Focus on high-value findings that map to tier classifications.
Normalize Output
Map scanner findings to Beacon tiers using CVSS scores, MITRE techniques, and compliance framework references.
Apply SLAs
Route findings to appropriate teams with tier-based SLAs. Track remediation metrics and escalate overdue items.