Skip to main content

Overview

Security rules define the code vulnerabilities Cysmiq can detect. This page shows coverage by impact category and language. Secrets scanning is documented separately in Secrets.

Impact coverage by language

ImpactJavaScriptTypeScriptPythonJavaGoPHPC#
Execute CommandsYesYesYesYesYesYesYes
Takeover Accounts---Yes-YesYes
Gain AccessYesYesYesYesYesYesYes
Access DataYesYesYesYesYesYesYes
Access FilesYesYesYesYesYesYesYes
Intercept TrafficYesYesYesYesYesYesYes
Insufficient Data ProtectionYesYesYesYesYesYesYes
Bypass Cryptographic ControlsYesYes-YesYes-Yes
Facilitate Client-side AttacksYesYesYesYesYesYesYes
Access Application State----YesYesYes
Evade Detection---Yes---
Degrade PerformanceYesYes--Yes--
  • Yes means at least one rule maps to the impact for that language
  • - means no current coverage
  • Coverage includes core language rules plus all library rule packs
  • Obtain Secrets is covered by secrets scanning and omitted here
  • See Impacts for CWE mappings

Library rule packs

Library rule packs add coverage for specific frameworks and libraries beyond core language rules.