Catalog comparison
Side-by-side facts from the TestGuild Tool Matcher catalog. Empty cells mean the catalog does not list that attribute — not that the product lacks it.
Open-source automated DAST framework for Android apps from PhonePe. Drop in an APK (or target a package on a connected device/emulator): Thorfinn decompiles with JADX/APKTool, traces Android-specific taint flows (intents, deep links, WebViews, Content Providers) with Tai-e plus Semgrep, TruffleHog, and Manifest checks, then uses LLMs (OpenAI, Anthropic, Gemini, or GitHub Copilot CLI) to triage findings, generate adb PoCs, and validate exploitability on-device. HTML/JSON reports include source-to-sink paths and runtime evidence. Apache-2.0.
AI-powered static code analysis and unit testing solution for C/C++ development. Ensures compliance with safety and security standards like MISRA, CERT, AUTOSAR C++14, ISO 26262, and DO-178C with automated vulnerability detection and ML-based violation prioritization.
Primary testing surface
Thorfinn
Security
Parasoft C/C++test
Security
Primary capability
Thorfinn
Security
Parasoft C/C++test
Security
License and pricing
Thorfinn
free
Parasoft C/C++test
paid
Free trial
Thorfinn
No
Parasoft C/C++test
No
Complexity
Thorfinn
advanced
Parasoft C/C++test
advanced
Team fit
Thorfinn
enterprise, large, medium, small
Parasoft C/C++test
enterprise, large, medium
Test authoring languages
Thorfinn
Java, Kotlin, Python
Parasoft C/C++test
C, C++, C++11, C++14, C++17, C++20, Embedded C
Supported platforms
Thorfinn
android, apk, cli, emulators, linux, macos, real devices
Parasoft C/C++test
CI/CD Pipelines, Cross-platform, Eclipse, Embedded Systems, Jenkins, Linux, macOS, VS Code, Windows
MCP server
Thorfinn
No
Parasoft C/C++test
No
Key features (catalog)
Thorfinn
Automated Android DAST from APK / installed package, Detects intent redirection, WebView issues, Content Provider path traversal, and more, Diff and re-run modes to skip prior findings and save LLM tokens, HTML and JSON reports with taint paths, payloads, and runtime evidence, Integrates Tai-e, Semgrep, TruffleHog, and PermissionChecker, LLM triage and PoC generation (OpenAI, Anthropic, Gemini, GitHub Copilot CLI), Manifest auditing for exported components, permissions, and insecure flags, On-device/emulator PoC execution via adb with interactive or auto-approve modes, Open-source Apache-2.0 (PhonePe), Source-to-sink taint tracing across intents, extras, deep links, and components
Parasoft C/C++test
AI-generated code fix recommendations, AI-powered static code analysis, Automated code quality checks, Automated defect prevention, Automated risk mitigation, AUTOSAR C++14 compliance checking, Build system integration (Maven, Gradle), CERT C/C++ compliance checking, CI/CD pipeline integration, Code complexity analysis +31 more
Limitations (catalog)
Thorfinn
Android-only — not a web, iOS, or general network DAST scanner, Authorized testing only — not for unauthorized app assessment, Large APKs may need heap/time limits; whole-program analysis can be heavy, LLM-generated adb commands should be reviewed; auto-approve is unsafe on untrusted targets, Requires Java 17, Maven, ADB, connected device/emulator, and LLM API access for full triage/PoC flow
Parasoft C/C++test
Complex configuration for compliance standards, Enterprise pricing model, Limited community support compared to open source, Limited to C/C++ languages, May produce false positives requiring triage, Requires dedicated infrastructure setup, Requires training for optimal usage, Resource intensive for large codebases +2 more
| Attribute | Thorfinn | Parasoft C/C++test |
|---|---|---|
| Primary testing surface | Security | Security |
| Primary capability | Security | Security |
| License and pricing | free | paid |
| Free trial | No | No |
| Complexity | advanced | advanced |
| Team fit | enterprise, large, medium, small | enterprise, large, medium |
| Test authoring languages | Java, Kotlin, Python | C, C++, C++11, C++14, C++17, C++20, Embedded C |
| Supported platforms | android, apk, cli, emulators, linux, macos, real devices | CI/CD Pipelines, Cross-platform, Eclipse, Embedded Systems, Jenkins, Linux, macOS, VS Code, Windows |
| MCP server | No | No |
| Key features (catalog) | Automated Android DAST from APK / installed package, Detects intent redirection, WebView issues, Content Provider path traversal, and more, Diff and re-run modes to skip prior findings and save LLM tokens, HTML and JSON reports with taint paths, payloads, and runtime evidence, Integrates Tai-e, Semgrep, TruffleHog, and PermissionChecker, LLM triage and PoC generation (OpenAI, Anthropic, Gemini, GitHub Copilot CLI), Manifest auditing for exported components, permissions, and insecure flags, On-device/emulator PoC execution via adb with interactive or auto-approve modes, Open-source Apache-2.0 (PhonePe), Source-to-sink taint tracing across intents, extras, deep links, and components | AI-generated code fix recommendations, AI-powered static code analysis, Automated code quality checks, Automated defect prevention, Automated risk mitigation, AUTOSAR C++14 compliance checking, Build system integration (Maven, Gradle), CERT C/C++ compliance checking, CI/CD pipeline integration, Code complexity analysis +31 more |
| Limitations (catalog) | Android-only — not a web, iOS, or general network DAST scanner, Authorized testing only — not for unauthorized app assessment, Large APKs may need heap/time limits; whole-program analysis can be heavy, LLM-generated adb commands should be reviewed; auto-approve is unsafe on untrusted targets, Requires Java 17, Maven, ADB, connected device/emulator, and LLM API access for full triage/PoC flow | Complex configuration for compliance standards, Enterprise pricing model, Limited community support compared to open source, Limited to C/C++ languages, May produce false positives requiring triage, Requires dedicated infrastructure setup, Requires training for optimal usage, Resource intensive for large codebases +2 more |
Guidance below is inferred only from catalog differences. It is not a winner pick.