AppSecNews
SAST Commercial Established

Parasoft

by Parasoft

Family of static analysis and automated testing products for C, C++, Java and .NET, oriented toward safety and security coding standard compliance.

Visit parasoft.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Parasoft in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Product naming and which analysis capabilities sit in which product, confirm against the current catalog
  • Language coverage beyond C, C++, Java and .NET, confirm
  • Integration list: confirm current supported connectors

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Parasoft is a family of analysis and testing products rather than a single scanner. The static analysis engines sit in language specific products: C and C++ in one, Java in another, .NET in a third, with a shared reporting and policy layer above them. Analysis combines several techniques. Pattern based checkers catch local coding standard violations. Flow analysis simulates execution paths to find null dereferences, buffer overruns, resource leaks and tainted data reaching a sensitive operation. Metrics analysis reports complexity and structural measures that certain standards require you to bound.

The part that distinguishes Parasoft from a pure scanner is what surrounds the analysis. It generates and maintains unit tests, measures structural code coverage including the modified condition and decision coverage that avionics software must demonstrate, and packages the results as compliance evidence against MISRA, AUTOSAR, CERT, CWE, OWASP and the process expectations of standards such as ISO 26262, IEC 62304 and DO-178. Findings can be traced to requirements, and violations can be formally deviated with a documented justification, which is a workflow auditors look for and most security scanners do not offer.

Where it fits

It lives in regulated development programs. Developers run analysis in the IDE against the same rule set the build enforces, the pipeline runs the full analysis and coverage collection, and a reporting server holds the history that a certification package draws from. It assumes a working build and a project structure someone is willing to configure carefully. The operator is typically a software quality, verification or functional safety engineer, not an application security analyst.

Strengths

  • Compliance reporting and formal deviation workflow that map directly to certification evidence, not just a list of findings.
  • Flow analysis plus unit test generation and structural coverage measurement in one toolchain, which avoids stitching several vendors together.
  • Long established C and C++ support covering embedded compilers and older language dialects.
  • Deep rule coverage for MISRA and AUTOSAR, maintained as those standards change.

Limitations

  • Significant configuration and licensing complexity. The product split by language means working out what you actually need is a project in itself.
  • Heavyweight for teams that just want vulnerability findings. Much of the value is in compliance machinery you will not use outside a regulated context.
  • Web application vulnerability coverage is weaker than in tools built for modern server side and JavaScript stacks.

Who it suits

Built for automotive, medical, industrial and aerospace software teams who have to prove standard compliance and would otherwise assemble three tools to do it. A web or cloud native team with no certification obligation will find the overhead disproportionate to what they get.

Used Parasoft? Recommend it under your own name and title.

Recommend this tool