Hi peers,
We have developed an eCommerce system using the Microsoft Technology Stack.
Now, we would like to perform Vulnerability Assessment and Penetration Testing (VAPT) of this system using a comprehensive tool.
Can anyone recommend a tool that (preferably, an open-source one) to perform VAPT on the eCommerce application before releasing it to the client on production?
Thanks for your help!
You can start with OpenVAS (an excellent tool during "first steps").
Depending on your goals, you can add Kali Linux during tests for "deeper inspection" validation. Remember that Microsoft offers some security tools and consulting based on your "contract/plan".