David and Eric are releasing a new application scanning tool, Grendel-Scan. David promises this tool will be something even the average security manager, or QSA, could use to do app scanning. One of the nicest features of this new tool is that it is extensible and can have capabilities added to it as needed. In the nature of full disclosure, I should also point out that David is a co-worker and one of the best pen testers I’ve ever known.
I’ll add a direct link to Grendel-Scan as soon as I have it. Edit: David provided the link almost immediately
Defcon Microcast 11: David Byrne and Eric Duprey