Abstract: A security scanner reviews the configuration of a SaaS environment, analyzes the static code of the environment, and generates malicious code to create a runtime security analysis engine that is executed to determine security vulnerabilities within the SaaS environment.