AppSecNews

Roundups

Guides and comparisons for choosing tools, written to the same editorial standard as the profiles.

Secret Scanning roundup

The 10 Best Secret Scanning Tools

Ten secret scanning tools compared by where they sit in the lifecycle, whether they verify credentials, and whether they carry a leak through to rotation.

12 min read

SCA roundup

The 10 Best Software Composition Analysis Tools

Ten software composition analysis tools picked for distinct jobs: reachability triage, license compliance, SBOM monitoring, malicious package detection and patching.

12 min read

SAST roundup

The 10 Best SAST Tools

A practitioner's guide to ten static analysis tools, chosen for distinct scenarios rather than ranked, with the trade-offs each one brings.

12 min read

RASP roundup

The 10 Best RASP Tools

A practitioner's guide to runtime application self-protection: true in-process agents, mobile hardening libraries, and the WAF-adjacent tools often filed alongside them.

12 min read

Mobile Security roundup

The 10 Best Mobile Application Security Tools

Ten mobile application security tools chosen for distinct scenarios, from automated binary scanning to runtime instrumentation, with honest caveats.

12 min read

IAST roundup

The 6 Best IAST Tools

A practitioner's guide to interactive application security testing tools, picked for distinct scenarios rather than ranked, with an honest caveat on each.

12 min read

DAST roundup

The 10 Best DAST Tools

A practitioner's guide to dynamic application security testing tools, picked for distinct scenarios rather than ranked, with an honest caveat on each.

12 min read

Container Security roundup

The 8 Best Container Security Tools

A practitioner's guide to eight container and Kubernetes security tools, picked for distinct scenarios rather than ranked, with honest trade-offs.

12 min read

ASPM roundup

The 10 Best ASPM Tools

A practitioner's guide to ten application security posture management platforms, chosen for distinct scenarios rather than ranked, with honest caveats.

12 min read

API Security roundup

The 9 Best API Security Tools

A practitioner's guide to API discovery, testing and runtime protection tools, chosen for distinct scenarios rather than ranked, with an honest caveat on each.

12 min read

AI Security roundup

The 10 Best AI Security Tools

A practitioner's guide to AI and LLM security tooling: red teaming, runtime guardrails, model artifact scanning, agent controls and governance.

12 min read