Categories
236 tools in 13 categories. Each tool sits in exactly one. The highlighted line on each tile says what the category covers and what it does not, which is where SAST, SCA and IAST usually get confused.
-
All 31 SAST toolsSAST 31 tools
Static Application Security Testing
Analyze source code or bytecode for vulnerable patterns without running the application.
Reads the code you wrote without running it. SCA checks the third party packages you depend on; IAST watches the running app while your tests exercise it.
-
All 28 SCA toolsSCA 28 tools
Software Composition Analysis
Identify open-source dependencies and match them against known vulnerability and license data.
Checks the open source packages you depend on for known vulnerabilities and license obligations. Flaws in code you wrote are SAST territory.
Best known
-
All 34 DAST toolsDAST 34 tools
Dynamic Application Security Testing
Probe a running application from the outside, the way an attacker would.
Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Best known
-
All 6 IAST toolsIAST 6 tools
Interactive Application Security Testing
Instrument the running application to observe real data flow during functional testing.
An agent inside the running app reports vulnerabilities while tests exercise it. DAST sees only HTTP responses; RASP uses similar instrumentation to block attacks in production instead.
Best known
-
All 9 RASP toolsRASP 9 tools
Runtime Application Self-Protection
Detect and block attacks from inside the running application process.
Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.
Best known
-
All 45 AI Security toolsAI Security 45 tools
AI and LLM Security
Test and defend models, prompts, agents and the infrastructure around them.
Tests and guards models, LLM applications and agents against prompt injection, jailbreaks and data leakage. Scanning an AI app's own code is still SAST or SCA.
Best known
-
All 9 API Security toolsAPI Security 9 tools
API Discovery and Protection
Inventory APIs, test their authorization logic, and watch runtime traffic for abuse.
Discovers, tests and protects APIs specifically, often working from the OpenAPI contract or live traffic. General web scanning of the same endpoints is DAST.
Best known
-
All 17 IaC Security toolsIaC Security 17 tools
Infrastructure as Code Security
Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.
Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.
-
All 16 ASPM toolsASPM 16 tools
Application Security Posture Management
Aggregate, deduplicate and prioritize findings across every other tool in the program.
Collects findings from your other scanners, deduplicates them and ranks them by application context. It aggregates rather than scans, though some platforms bundle scanners of their own.
Best known
-
All 23 Mobile Security toolsMobile Security 23 tools
Mobile Application Security
Analyze, instrument and harden Android and iOS applications.
Analyses Android and iOS app binaries, statically and at runtime. The backend APIs an app calls belong to API security or DAST.
-
All 8 Container Security toolsContainer Security 8 tools
Container and Kubernetes Security
Scan images, enforce policy and watch runtime behavior in containerized workloads.
Scans container images and enforces policy on running containers and Kubernetes workloads. Checking the manifests before deploy is IaC security.
-
All 9 Secret Scanning toolsSecret Scanning 9 tools
Secret Scanning
Find credentials, tokens and keys committed to code or exposed in build systems.
Finds credentials committed to code, git history and build artifacts. Vulnerable dependencies are SCA, not this.
Best known
-
All 1 WAF toolWAF 1 tool
Web Application Firewall
Filter and block malicious HTTP traffic in front of the application.
Filters malicious HTTP traffic in front of the application. RASP does a similar job from inside the app, with its context.
Best known