Arachni
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.