AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

16 tools match

  • Acunetix

    Invicti Security

    DAST

    Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.

    Commercial
    Established
  • Beagle Security

    Beagle Security

    DAST

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial
    Growing
  • DAST

    Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial
    Established
  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Burp Suite

    PortSwigger

    DAST

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium
    Established Verified
  • Dastardly

    PortSwigger

    DAST

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free
    Established Verified
  • DAST

    Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial
    Established
  • HCL AppScan

    HCLSoftware

    DAST

    Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.

    Commercial
    Established
  • Acunetix

    Invicti Security

    Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.

    Commercial Established
    DAST
  • Beagle Security

    Beagle Security

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial Growing
    DAST
  • Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial Established
    DAST
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Burp Suite

    PortSwigger

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium Established
    DAST
  • Dastardly

    PortSwigger

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free Established
    DAST
  • Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial Established
    DAST
  • HCL AppScan

    HCLSoftware

    Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.

    Commercial Established
    DAST
  • Invicti

    Invicti Security

    DAST

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial
    Established
  • Mayhem

    ForAllSecure

    DAST

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial
    Growing
  • Qualys WAS

    Qualys

    DAST

    Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.

    Commercial
    Established
  • DAST

    Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial
    Established
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • DAST

    Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial
    Established
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial
    Established
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • Invicti

    Invicti Security

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial Established
    DAST
  • Mayhem

    ForAllSecure

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial Growing
    DAST
  • Qualys WAS

    Qualys

    Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.

    Commercial Established
    DAST
  • Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial Established
    DAST
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial Established
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
Tick up to 4 tools above.