AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals

34 tools

  • DAST

    Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial
    Established
  • RunSybil

    RunSybil

    DAST

    Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.

    Commercial
    Emerging
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • Strix

    Strix

    DAST

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source
    Emerging
  • DAST

    Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial
    Established
  • Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial Established
    DAST
  • RunSybil

    RunSybil

    Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.

    Commercial Emerging
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • Strix

    Strix

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source Emerging
    DAST
  • Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial Established
    DAST
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial
    Established
  • w3af

    Andres Riancho and contributors

    DAST

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source
    Established
  • Wapiti

    Wapiti project

    DAST

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source
    Established Verified
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • ZeroThreat

    ZeroThreat

    DAST

    Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

    Freemium
    Emerging
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial Established
    DAST
  • w3af

    Andres Riancho and contributors

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source Established
    DAST
  • Wapiti

    Wapiti project

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source Established
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
  • ZeroThreat

    ZeroThreat

    Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

    Freemium Emerging
    DAST
Tick up to 4 tools above.