AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

7 tools match

  • AppTrana

    Indusface

    DAST

    Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.

    Commercial
    Established
  • Astra Security

    Astra Security

    DAST

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial
    Growing
  • Beagle Security

    Beagle Security

    DAST

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial
    Growing
  • DAST

    Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial
    Established
  • AppTrana

    Indusface

    Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.

    Commercial Established
    DAST
  • Astra Security

    Astra Security

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial Growing
    DAST
  • Beagle Security

    Beagle Security

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial Growing
    DAST
  • Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial Established
    DAST
  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Escape

    Escape Technologies

    DAST

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial
    Growing
  • GitLab DAST

    GitLab

    DAST

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial
    Established
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Escape

    Escape Technologies

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial Growing
    DAST
  • GitLab DAST

    GitLab

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial Established
    DAST
Tick up to 4 tools above.