AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

5 tools match

  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Dastardly

    PortSwigger

    DAST

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free
    Established Verified
  • GitLab DAST

    GitLab

    DAST

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial
    Established
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Dastardly

    PortSwigger

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free Established
    DAST
  • GitLab DAST

    GitLab

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
Tick up to 4 tools above.