w3af
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.