AppSecNews

IAST

Interactive Application Security Testing

Instrument the running application to observe real data flow during functional testing.

6 tools profiled

How it differs An agent inside the running app reports vulnerabilities while tests exercise it. DAST sees only HTTP responses; RASP uses similar instrumentation to block attacks in production instead.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

1 tool match

  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial
    Established
  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial Established
    IAST
Tick up to 4 tools above.