AppSecNews

IAST

Interactive Application Security Testing

Instrument the running application to observe real data flow during functional testing.

6 tools profiled

How it differs An agent inside the running app reports vulnerabilities while tests exercise it. DAST sees only HTTP responses; RASP uses similar instrumentation to block attacks in production instead.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

6 tools match

  • Acunetix AcuSensor

    Invicti Security

    IAST

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial
    Established
  • Contrast Security

    Contrast Security

    IAST

    Agent based platform that instruments running applications to detect vulnerabilities, inventory libraries actually loaded, and optionally block attacks in production.

    Commercial
    Established
  • Adds taint tracking to Datadog's existing tracing libraries so vulnerable code paths surface as part of the same telemetry pipeline as traces and logs.

    Commercial
    Growing
  • Acunetix AcuSensor

    Invicti Security

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial Established
    IAST
  • Contrast Security

    Contrast Security

    Agent based platform that instruments running applications to detect vulnerabilities, inventory libraries actually loaded, and optionally block attacks in production.

    Commercial Established
    IAST
  • Adds taint tracking to Datadog's existing tracing libraries so vulnerable code paths surface as part of the same telemetry pipeline as traces and logs.

    Commercial Growing
    IAST
  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial
    Established
  • HCL AppScan IAST

    HCL Software

    IAST

    Agent based runtime testing that observes application behavior during functional or automated testing and reports confirmed vulnerabilities into the AppScan console.

    Commercial
    Established
  • Seeker IAST

    Black Duck

    IAST

    Agent based interactive testing that instruments the running application, tracks tainted and sensitive data through it, and replays requests to confirm exploitability.

    Commercial
    Established
  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial Established
    IAST
  • HCL AppScan IAST

    HCL Software

    Agent based runtime testing that observes application behavior during functional or automated testing and reports confirmed vulnerabilities into the AppScan console.

    Commercial Established
    IAST
  • Seeker IAST

    Black Duck

    Agent based interactive testing that instruments the running application, tracks tainted and sensitive data through it, and replays requests to confirm exploitability.

    Commercial Established
    IAST
Tick up to 4 tools above.