AppSecNews

IAST

Interactive Application Security Testing

Instrument the running application to observe real data flow during functional testing.

6 tools profiled

How it differs An agent inside the running app reports vulnerabilities while tests exercise it. DAST sees only HTTP responses; RASP uses similar instrumentation to block attacks in production instead.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

3 tools match

  • Acunetix AcuSensor

    Invicti Security

    IAST

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial
    Established
  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial
    Established
  • HCL AppScan IAST

    HCL Software

    IAST

    Agent based runtime testing that observes application behavior during functional or automated testing and reports confirmed vulnerabilities into the AppScan console.

    Commercial
    Established
  • Acunetix AcuSensor

    Invicti Security

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial Established
    IAST
  • Runtime agent that pairs with Fortify WebInspect dynamic scans to report the server side code path behind each finding and expand attack surface discovery.

    Commercial Established
    IAST
  • HCL AppScan IAST

    HCL Software

    Agent based runtime testing that observes application behavior during functional or automated testing and reports confirmed vulnerabilities into the AppScan console.

    Commercial Established
    IAST
Tick up to 4 tools above.