Acunetix
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
Black Duck
Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
Black Duck
Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
ForAllSecure
Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
ForAllSecure
Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.