AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

14 tools match

  • Arachni

    Arachni Project (Tasos Laskos)

    DAST

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source
    Established
  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Caido

    Caido Labs

    DAST

    Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.

    Not recorded
    Growing
  • Dastardly

    PortSwigger

    DAST

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free
    Established Verified
  • Escape

    Escape Technologies

    DAST

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial
    Growing
  • Fluid Attacks

    Fluid Attacks

    DAST

    Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.

    Commercial
    Growing
  • Nikto

    Chris Sullo and contributors

    DAST

    Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.

    Open source
    Established Verified
  • Arachni

    Arachni Project (Tasos Laskos)

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source Established
    DAST
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Caido

    Caido Labs

    Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.

    Not recorded Growing
    DAST
  • Dastardly

    PortSwigger

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free Established
    DAST
  • Escape

    Escape Technologies

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial Growing
    DAST
  • Fluid Attacks

    Fluid Attacks

    Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.

    Commercial Growing
    DAST
  • Nikto

    Chris Sullo and contributors

    Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.

    Open source Established
    DAST
  • Nuclei

    ProjectDiscovery

    DAST

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source
    Established Verified
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • Strix

    Strix

    DAST

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source
    Emerging
  • DAST

    Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial
    Established
  • w3af

    Andres Riancho and contributors

    DAST

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source
    Established
  • Wapiti

    Wapiti project

    DAST

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source
    Established Verified
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • Nuclei

    ProjectDiscovery

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • Strix

    Strix

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source Emerging
    DAST
  • Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial Established
    DAST
  • w3af

    Andres Riancho and contributors

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source Established
    DAST
  • Wapiti

    Wapiti project

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source Established
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
Tick up to 4 tools above.