AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

10 tools match

  • Beagle Security

    Beagle Security

    DAST

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial
    Growing
  • DAST

    Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial
    Established
  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Burp Suite

    PortSwigger

    DAST

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium
    Established Verified
  • Dastardly

    PortSwigger

    DAST

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free
    Established Verified
  • Beagle Security

    Beagle Security

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial Growing
    DAST
  • Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial Established
    DAST
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Burp Suite

    PortSwigger

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium Established
    DAST
  • Dastardly

    PortSwigger

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free Established
    DAST
  • Escape

    Escape Technologies

    DAST

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial
    Growing
  • Mayhem

    ForAllSecure

    DAST

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial
    Growing
  • Nuclei

    ProjectDiscovery

    DAST

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source
    Established Verified
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • Escape

    Escape Technologies

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial Growing
    DAST
  • Mayhem

    ForAllSecure

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial Growing
    DAST
  • Nuclei

    ProjectDiscovery

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
Tick up to 4 tools above.