AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

13 tools match

  • AppCheck

    AppCheck

    DAST

    Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.

    Commercial
    Established
  • AppTrana

    Indusface

    DAST

    Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.

    Commercial
    Established
  • Astra Security

    Astra Security

    DAST

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial
    Growing
  • Beagle Security

    Beagle Security

    DAST

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial
    Growing
  • Bright Security

    Bright Security

    DAST

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium
    Growing
  • Detectify

    Detectify

    DAST

    Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.

    Commercial
    Established
  • Escape

    Escape Technologies

    DAST

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial
    Growing
  • AppCheck

    AppCheck

    Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.

    Commercial Established
    DAST
  • AppTrana

    Indusface

    Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.

    Commercial Established
    DAST
  • Astra Security

    Astra Security

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial Growing
    DAST
  • Beagle Security

    Beagle Security

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial Growing
    DAST
  • Bright Security

    Bright Security

    Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.

    Freemium Growing
    DAST
  • Detectify

    Detectify

    Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.

    Commercial Established
    DAST
  • Escape

    Escape Technologies

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial Growing
    DAST
  • Intruder

    Intruder

    DAST

    Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.

    Commercial
    Growing
  • Invicti

    Invicti Security

    DAST

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial
    Established
  • Nuclei

    ProjectDiscovery

    DAST

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source
    Established Verified
  • Pentest Tools

    Pentest-Tools.com

    DAST

    Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.

    Commercial
    Growing
  • DAST

    Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial
    Established
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • Intruder

    Intruder

    Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.

    Commercial Growing
    DAST
  • Invicti

    Invicti Security

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial Established
    DAST
  • Nuclei

    ProjectDiscovery

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source Established
    DAST
  • Pentest Tools

    Pentest-Tools.com

    Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.

    Commercial Growing
    DAST
  • Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.

    Commercial Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
Tick up to 4 tools above.