Rapid7 InsightAppSec
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
RunSybil
Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
RunSybil
Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
ZeroThreat
Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
ZeroThreat
Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.