AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

2 tools match

  • Nikto

    Chris Sullo and contributors

    DAST

    Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.

    Open source
    Established Verified
  • Nuclei

    ProjectDiscovery

    DAST

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source
    Established Verified
  • Nikto

    Chris Sullo and contributors

    Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.

    Open source Established
    DAST
  • Nuclei

    ProjectDiscovery

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source Established
    DAST
Tick up to 4 tools above.