AppSecNews

IAST

Interactive Application Security Testing

Instrument the running application to observe real data flow during functional testing.

6 tools profiled

How it differs An agent inside the running app reports vulnerabilities while tests exercise it. DAST sees only HTTP responses; RASP uses similar instrumentation to block attacks in production instead.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

2 tools match

  • Acunetix AcuSensor

    Invicti Security

    IAST

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial
    Established
  • Adds taint tracking to Datadog's existing tracing libraries so vulnerable code paths surface as part of the same telemetry pipeline as traces and logs.

    Commercial
    Growing
  • Acunetix AcuSensor

    Invicti Security

    Server side sensor that runs inside the application under test and feeds Acunetix dynamic scans file, line and query level context for its findings.

    Commercial Established
    IAST
  • Adds taint tracking to Datadog's existing tracing libraries so vulnerable code paths surface as part of the same telemetry pipeline as traces and logs.

    Commercial Growing
    IAST
Tick up to 4 tools above.