Best Dynamic Application Security Testing (DAST) Software

LW
Researched and written by Lauren Worth

Dynamic application security testing (DAST) tools automate security tests for a variety of real-world threats. These tools typically test HTTP and HTML interfaces of web applications. DAST is a black-box testing method, meaning it is performed from the outside. Companies use these tools to identify vulnerabilities in their applications from an external perspective to better simulate threats most easily accessed by hackers outside their organization. There are similarities between DAST tools and other application security and vulnerability management solutions, but most other technologies perform internal tests and code analysis instead of focusing on black-box testing.

SAST vs DAST — Learn the difference

To qualify for inclusion in the Dynamic Application Security Testing (DAST) category, a product must:

Test applications in their operational state
Perform external black-box security tests
Trace penetrations and exploits to their sources

Best Dynamic Application Security Testing (DAST) Software At A Glance

Highest Performer:
Best Contender:
Most Trending:
Show LessShow More
Best Contender:
Most Trending:

G2 takes pride in showing unbiased reviews on user satisfaction in our ratings and reports. We do not allow paid placements in any of our ratings, rankings, or reports. Learn about our scoring methodologies.

No filters applied
77 Listings in Dynamic Application Security Testing (DAST) Available
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint

    Users
    No information available
    Industries
    • Information Technology and Services
    • Computer & Network Security
    Market Segment
    • 54% Enterprise
    • 28% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • HCL AppScan Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    13
    Scanning Efficiency
    13
    Security
    12
    Vulnerability Detection
    11
    Accuracy of Results
    8
    Cons
    Expensive
    8
    Scanning Issues
    6
    Complexity
    5
    Slow Scanning
    4
    Difficult Setup
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • HCL AppScan features and usability ratings that predict user satisfaction
    8.8
    Has the product been a good partner in doing business?
    Average: 9.2
    8.1
    API / Integrations
    Average: 8.4
    8.2
    Detection Rate
    Average: 8.6
    7.9
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    1999
    HQ Location
    Noida, Uttar Pradesh
    Twitter
    @hcltech
    444,354 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    244,701 employees on LinkedIn®
    Ownership
    NSE - National Stock Exchange of India
Product Description
How are these determined?Information
This description is provided by the seller.

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint

Users
No information available
Industries
  • Information Technology and Services
  • Computer & Network Security
Market Segment
  • 54% Enterprise
  • 28% Small-Business
HCL AppScan Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
13
Scanning Efficiency
13
Security
12
Vulnerability Detection
11
Accuracy of Results
8
Cons
Expensive
8
Scanning Issues
6
Complexity
5
Slow Scanning
4
Difficult Setup
3
HCL AppScan features and usability ratings that predict user satisfaction
8.8
Has the product been a good partner in doing business?
Average: 9.2
8.1
API / Integrations
Average: 8.4
8.2
Detection Rate
Average: 8.6
7.9
Test Automation
Average: 8.8
Seller Details
Year Founded
1999
HQ Location
Noida, Uttar Pradesh
Twitter
@hcltech
444,354 Twitter followers
LinkedIn® Page
www.linkedin.com
244,701 employees on LinkedIn®
Ownership
NSE - National Stock Exchange of India
(36)4.7 out of 5
Optimized for quick response
2nd Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empow

    Users
    No information available
    Industries
    • Computer Software
    • Financial Services
    Market Segment
    • 53% Mid-Market
    • 36% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Jit Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    19
    Security
    18
    Integration Support
    15
    Customer Support
    14
    Features
    13
    Cons
    Poor User Interface
    6
    Integration Issues
    4
    Limited Cloud Integration
    4
    Limited Features
    4
    Complexity
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Jit features and usability ratings that predict user satisfaction
    9.7
    Has the product been a good partner in doing business?
    Average: 9.2
    8.7
    API / Integrations
    Average: 8.4
    9.0
    Detection Rate
    Average: 8.6
    8.5
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    jit
    Company Website
    Year Founded
    2021
    HQ Location
    Boston, MA
    Twitter
    @jit_io
    512 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    97 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empow

Users
No information available
Industries
  • Computer Software
  • Financial Services
Market Segment
  • 53% Mid-Market
  • 36% Small-Business
Jit Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
19
Security
18
Integration Support
15
Customer Support
14
Features
13
Cons
Poor User Interface
6
Integration Issues
4
Limited Cloud Integration
4
Limited Features
4
Complexity
3
Jit features and usability ratings that predict user satisfaction
9.7
Has the product been a good partner in doing business?
Average: 9.2
8.7
API / Integrations
Average: 8.4
9.0
Detection Rate
Average: 8.6
8.5
Test Automation
Average: 8.8
Seller Details
Seller
jit
Company Website
Year Founded
2021
HQ Location
Boston, MA
Twitter
@jit_io
512 Twitter followers
LinkedIn® Page
www.linkedin.com
97 employees on LinkedIn®

This is how G2 Deals can help you:

  • Easily shop for curated – and trusted – software
  • Own your own software buying journey
  • Discover exclusive deals on software
(43)4.5 out of 5
Optimized for quick response
15th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — AP

    Users
    No information available
    Industries
    • Financial Services
    • Computer Software
    Market Segment
    • 51% Mid-Market
    • 28% Enterprise
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Akto Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    18
    API Testing
    15
    Automation Testing
    13
    Customer Support
    13
    Features
    12
    Cons
    Poor Documentation
    6
    API Issues
    4
    Complexity
    4
    Complex Setup
    4
    Difficult Learning
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Akto features and usability ratings that predict user satisfaction
    9.1
    Has the product been a good partner in doing business?
    Average: 9.2
    9.1
    API / Integrations
    Average: 8.4
    8.1
    Detection Rate
    Average: 8.6
    8.8
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Akto.io
    Company Website
    Year Founded
    2022
    HQ Location
    San Francisco, California
    Twitter
    @Aktodotio
    1,324 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    20 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — AP

Users
No information available
Industries
  • Financial Services
  • Computer Software
Market Segment
  • 51% Mid-Market
  • 28% Enterprise
Akto Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
18
API Testing
15
Automation Testing
13
Customer Support
13
Features
12
Cons
Poor Documentation
6
API Issues
4
Complexity
4
Complex Setup
4
Difficult Learning
4
Akto features and usability ratings that predict user satisfaction
9.1
Has the product been a good partner in doing business?
Average: 9.2
9.1
API / Integrations
Average: 8.4
8.1
Detection Rate
Average: 8.6
8.8
Test Automation
Average: 8.8
Seller Details
Seller
Akto.io
Company Website
Year Founded
2022
HQ Location
San Francisco, California
Twitter
@Aktodotio
1,324 Twitter followers
LinkedIn® Page
www.linkedin.com
20 employees on LinkedIn®
(54)4.7 out of 5
Optimized for quick response
7th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Aikido is an application security (AppSec) platform specifically designed for developers who prioritize their coding tasks over managing security alerts. Our innovative solution consolidates nine esse

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 78% Small-Business
    • 22% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Aikido Security Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    29
    Security
    26
    Easy Integrations
    23
    Easy Setup
    21
    Features
    20
    Cons
    Missing Features
    8
    False Positives
    7
    Limited Features
    7
    Improvement Needed
    6
    Lack of Information
    6
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Aikido Security features and usability ratings that predict user satisfaction
    9.6
    Has the product been a good partner in doing business?
    Average: 9.2
    8.3
    API / Integrations
    Average: 8.4
    10.0
    Detection Rate
    Average: 8.6
    10.0
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2022
    HQ Location
    Ghent, Belgium
    Twitter
    @AikidoSecurity
    1,273 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    50 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Aikido is an application security (AppSec) platform specifically designed for developers who prioritize their coding tasks over managing security alerts. Our innovative solution consolidates nine esse

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 78% Small-Business
  • 22% Mid-Market
Aikido Security Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
29
Security
26
Easy Integrations
23
Easy Setup
21
Features
20
Cons
Missing Features
8
False Positives
7
Limited Features
7
Improvement Needed
6
Lack of Information
6
Aikido Security features and usability ratings that predict user satisfaction
9.6
Has the product been a good partner in doing business?
Average: 9.2
8.3
API / Integrations
Average: 8.4
10.0
Detection Rate
Average: 8.6
10.0
Test Automation
Average: 8.8
Seller Details
Company Website
Year Founded
2022
HQ Location
Ghent, Belgium
Twitter
@AikidoSecurity
1,273 Twitter followers
LinkedIn® Page
www.linkedin.com
50 employees on LinkedIn®
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    StackHawk is a comprehensive API security solution designed to help developer & security teams identify and remediate security vulnerabilities within their code. By integrating seamlessly into the

    Users
    No information available
    Industries
    • Information Technology and Services
    • Computer Software
    Market Segment
    • 46% Small-Business
    • 35% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • StackHawk Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Easy Integrations
    11
    Customer Support
    10
    Ease of Use
    10
    Integrations
    8
    Automated Scanning
    5
    Cons
    Setup Complexity
    5
    Complex Setup
    4
    High Learning Curve
    3
    Inadequate Reporting
    3
    Lacking Features
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • StackHawk features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    8.8
    API / Integrations
    Average: 8.4
    8.1
    Detection Rate
    Average: 8.6
    8.8
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    StackHawk
    Company Website
    Year Founded
    2019
    HQ Location
    Denver, CO
    Twitter
    @StackHawk
    1,147 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    46 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

StackHawk is a comprehensive API security solution designed to help developer & security teams identify and remediate security vulnerabilities within their code. By integrating seamlessly into the

Users
No information available
Industries
  • Information Technology and Services
  • Computer Software
Market Segment
  • 46% Small-Business
  • 35% Mid-Market
StackHawk Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Easy Integrations
11
Customer Support
10
Ease of Use
10
Integrations
8
Automated Scanning
5
Cons
Setup Complexity
5
Complex Setup
4
High Learning Curve
3
Inadequate Reporting
3
Lacking Features
3
StackHawk features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
8.8
API / Integrations
Average: 8.4
8.1
Detection Rate
Average: 8.6
8.8
Test Automation
Average: 8.8
Seller Details
Seller
StackHawk
Company Website
Year Founded
2019
HQ Location
Denver, CO
Twitter
@StackHawk
1,147 Twitter followers
LinkedIn® Page
www.linkedin.com
46 employees on LinkedIn®
(117)4.6 out of 5
Optimized for quick response
6th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
10% off: $5400
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management capabilities. Our comprehensive cybersecurity solutions blend automation and manual experti

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 68% Small-Business
    • 29% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Astra Pentest Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Vulnerability Detection
    35
    Customer Support
    34
    Ease of Use
    33
    Pentesting Efficiency
    28
    Vulnerability Identification
    27
    Cons
    Poor Customer Support
    9
    Technical Issues
    9
    Lack of Information
    7
    Slow Performance
    7
    Poor Interface Design
    6
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Astra Pentest features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    7.9
    API / Integrations
    Average: 8.4
    8.6
    Detection Rate
    Average: 8.6
    8.6
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2018
    HQ Location
    New Delhi, IN
    Twitter
    @getastra
    661 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    87 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management capabilities. Our comprehensive cybersecurity solutions blend automation and manual experti

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 68% Small-Business
  • 29% Mid-Market
Astra Pentest Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Vulnerability Detection
35
Customer Support
34
Ease of Use
33
Pentesting Efficiency
28
Vulnerability Identification
27
Cons
Poor Customer Support
9
Technical Issues
9
Lack of Information
7
Slow Performance
7
Poor Interface Design
6
Astra Pentest features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
7.9
API / Integrations
Average: 8.4
8.6
Detection Rate
Average: 8.6
8.6
Test Automation
Average: 8.8
Seller Details
Company Website
Year Founded
2018
HQ Location
New Delhi, IN
Twitter
@getastra
661 Twitter followers
LinkedIn® Page
www.linkedin.com
87 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Bright Security’s dev-centric DAST platform empowers both developers and AppSec professionals with enterprise-grade security testing capabilities for web applications, APIs, and GenAI and LLM applicat

    Users
    No information available
    Industries
    • Computer & Network Security
    • Information Technology and Services
    Market Segment
    • 56% Enterprise
    • 28% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Bright Security Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Customer Support
    8
    Ease of Use
    8
    Automated Scanning
    7
    Scanning Efficiency
    5
    Speed
    5
    Cons
    Complexity
    5
    Learning Curve
    4
    Complex Setup
    2
    Integration Issues
    2
    Lack of Information
    2
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Bright Security features and usability ratings that predict user satisfaction
    9.3
    Has the product been a good partner in doing business?
    Average: 9.2
    8.4
    API / Integrations
    Average: 8.4
    8.2
    Detection Rate
    Average: 8.6
    8.9
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2018
    HQ Location
    San Rafael
    Twitter
    @BrightAppSec
    1,517 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    106 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Bright Security’s dev-centric DAST platform empowers both developers and AppSec professionals with enterprise-grade security testing capabilities for web applications, APIs, and GenAI and LLM applicat

Users
No information available
Industries
  • Computer & Network Security
  • Information Technology and Services
Market Segment
  • 56% Enterprise
  • 28% Mid-Market
Bright Security Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Customer Support
8
Ease of Use
8
Automated Scanning
7
Scanning Efficiency
5
Speed
5
Cons
Complexity
5
Learning Curve
4
Complex Setup
2
Integration Issues
2
Lack of Information
2
Bright Security features and usability ratings that predict user satisfaction
9.3
Has the product been a good partner in doing business?
Average: 9.2
8.4
API / Integrations
Average: 8.4
8.2
Detection Rate
Average: 8.6
8.9
Test Automation
Average: 8.8
Seller Details
Year Founded
2018
HQ Location
San Rafael
Twitter
@BrightAppSec
1,517 Twitter followers
LinkedIn® Page
www.linkedin.com
106 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly s

    Users
    No information available
    Industries
    • Computer & Network Security
    • Computer Software
    Market Segment
    • 50% Small-Business
    • 28% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Pynt - API Security Testing Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Easy Integrations
    19
    Security
    17
    Vulnerability Detection
    17
    Ease of Use
    15
    API Management
    13
    Cons
    Complex Setup
    7
    Setup Complexity
    6
    Limited Features
    4
    Poor Interface Design
    4
    Poor User Interface
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Pynt - API Security Testing features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    9.4
    API / Integrations
    Average: 8.4
    9.1
    Detection Rate
    Average: 8.6
    9.2
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Pynt
    Year Founded
    2022
    HQ Location
    Tel Aviv, IL
    Twitter
    @pynt_io
    373 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    26 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly s

Users
No information available
Industries
  • Computer & Network Security
  • Computer Software
Market Segment
  • 50% Small-Business
  • 28% Mid-Market
Pynt - API Security Testing Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Easy Integrations
19
Security
17
Vulnerability Detection
17
Ease of Use
15
API Management
13
Cons
Complex Setup
7
Setup Complexity
6
Limited Features
4
Poor Interface Design
4
Poor User Interface
4
Pynt - API Security Testing features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
9.4
API / Integrations
Average: 8.4
9.1
Detection Rate
Average: 8.6
9.2
Test Automation
Average: 8.8
Seller Details
Seller
Pynt
Year Founded
2022
HQ Location
Tel Aviv, IL
Twitter
@pynt_io
373 Twitter followers
LinkedIn® Page
www.linkedin.com
26 employees on LinkedIn®
(112)4.6 out of 5
5th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Contact Us
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Cobalt unifies the best of human security talent and effective security tools. Our end-to-end offensive security solution enables customers to remediate risk across a dynamically changing attack surfa

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 50% Mid-Market
    • 25% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Cobalt Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Pentesting Efficiency
    26
    Customer Support
    24
    Ease of Use
    21
    Communication
    17
    Expertise
    16
    Cons
    Lack of Detail
    6
    Expensive
    5
    Inaccuracy
    4
    Inadequate Testing
    4
    Limited Scope
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Cobalt features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    8.6
    API / Integrations
    Average: 8.4
    8.3
    Detection Rate
    Average: 8.6
    8.7
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Cobalt
    Company Website
    Year Founded
    2013
    HQ Location
    San Francisco, California
    Twitter
    @cobalt_io
    8,582 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    464 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Cobalt unifies the best of human security talent and effective security tools. Our end-to-end offensive security solution enables customers to remediate risk across a dynamically changing attack surfa

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 50% Mid-Market
  • 25% Small-Business
Cobalt Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Pentesting Efficiency
26
Customer Support
24
Ease of Use
21
Communication
17
Expertise
16
Cons
Lack of Detail
6
Expensive
5
Inaccuracy
4
Inadequate Testing
4
Limited Scope
3
Cobalt features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
8.6
API / Integrations
Average: 8.4
8.3
Detection Rate
Average: 8.6
8.7
Test Automation
Average: 8.8
Seller Details
Seller
Cobalt
Company Website
Year Founded
2013
HQ Location
San Francisco, California
Twitter
@cobalt_io
8,582 Twitter followers
LinkedIn® Page
www.linkedin.com
464 employees on LinkedIn®
Entry Level Price:$59.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 55% Small-Business
    • 36% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Indusface WAS Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Vulnerability Detection
    14
    Vulnerability Identification
    12
    Customer Support
    5
    Ease of Use
    5
    Pentesting Efficiency
    5
    Cons
    Expensive
    1
    Lacking Features
    1
    Limited Scope
    1
    Pricing Issues
    1
    Vulnerability Management
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Indusface WAS features and usability ratings that predict user satisfaction
    9.4
    Has the product been a good partner in doing business?
    Average: 9.2
    9.7
    API / Integrations
    Average: 8.4
    9.4
    Detection Rate
    Average: 8.6
    9.5
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Indusface
    Year Founded
    2012
    HQ Location
    Vadodara
    Twitter
    @Indusface
    3,524 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    161 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 55% Small-Business
  • 36% Mid-Market
Indusface WAS Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Vulnerability Detection
14
Vulnerability Identification
12
Customer Support
5
Ease of Use
5
Pentesting Efficiency
5
Cons
Expensive
1
Lacking Features
1
Limited Scope
1
Pricing Issues
1
Vulnerability Management
1
Indusface WAS features and usability ratings that predict user satisfaction
9.4
Has the product been a good partner in doing business?
Average: 9.2
9.7
API / Integrations
Average: 8.4
9.4
Detection Rate
Average: 8.6
9.5
Test Automation
Average: 8.8
Seller Details
Seller
Indusface
Year Founded
2012
HQ Location
Vadodara
Twitter
@Indusface
3,524 Twitter followers
LinkedIn® Page
www.linkedin.com
161 employees on LinkedIn®
(61)4.7 out of 5
11th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 52% Mid-Market
    • 28% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • APPCHECK Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Customer Support
    24
    Ease of Use
    23
    Vulnerability Detection
    22
    Automated Scanning
    19
    Security
    15
    Cons
    Poor User Interface
    8
    Poor Interface Design
    6
    Lacking Features
    4
    Limited Customization
    4
    Scanning Issues
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • APPCHECK features and usability ratings that predict user satisfaction
    9.6
    Has the product been a good partner in doing business?
    Average: 9.2
    8.2
    API / Integrations
    Average: 8.4
    9.0
    Detection Rate
    Average: 8.6
    9.3
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    APPCHECK
    Company Website
    Year Founded
    2014
    HQ Location
    Leeds, GB
    Twitter
    @AppcheckNG
    662 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    94 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 52% Mid-Market
  • 28% Small-Business
APPCHECK Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Customer Support
24
Ease of Use
23
Vulnerability Detection
22
Automated Scanning
19
Security
15
Cons
Poor User Interface
8
Poor Interface Design
6
Lacking Features
4
Limited Customization
4
Scanning Issues
4
APPCHECK features and usability ratings that predict user satisfaction
9.6
Has the product been a good partner in doing business?
Average: 9.2
8.2
API / Integrations
Average: 8.4
9.0
Detection Rate
Average: 8.6
9.3
Test Automation
Average: 8.8
Seller Details
Seller
APPCHECK
Company Website
Year Founded
2014
HQ Location
Leeds, GB
Twitter
@AppcheckNG
662 Twitter followers
LinkedIn® Page
www.linkedin.com
94 employees on LinkedIn®
(12)4.7 out of 5
View top Consulting Services for ZAP by Checkmarx
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Users
    No information available
    Industries
    • Computer & Network Security
    Market Segment
    • 75% Small-Business
    • 17% Enterprise
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • ZAP by Checkmarx Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    6
    Automation
    5
    Scanning Efficiency
    5
    Easy Integrations
    4
    Automated Testing
    3
    Cons
    False Positives
    4
    Poor Documentation
    3
    Lack of Detail
    1
    Limited Scope
    1
    Navigation Problems
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • ZAP by Checkmarx features and usability ratings that predict user satisfaction
    0.0
    No information available
    6.7
    API / Integrations
    Average: 8.4
    6.7
    Detection Rate
    Average: 8.6
    6.7
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Zaproxy
    HQ Location
    N/A
    Twitter
    @zaproxy
    15,442 Twitter followers
Users
No information available
Industries
  • Computer & Network Security
Market Segment
  • 75% Small-Business
  • 17% Enterprise
ZAP by Checkmarx Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
6
Automation
5
Scanning Efficiency
5
Easy Integrations
4
Automated Testing
3
Cons
False Positives
4
Poor Documentation
3
Lack of Detail
1
Limited Scope
1
Navigation Problems
1
ZAP by Checkmarx features and usability ratings that predict user satisfaction
0.0
No information available
6.7
API / Integrations
Average: 8.4
6.7
Detection Rate
Average: 8.6
6.7
Test Automation
Average: 8.8
Seller Details
Seller
Zaproxy
HQ Location
N/A
Twitter
@zaproxy
15,442 Twitter followers
(60)4.6 out of 5
Optimized for quick response
4th Easiest To Use in Dynamic Application Security Testing (DAST) software
View top Consulting Services for Invicti (formerly Netsparker)
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Invicti is an automated application and API security testing solution that allows enterprise organizations to secure thousands of websites, web apps, and APIs and dramatically reduce the risk of attac

    Users
    No information available
    Industries
    • Financial Services
    • Information Technology and Services
    Market Segment
    • 50% Enterprise
    • 25% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Invicti (formerly Netsparker) Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Customer Support
    4
    Ease of Use
    4
    Vulnerability Detection
    4
    Vulnerability Identification
    4
    Accuracy of Results
    3
    Cons
    API Issues
    1
    Inadequate Testing
    1
    Limited Testing Capabilities
    1
    Scanning Issues
    1
    Slow Performance
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Invicti (formerly Netsparker) features and usability ratings that predict user satisfaction
    9.7
    Has the product been a good partner in doing business?
    Average: 9.2
    8.1
    API / Integrations
    Average: 8.4
    8.4
    Detection Rate
    Average: 8.6
    8.4
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2018
    HQ Location
    Austin, Texas
    Twitter
    @InvictiSecurity
    2,549 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    312 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Invicti is an automated application and API security testing solution that allows enterprise organizations to secure thousands of websites, web apps, and APIs and dramatically reduce the risk of attac

Users
No information available
Industries
  • Financial Services
  • Information Technology and Services
Market Segment
  • 50% Enterprise
  • 25% Mid-Market
Invicti (formerly Netsparker) Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Customer Support
4
Ease of Use
4
Vulnerability Detection
4
Vulnerability Identification
4
Accuracy of Results
3
Cons
API Issues
1
Inadequate Testing
1
Limited Testing Capabilities
1
Scanning Issues
1
Slow Performance
1
Invicti (formerly Netsparker) features and usability ratings that predict user satisfaction
9.7
Has the product been a good partner in doing business?
Average: 9.2
8.1
API / Integrations
Average: 8.4
8.4
Detection Rate
Average: 8.6
8.4
Test Automation
Average: 8.8
Seller Details
Company Website
Year Founded
2018
HQ Location
Austin, Texas
Twitter
@InvictiSecurity
2,549 Twitter followers
LinkedIn® Page
www.linkedin.com
312 employees on LinkedIn®
(167)4.8 out of 5
Optimized for quick response
1st Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Starting at $99.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Intruder is an exposure management platform for scaling to mid-market businesses. Over 3000 companies - across all industries - use Intruder to find critical exposures, respond faster and prevent bre

    Users
    • CTO
    • Director
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 60% Small-Business
    • 35% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Intruder Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    7
    Security
    7
    Vulnerability Detection
    7
    Customer Support
    6
    Scanning Efficiency
    6
    Cons
    Slow Scanning
    3
    Expensive
    2
    High Licensing Costs
    2
    Inadequate Reporting
    2
    Limited Features
    2
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Intruder features and usability ratings that predict user satisfaction
    9.7
    Has the product been a good partner in doing business?
    Average: 9.2
    8.9
    API / Integrations
    Average: 8.4
    10.0
    Detection Rate
    Average: 8.6
    10.0
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Intruder
    Company Website
    Year Founded
    2015
    HQ Location
    London
    Twitter
    @intruder_io
    949 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    68 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Intruder is an exposure management platform for scaling to mid-market businesses. Over 3000 companies - across all industries - use Intruder to find critical exposures, respond faster and prevent bre

Users
  • CTO
  • Director
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 60% Small-Business
  • 35% Mid-Market
Intruder Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
7
Security
7
Vulnerability Detection
7
Customer Support
6
Scanning Efficiency
6
Cons
Slow Scanning
3
Expensive
2
High Licensing Costs
2
Inadequate Reporting
2
Limited Features
2
Intruder features and usability ratings that predict user satisfaction
9.7
Has the product been a good partner in doing business?
Average: 9.2
8.9
API / Integrations
Average: 8.4
10.0
Detection Rate
Average: 8.6
10.0
Test Automation
Average: 8.8
Seller Details
Seller
Intruder
Company Website
Year Founded
2015
HQ Location
London
Twitter
@intruder_io
949 Twitter followers
LinkedIn® Page
www.linkedin.com
68 employees on LinkedIn®
(823)4.5 out of 5
Optimized for quick response
9th Easiest To Use in Dynamic Application Security Testing (DAST) software
View top Consulting Services for GitLab
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab

    Users
    • Software Engineer
    • Senior Software Engineer
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 37% Small-Business
    • 37% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • GitLab Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    46
    Features
    42
    Deployment
    30
    Repository Management
    30
    Version Control
    28
    Cons
    Complexity
    15
    Limited Features
    14
    Missing Features
    13
    Poor User Interface
    13
    Confusing Interface
    11
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • GitLab features and usability ratings that predict user satisfaction
    8.8
    Has the product been a good partner in doing business?
    Average: 9.2
    9.0
    API / Integrations
    Average: 8.4
    8.9
    Detection Rate
    Average: 8.6
    9.1
    Test Automation
    Average: 8.8
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2014
    HQ Location
    San Francisco, California
    Twitter
    @gitlab
    167,554 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    2,843 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab

Users
  • Software Engineer
  • Senior Software Engineer
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 37% Small-Business
  • 37% Mid-Market
GitLab Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
46
Features
42
Deployment
30
Repository Management
30
Version Control
28
Cons
Complexity
15
Limited Features
14
Missing Features
13
Poor User Interface
13
Confusing Interface
11
GitLab features and usability ratings that predict user satisfaction
8.8
Has the product been a good partner in doing business?
Average: 9.2
9.0
API / Integrations
Average: 8.4
8.9
Detection Rate
Average: 8.6
9.1
Test Automation
Average: 8.8
Seller Details
Company Website
Year Founded
2014
HQ Location
San Francisco, California
Twitter
@gitlab
167,554 Twitter followers
LinkedIn® Page
www.linkedin.com
2,843 employees on LinkedIn®

Learn More About Dynamic Application Security Testing (DAST) Software

What is Dynamic Application Security Testing (DAST) Software?

Dynamic application security testing (DAST) is one of the many technology groupings of security testing solutions. DAST is a form of black-box security testing, meaning it simulates realistic threats and attacks. This differs from other forms of testing such as static application security testing (SAST), a white-box testing methodology used to examine the source code of an application.

DAST includes a number of testing components that operate while an application is running. Security professionals simulate real-world functionality through testing the application for vulnerabilities and then evaluate the effects on application performance. The methodology is often used to find issues near the end of the software development lifecycle. These issues may be tougher to fix than early flaws and bugs are, but those flaws pose a larger threat to critical components of an application.

DAST can also be thought of as a methodology. It’s a different approach than traditional security testing because once a test is completed, there are still tests to be done. It involves periodic inspections as updates are pushed live or changes are made before release. While a penetration test or code scan might serve as a one-off test for specific vulnerabilities or bugs, dynamic testing can be performed continually throughout the lifecycle of an application.

Key Benefits of Dynamic Application Security Testing (DAST) Software

  • Simulate realistic attacks and threats
  • Discover vulnerabilities not found in source code
  • Flexible and customizable testing options
  • Comprehensive assessment and scalable testing

Why Use Dynamic Application Security Testing (DAST) Software?

There are a number of testing solutions necessary for an all-encompassing approach to security testing and vulnerability discovery. Most start in the early stages of software development and help programmers discover bugs in the code and issues with the underlying framework or design. These tests require access to source code and are often used during development and quality assurance (QA) processes.

While early testing solutions approach testing from the standpoint of the developer, DAST approaches testing from the standpoint of a hacker. These tools simulate real threats to a functional, running application. Security professionals can simulate common attacks such as SQL injection and cross-site scripting or customize tests to threats specific to their product. These tools offer a highly customizable solution for testing during the later stages of development and while applications are deployed.

Flexibility — Users can schedule tests as they please or perform them continuously throughout an application’s or website’s lifecycle. Security professionals can modify environments to simulate their resources and infrastructure to ensure a realistic test and evaluation. They’re often scalable, as well, to see if increased traffic or usage would affect vulnerabilities and protection.

Industries with more specific threats may require more specific testing. Security professionals may identify a threat specific to the health care industry or financial sector and alter tests to simulate the threats most common to them. If performed correctly, these tools offer some of the most realistic and customizable solutions to the threats present in real-world situations.

Comprehensiveness — Threats are continuously evolving and expanding, making the ability to simulate multiple tests more necessary. DAST offers a versatile approach to testing, wherein security professionals can simulate and analyze each threat or attack type individually. These tests deliver comprehensive feedback and actionable insights that security and development teams use to remediate any issues, flaws, and vulnerabilities.

These tools will first perform an initial crawl, or examination, of applications and websites from a third-party perspective. They interact with applications using HTTP, allowing the tools to examine applications built with any programming language or on any framework. The tool will then test for misconfigurations, which expose a greater attack surface than internal vulnerabilities. Additional tests can be run, depending on the solution, but all the results and discoveries can be stored for actionable remediation.

Continuous assessment — Agile teams and other companies relying on frequent updates to applications should use DAST products with continuous assessment capabilities. SAST tools will provide more direct solutions for issues related to continuous integration processes, but DAST tools will provide a better view of how updates and changes will be seen from an outside perspective. Each new update may pose a new threat or unveil a new vulnerability; it is therefore crucial to continue testing even after applications have been completed and deployed.

Unlike SAST, DAST also requires less access to potentially sensitive source code within the application. DAST approaches the situation from an outside perspective as simulated threats attempt to gain access to vulnerable systems or sensitive information. This can make it easier to perform tests continuously without requiring individuals to access source code or other internal systems.

What are the Common Features of Dynamic Application Security Testing (DAST) Software?

Standard functionality is included in most dynamic application security testing (DAST) solutions:

Compliance testing — Compliance testing gives users the ability to test for various requirements from regulatory bodies. This can help ensure information is stored securely and protected from hackers.

Test automation — Test automation is the feature powering continuous testing processes. This functionality operates by running prescripted tests as frequently as required without the need for hands-on or manual testing.

Manual testing — Manual testing gives the user complete control over individual tests. These features allow users to perform hands-on live simulations and penetration tests.

Command-line tools — The command-line interface (CLI) is the language interpreter of a computer. CLI capabilities will allow security testers to simulate threats directly from the terminal host system and input command sequences.

Static code analysis — Static code analysis and static security testing is used to test from the inside out. These tools help security professionals examine application source code for security flaws without executing it.

Issue tracking — Issue tracking helps security professionals and developers document flaws or vulnerabilities as they are discovered. Proper documentation will make it easier to organize the actionable insights provided by the DAST tool.

Reporting and analytics — Reporting capabilities are important to DAST tools because they provide the information necessary to remediate any recently discovered vulnerabilities. Reporting and analytics features can also give teams a better idea of how attacks may affect application availability and performance.

Extensibility — Many applications offer the ability to expand functionality through the use of integrations, APIs, and plugins. These extensible components provide the ability to extend the platform beyond its native feature set to include additional features and functionalities.


Potential Issues with Dynamic Application Security Testing (DAST) Software

Testing coverage — While DAST technologies have come a long way, DAST tools alone are unable to discover the majority of vulnerabilities. This is why most experts suggest pairing them with SAST solutions. Combining the two can decrease the rate at which false positives occur. They can also be used to simplify the continuous testing process for agile teams. While no tool will detect every vulnerability, DAST may be less efficient than other testing tools if used alone.

Late-stage issues — DAST tools will require code to be compiled for each individual test because they rely on simulated functionality to test responses. This can be a roadblock for agile teams constantly integrating new code into an application. Reports are usually static and result from single tests. For agile teams, those reports can become outdated and lose value very quickly. This is just one more reason DAST tools should be used as a component of an all-encompassing security testing stack rather than a standalone solution.

Testing capabilities — Because DAST tools do not access an application's underlying source code, there are a number of flaws DAST tools will be unable to detect. For example, DAST tools are most effective at simulating reflection, or call-and-response, attacks where they can simulate an input and receive a response. They are not, however, highly effective in discovering smaller vulnerabilities or flaws in areas of the application that are rarely touched by users. These issues, as well as vulnerabilities in the original source code, will need to be addressed by additional security testing technologies.