Mayhem
ForAllSecure
Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
ForAllSecure
Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
ForAllSecure
Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.