Astra Security
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.