Intruder
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
ProjectDiscovery
Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
Escape Technologies
API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.