DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals

34 tools

  • Mayhem

    ForAllSecure

    DAST

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial
    Growing
  • Intruder

    Intruder

    DAST

    Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.

    Commercial
    Growing
  • ZeroThreat

    ZeroThreat

    DAST

    Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

    Freemium
    Emerging
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial
    Established
  • DAST

    Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial
    Established
  • Astra Security

    Astra Security

    DAST

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial
    Growing
  • Dastardly

    PortSwigger

    DAST

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free
    Established Verified
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • Wapiti

    Wapiti project

    DAST

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source
    Established Verified
  • StackHawk

    StackHawk

    DAST

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial
    Growing
  • Nuclei

    ProjectDiscovery

    DAST

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source
    Established Verified
  • Detectify

    Detectify

    DAST

    Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.

    Commercial
    Established
  • Mayhem

    ForAllSecure

    Autonomous fuzzing platform that combines coverage-guided mutation with symbolic execution to drive programs and APIs into crashing states.

    Commercial Growing
    DAST
  • Intruder

    Intruder

    Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.

    Commercial Growing
    DAST
  • ZeroThreat

    ZeroThreat

    Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

    Freemium Emerging
    DAST
  • Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.

    Commercial Established
    DAST
  • Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.

    Commercial Established
    DAST
  • Astra Security

    Astra Security

    Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.

    Commercial Growing
    DAST
  • Dastardly

    PortSwigger

    Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.

    Free Established
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
  • Wapiti

    Wapiti project

    Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.

    Open source Established
    DAST
  • StackHawk

    StackHawk

    Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.

    Commercial Growing
    DAST
  • Nuclei

    ProjectDiscovery

    Go-based scanner that executes YAML templates describing a request and a match condition, run at high concurrency across large target lists.

    Open source Established
    DAST
  • Detectify

    Detectify

    Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.

    Commercial Established
    DAST
  • w3af

    Andres Riancho and contributors

    DAST

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source
    Established
  • DAST

    Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial
    Established
  • Beagle Security

    Beagle Security

    DAST

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial
    Growing
  • RunSybil

    RunSybil

    DAST

    Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.

    Commercial
    Emerging
  • AppCheck

    AppCheck

    DAST

    Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.

    Commercial
    Established
  • Invicti

    Invicti Security

    DAST

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial
    Established
  • GitLab DAST

    GitLab

    DAST

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial
    Established
  • DAST

    Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial
    Established
  • Escape

    Escape Technologies

    DAST

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial
    Growing
  • Strix

    Strix

    DAST

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source
    Emerging
  • Arachni

    Arachni Project (Tasos Laskos)

    DAST

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source
    Established
  • Qualys WAS

    Qualys

    DAST

    Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.

    Commercial
    Established
  • w3af

    Andres Riancho and contributors

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source Established
    DAST
  • Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial Established
    DAST
  • Beagle Security

    Beagle Security

    Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.

    Commercial Growing
    DAST
  • RunSybil

    RunSybil

    Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.

    Commercial Emerging
    DAST
  • AppCheck

    AppCheck

    Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.

    Commercial Established
    DAST
  • Invicti

    Invicti Security

    Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

    Commercial Established
    DAST
  • GitLab DAST

    GitLab

    Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.

    Commercial Established
    DAST
  • Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial Established
    DAST
  • Escape

    Escape Technologies

    API focused dynamic scanner that models a schema, generates traffic from it, and tests authorization and business logic as well as injection classes.

    Commercial Growing
    DAST
  • Strix

    Strix

    Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.

    Open source Emerging
    DAST
  • Arachni

    Arachni Project (Tasos Laskos)

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source Established
    DAST
  • Qualys WAS

    Qualys

    Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.

    Commercial Established
    DAST
Tick up to 4 tools above.