Nikto
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Chris Sullo and contributors
Perl command line scanner that checks a web server against a large database of known dangerous files, outdated software banners and misconfigurations.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.
Pentest-Tools.com
Hosted platform that packages web and network scanners behind one interface, with chained scan automation and report generation.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Bright Security
Developer oriented dynamic scanner for web apps and APIs that validates each finding before reporting it, designed to run on every build.