AppTrana
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.
Indusface
Managed web application and API protection platform that pairs dynamic scanning with a WAF, using scan findings to drive virtual patch rules.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Invicti Security
Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.