Intruder
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
ZeroThreat
Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
Black Duck
Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Intruder
Hosted scanner that watches an organization's internet-facing footprint and re-tests it automatically whenever significant new vulnerabilities are published.
ZeroThreat
Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.
Tenable
Web application scanning module of the Tenable platform, using a browser-based crawler and sharing asset inventory and reporting with infrastructure scanning.
Black Duck
Hosted dynamic scanner offered alongside Black Duck's static and composition analysis, aimed at automated web and API testing inside a pipeline.
Astra Security
Pentest platform that pairs a continuous automated scanner with human driven testing, reporting findings through a shared remediation dashboard.
PortSwigger
Free container based scanner from PortSwigger that runs a small subset of Burp Scanner checks against a web app inside CI.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
Wapiti project
Python command line web application scanner that crawls a target, then injects payloads into every discovered parameter through selectable attack modules.
StackHawk
Developer-oriented dynamic scanner driven by a YAML config and a CLI scanner, built to run against an application spun up inside the build pipeline.
Detectify
Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
RunSybil
Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
Beagle Security
Hosted scanner that runs automated penetration tests against web applications and APIs, with pipeline triggers and remediation guidance per finding.
RunSybil
Commercial service that runs an AI agent against a target application to find and demonstrate vulnerabilities the way a human tester would.
AppCheck
Commercial scanning platform that covers web applications, APIs and network infrastructure from a single console, backed by an in-house research team.
Invicti Security
Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.
GitLab
Dynamic scanning built into GitLab pipelines, running a browser based analyzer against a deployed review environment and reporting into merge requests.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Strix
Open source framework that runs AI agents with browser, proxy and shell tooling against a target to find and validate vulnerabilities.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
Qualys
Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.
Rapid7
Cloud-managed dynamic scanner that crawls and attacks web applications through distributed engines, with replayable proof steps for each finding.
Fluid Attacks
Continuous security testing service combining automated scanners with a standing team of testers, delivered through a shared platform with a build gate.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.