Introducing G2.ai, the future of software buying.Try now

Best Dynamic Application Security Testing (DAST) Software

Lauren Worth
LW
Researched and written by Lauren Worth

Dynamic application security testing (DAST) tools automate security tests for a variety of real-world threats. These tools typically test HTTP and HTML interfaces of web applications. DAST is a black-box testing method, meaning it is performed from the outside. Companies use these tools to identify vulnerabilities in their applications from an external perspective to better simulate threats most easily accessed by hackers outside their organization. There are similarities between DAST tools and other application security and vulnerability management solutions, but most other technologies perform internal tests and code analysis instead of focusing on black-box testing.

SAST vs DAST — Learn the difference

To qualify for inclusion in the Dynamic Application Security Testing (DAST) category, a product must:

Test applications in their operational state
Perform external black-box security tests
Trace penetrations and exploits to their sources
Show More
Show Less

Featured Dynamic Application Security Testing (DAST) Software At A Glance

Intruder
Sponsored
Highest Performer:
Easiest to Use:
Top Trending:
Show LessShow More
Highest Performer:
Easiest to Use:
Top Trending:

G2 takes pride in showing unbiased reviews on user satisfaction in our ratings and reports. We do not allow paid placements in any of our ratings, rankings, or reports. Learn about our scoring methodologies.

No filters applied
90 Listings in Dynamic Application Security Testing (DAST) Available
(57)4.9 out of 5
1st Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Qodex.ai | AI Powered API Testing and Security Qodex.ai is an AI agent purpose built for API testing and security automation. It helps engineering teams ship faster and safer by turning plain Engli

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 77% Small-Business
    • 19% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Qodex.ai Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    19
    Testing
    15
    Testing Efficiency
    15
    Automation
    13
    Helpful
    12
    Cons
    Slow Loading
    6
    Slow Performance
    5
    Bug Issues
    4
    Bugs
    4
    Functionality Issues
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Qodex.ai features and usability ratings that predict user satisfaction
    9.6
    Has the product been a good partner in doing business?
    Average: 9.2
    0.0
    No information available
    0.0
    No information available
    0.0
    No information available
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    QodexAI
    Company Website
    Year Founded
    2023
    HQ Location
    San Francisco, California
    LinkedIn® Page
    linkedin.com
    11 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Qodex.ai | AI Powered API Testing and Security Qodex.ai is an AI agent purpose built for API testing and security automation. It helps engineering teams ship faster and safer by turning plain Engli

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 77% Small-Business
  • 19% Mid-Market
Qodex.ai Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
19
Testing
15
Testing Efficiency
15
Automation
13
Helpful
12
Cons
Slow Loading
6
Slow Performance
5
Bug Issues
4
Bugs
4
Functionality Issues
3
Qodex.ai features and usability ratings that predict user satisfaction
9.6
Has the product been a good partner in doing business?
Average: 9.2
0.0
No information available
0.0
No information available
0.0
No information available
Seller Details
Seller
QodexAI
Company Website
Year Founded
2023
HQ Location
San Francisco, California
LinkedIn® Page
linkedin.com
11 employees on LinkedIn®
(293)4.5 out of 5
Optimized for quick response
10th Easiest To Use in Dynamic Application Security Testing (DAST) software
View top Consulting Services for Tenable Nessus
Save to My Lists
Entry Level Price:$3,390.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to

    Users
    • Security Engineer
    • Network Engineer
    Industries
    • Information Technology and Services
    • Computer & Network Security
    Market Segment
    • 39% Mid-Market
    • 33% Enterprise
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Tenable Nessus Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Vulnerability Identification
    17
    Automated Scanning
    14
    Features
    12
    Vulnerability Detection
    12
    Ease of Use
    8
    Cons
    Slow Scanning
    6
    False Positives
    5
    Limited Features
    5
    Inaccuracy
    3
    Lack of Automation
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Tenable Nessus features and usability ratings that predict user satisfaction
    8.7
    Has the product been a good partner in doing business?
    Average: 9.2
    0.0
    No information available
    0.0
    No information available
    0.0
    No information available
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Tenable
    Company Website
    HQ Location
    Columbia, MD
    Twitter
    @TenableSecurity
    87,462 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    2,341 employees on LinkedIn®
    Ownership
    NASDAQ: TENB
Product Description
How are these determined?Information
This description is provided by the seller.

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to

Users
  • Security Engineer
  • Network Engineer
Industries
  • Information Technology and Services
  • Computer & Network Security
Market Segment
  • 39% Mid-Market
  • 33% Enterprise
Tenable Nessus Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Vulnerability Identification
17
Automated Scanning
14
Features
12
Vulnerability Detection
12
Ease of Use
8
Cons
Slow Scanning
6
False Positives
5
Limited Features
5
Inaccuracy
3
Lack of Automation
3
Tenable Nessus features and usability ratings that predict user satisfaction
8.7
Has the product been a good partner in doing business?
Average: 9.2
0.0
No information available
0.0
No information available
0.0
No information available
Seller Details
Seller
Tenable
Company Website
HQ Location
Columbia, MD
Twitter
@TenableSecurity
87,462 Twitter followers
LinkedIn® Page
www.linkedin.com
2,341 employees on LinkedIn®
Ownership
NASDAQ: TENB

This is how G2 Deals can help you:

  • Easily shop for curated – and trusted – software
  • Own your own software buying journey
  • Discover exclusive deals on software
(93)4.6 out of 5
Optimized for quick response
4th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido hel

    Users
    • CTO
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 76% Small-Business
    • 20% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Aikido Security Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    42
    Security
    37
    Easy Integrations
    32
    Features
    32
    Customer Support
    29
    Cons
    Limited Features
    11
    Missing Features
    11
    False Positives
    8
    Lacking Features
    8
    Improvement Needed
    7
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Aikido Security features and usability ratings that predict user satisfaction
    9.4
    Has the product been a good partner in doing business?
    Average: 9.2
    8.3
    API / Integrations
    Average: 8.6
    10.0
    Detection Rate
    Average: 8.7
    10.0
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2022
    HQ Location
    Ghent, Belgium
    Twitter
    @AikidoSecurity
    3,514 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    102 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido hel

Users
  • CTO
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 76% Small-Business
  • 20% Mid-Market
Aikido Security Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
42
Security
37
Easy Integrations
32
Features
32
Customer Support
29
Cons
Limited Features
11
Missing Features
11
False Positives
8
Lacking Features
8
Improvement Needed
7
Aikido Security features and usability ratings that predict user satisfaction
9.4
Has the product been a good partner in doing business?
Average: 9.2
8.3
API / Integrations
Average: 8.6
10.0
Detection Rate
Average: 8.7
10.0
Test Automation
Average: 8.6
Seller Details
Company Website
Year Founded
2022
HQ Location
Ghent, Belgium
Twitter
@AikidoSecurity
3,514 Twitter followers
LinkedIn® Page
www.linkedin.com
102 employees on LinkedIn®
(68)4.6 out of 5
Optimized for quick response
5th Easiest To Use in Dynamic Application Security Testing (DAST) software
View top Consulting Services for Invicti (formerly Netsparker)
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Invicti is an automated application and API security testing solution that allows enterprise organizations to secure thousands of websites, web apps, and APIs and dramatically reduce the risk of attac

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 49% Enterprise
    • 26% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Invicti (formerly Netsparker) Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    4
    Scanning Technology
    4
    Vulnerability Detection
    4
    Vulnerability Identification
    4
    Automated Scanning
    3
    Cons
    Slow Performance
    2
    API Issues
    1
    Difficult Upgrades
    1
    Inadequate Testing
    1
    Limited Testing Capabilities
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Invicti (formerly Netsparker) features and usability ratings that predict user satisfaction
    9.6
    Has the product been a good partner in doing business?
    Average: 9.2
    8.2
    API / Integrations
    Average: 8.6
    8.7
    Detection Rate
    Average: 8.7
    8.5
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2018
    HQ Location
    Austin, Texas
    Twitter
    @InvictiSecurity
    2,557 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    309 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Invicti is an automated application and API security testing solution that allows enterprise organizations to secure thousands of websites, web apps, and APIs and dramatically reduce the risk of attac

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 49% Enterprise
  • 26% Mid-Market
Invicti (formerly Netsparker) Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
4
Scanning Technology
4
Vulnerability Detection
4
Vulnerability Identification
4
Automated Scanning
3
Cons
Slow Performance
2
API Issues
1
Difficult Upgrades
1
Inadequate Testing
1
Limited Testing Capabilities
1
Invicti (formerly Netsparker) features and usability ratings that predict user satisfaction
9.6
Has the product been a good partner in doing business?
Average: 9.2
8.2
API / Integrations
Average: 8.6
8.7
Detection Rate
Average: 8.7
8.5
Test Automation
Average: 8.6
Seller Details
Company Website
Year Founded
2018
HQ Location
Austin, Texas
Twitter
@InvictiSecurity
2,557 Twitter followers
LinkedIn® Page
www.linkedin.com
309 employees on LinkedIn®
(43)4.8 out of 5
6th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly s

    Users
    No information available
    Industries
    • Computer Software
    • Computer & Network Security
    Market Segment
    • 56% Small-Business
    • 23% Enterprise
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Pynt - API Security Testing Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Security
    24
    Vulnerability Detection
    24
    Easy Integrations
    23
    Ease of Use
    20
    API Management
    19
    Cons
    Complex Setup
    12
    Setup Complexity
    7
    Limited Features
    5
    Poor Interface Design
    4
    UX Improvement
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Pynt - API Security Testing features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    9.5
    API / Integrations
    Average: 8.6
    9.3
    Detection Rate
    Average: 8.7
    9.2
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Pynt
    Year Founded
    2022
    HQ Location
    Tel Aviv, IL
    Twitter
    @pynt_io
    367 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    28 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly s

Users
No information available
Industries
  • Computer Software
  • Computer & Network Security
Market Segment
  • 56% Small-Business
  • 23% Enterprise
Pynt - API Security Testing Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Security
24
Vulnerability Detection
24
Easy Integrations
23
Ease of Use
20
API Management
19
Cons
Complex Setup
12
Setup Complexity
7
Limited Features
5
Poor Interface Design
4
UX Improvement
4
Pynt - API Security Testing features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
9.5
API / Integrations
Average: 8.6
9.3
Detection Rate
Average: 8.7
9.2
Test Automation
Average: 8.6
Seller Details
Seller
Pynt
Year Founded
2022
HQ Location
Tel Aviv, IL
Twitter
@pynt_io
367 Twitter followers
LinkedIn® Page
www.linkedin.com
28 employees on LinkedIn®
(43)4.5 out of 5
Optimized for quick response
7th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empow

    Users
    No information available
    Industries
    • Computer Software
    • Financial Services
    Market Segment
    • 44% Mid-Market
    • 42% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Jit Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Security
    21
    Ease of Use
    20
    Integration Support
    17
    Easy Integrations
    14
    Features
    13
    Cons
    Limited Features
    6
    UX Improvement
    6
    Complexity
    4
    Integration Issues
    4
    Lacking Features
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Jit features and usability ratings that predict user satisfaction
    9.6
    Has the product been a good partner in doing business?
    Average: 9.2
    8.7
    API / Integrations
    Average: 8.6
    9.0
    Detection Rate
    Average: 8.7
    8.5
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    jit
    Company Website
    Year Founded
    2021
    HQ Location
    Boston, MA
    Twitter
    @jit_io
    537 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    117 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empow

Users
No information available
Industries
  • Computer Software
  • Financial Services
Market Segment
  • 44% Mid-Market
  • 42% Small-Business
Jit Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Security
21
Ease of Use
20
Integration Support
17
Easy Integrations
14
Features
13
Cons
Limited Features
6
UX Improvement
6
Complexity
4
Integration Issues
4
Lacking Features
4
Jit features and usability ratings that predict user satisfaction
9.6
Has the product been a good partner in doing business?
Average: 9.2
8.7
API / Integrations
Average: 8.6
9.0
Detection Rate
Average: 8.7
8.5
Test Automation
Average: 8.6
Seller Details
Seller
jit
Company Website
Year Founded
2021
HQ Location
Boston, MA
Twitter
@jit_io
537 Twitter followers
LinkedIn® Page
www.linkedin.com
117 employees on LinkedIn®
(147)4.5 out of 5
9th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Contact Us
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Cobalt unifies the best of human security talent and effective security tools. Our end-to-end offensive security solution enables customers to remediate risk across a dynamically changing attack surfa

    Users
    • Security Engineer
    • CTO
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 50% Mid-Market
    • 25% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Cobalt Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Pentesting Efficiency
    31
    Customer Support
    26
    Ease of Use
    24
    Communication
    20
    Reporting Quality
    18
    Cons
    Expensive
    7
    Lack of Detail
    5
    Inaccuracy
    4
    Inadequate Testing
    4
    Pricing Issues
    4
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Cobalt features and usability ratings that predict user satisfaction
    9.3
    Has the product been a good partner in doing business?
    Average: 9.2
    8.6
    API / Integrations
    Average: 8.6
    8.6
    Detection Rate
    Average: 8.7
    8.9
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Cobalt
    Company Website
    Year Founded
    2013
    HQ Location
    San Francisco, California
    Twitter
    @cobalt_io
    8,547 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    512 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Cobalt unifies the best of human security talent and effective security tools. Our end-to-end offensive security solution enables customers to remediate risk across a dynamically changing attack surfa

Users
  • Security Engineer
  • CTO
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 50% Mid-Market
  • 25% Small-Business
Cobalt Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Pentesting Efficiency
31
Customer Support
26
Ease of Use
24
Communication
20
Reporting Quality
18
Cons
Expensive
7
Lack of Detail
5
Inaccuracy
4
Inadequate Testing
4
Pricing Issues
4
Cobalt features and usability ratings that predict user satisfaction
9.3
Has the product been a good partner in doing business?
Average: 9.2
8.6
API / Integrations
Average: 8.6
8.6
Detection Rate
Average: 8.7
8.9
Test Automation
Average: 8.6
Seller Details
Seller
Cobalt
Company Website
Year Founded
2013
HQ Location
San Francisco, California
Twitter
@cobalt_io
8,547 Twitter followers
LinkedIn® Page
www.linkedin.com
512 employees on LinkedIn®
(124)4.8 out of 5
View top Consulting Services for Burp Suite
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    PortSwigger Web Security is a global leader in the creation of software tools for the security testing of web applications. The software (Burp Suite) is well established as the de facto standard tool

    Users
    • Cyber Security Analyst
    Industries
    • Computer & Network Security
    • Information Technology and Services
    Market Segment
    • 41% Mid-Market
    • 31% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Burp Suite Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    10
    User Interface
    7
    Testing Services
    6
    Features
    5
    Easy Integrations
    4
    Cons
    Slow Performance
    4
    Expensive
    3
    Poor Interface Design
    2
    Bugs
    1
    False Positives
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Burp Suite features and usability ratings that predict user satisfaction
    9.7
    Has the product been a good partner in doing business?
    Average: 9.2
    8.3
    API / Integrations
    Average: 8.6
    7.5
    Detection Rate
    Average: 8.7
    7.5
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2008
    HQ Location
    Knutsford, GB
    Twitter
    @Burp_Suite
    132,262 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    248 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

PortSwigger Web Security is a global leader in the creation of software tools for the security testing of web applications. The software (Burp Suite) is well established as the de facto standard tool

Users
  • Cyber Security Analyst
Industries
  • Computer & Network Security
  • Information Technology and Services
Market Segment
  • 41% Mid-Market
  • 31% Small-Business
Burp Suite Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
10
User Interface
7
Testing Services
6
Features
5
Easy Integrations
4
Cons
Slow Performance
4
Expensive
3
Poor Interface Design
2
Bugs
1
False Positives
1
Burp Suite features and usability ratings that predict user satisfaction
9.7
Has the product been a good partner in doing business?
Average: 9.2
8.3
API / Integrations
Average: 8.6
7.5
Detection Rate
Average: 8.7
7.5
Test Automation
Average: 8.6
Seller Details
Company Website
Year Founded
2008
HQ Location
Knutsford, GB
Twitter
@Burp_Suite
132,262 Twitter followers
LinkedIn® Page
www.linkedin.com
248 employees on LinkedIn®
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint

    Users
    No information available
    Industries
    • Information Technology and Services
    • Computer & Network Security
    Market Segment
    • 54% Enterprise
    • 28% Small-Business
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • HCL AppScan features and usability ratings that predict user satisfaction
    8.8
    Has the product been a good partner in doing business?
    Average: 9.2
    8.1
    API / Integrations
    Average: 8.6
    8.2
    Detection Rate
    Average: 8.7
    7.9
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    1999
    HQ Location
    Noida, Uttar Pradesh
    Twitter
    @hcltech
    439,061 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    245,251 employees on LinkedIn®
    Ownership
    NSE - National Stock Exchange of India
Product Description
How are these determined?Information
This description is provided by the seller.

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint

Users
No information available
Industries
  • Information Technology and Services
  • Computer & Network Security
Market Segment
  • 54% Enterprise
  • 28% Small-Business
HCL AppScan features and usability ratings that predict user satisfaction
8.8
Has the product been a good partner in doing business?
Average: 9.2
8.1
API / Integrations
Average: 8.6
8.2
Detection Rate
Average: 8.7
7.9
Test Automation
Average: 8.6
Seller Details
Year Founded
1999
HQ Location
Noida, Uttar Pradesh
Twitter
@hcltech
439,061 Twitter followers
LinkedIn® Page
www.linkedin.com
245,251 employees on LinkedIn®
Ownership
NSE - National Stock Exchange of India
(156)4.6 out of 5
Optimized for quick response
12th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
10% Off: $5400
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management capabilities. Our comprehensive cybersecurity solutions blend automation and manual experti

    Users
    • CTO
    • CEO
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 67% Small-Business
    • 29% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Astra Pentest Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Customer Support
    56
    Ease of Use
    45
    Vulnerability Detection
    44
    Pentesting Efficiency
    43
    User Interface
    33
    Cons
    Poor Customer Support
    9
    Poor Interface Design
    8
    Dashboard Issues
    6
    False Positives
    6
    Lack of Information
    6
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Astra Pentest features and usability ratings that predict user satisfaction
    9.2
    Has the product been a good partner in doing business?
    Average: 9.2
    8.2
    API / Integrations
    Average: 8.6
    8.8
    Detection Rate
    Average: 8.7
    8.7
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2018
    HQ Location
    New Delhi, IN
    Twitter
    @getastra
    695 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    108 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management capabilities. Our comprehensive cybersecurity solutions blend automation and manual experti

Users
  • CTO
  • CEO
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 67% Small-Business
  • 29% Mid-Market
Astra Pentest Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Customer Support
56
Ease of Use
45
Vulnerability Detection
44
Pentesting Efficiency
43
User Interface
33
Cons
Poor Customer Support
9
Poor Interface Design
8
Dashboard Issues
6
False Positives
6
Lack of Information
6
Astra Pentest features and usability ratings that predict user satisfaction
9.2
Has the product been a good partner in doing business?
Average: 9.2
8.2
API / Integrations
Average: 8.6
8.8
Detection Rate
Average: 8.7
8.7
Test Automation
Average: 8.6
Seller Details
Company Website
Year Founded
2018
HQ Location
New Delhi, IN
Twitter
@getastra
695 Twitter followers
LinkedIn® Page
www.linkedin.com
108 employees on LinkedIn®
(856)4.5 out of 5
Optimized for quick response
14th Easiest To Use in Dynamic Application Security Testing (DAST) software
View top Consulting Services for GitLab
Save to My Lists
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab

    Users
    • Software Engineer
    • Senior Software Engineer
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 37% Small-Business
    • 37% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • GitLab Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Features
    32
    Ease of Use
    31
    CI
    28
    CD Integration
    27
    Collaboration
    26
    Cons
    Complexity
    18
    Difficult Learning
    18
    Complex User Interface
    13
    Learning Difficulty
    13
    Confusing Interface
    12
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • GitLab features and usability ratings that predict user satisfaction
    8.8
    Has the product been a good partner in doing business?
    Average: 9.2
    9.2
    API / Integrations
    Average: 8.6
    8.9
    Detection Rate
    Average: 8.7
    9.1
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2014
    HQ Location
    San Francisco, California
    Twitter
    @gitlab
    168,735 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    3,243 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab

Users
  • Software Engineer
  • Senior Software Engineer
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 37% Small-Business
  • 37% Mid-Market
GitLab Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Features
32
Ease of Use
31
CI
28
CD Integration
27
Collaboration
26
Cons
Complexity
18
Difficult Learning
18
Complex User Interface
13
Learning Difficulty
13
Confusing Interface
12
GitLab features and usability ratings that predict user satisfaction
8.8
Has the product been a good partner in doing business?
Average: 9.2
9.2
API / Integrations
Average: 8.6
8.9
Detection Rate
Average: 8.7
9.1
Test Automation
Average: 8.6
Seller Details
Company Website
Year Founded
2014
HQ Location
San Francisco, California
Twitter
@gitlab
168,735 Twitter followers
LinkedIn® Page
www.linkedin.com
3,243 employees on LinkedIn®
(195)4.8 out of 5
Optimized for quick response
3rd Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Starting at $99.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Intruder is an exposure management platform for scaling to mid-market businesses. Over 3000 companies - across all industries - use Intruder to find critical exposures, respond faster and prevent bre

    Users
    • CTO
    • Director
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 59% Small-Business
    • 35% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Intruder Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    33
    Vulnerability Detection
    26
    Customer Support
    24
    Vulnerability Identification
    23
    Scanning Efficiency
    21
    Cons
    Expensive
    10
    Licensing Issues
    7
    Limited Features
    6
    Pricing Issues
    6
    Slow Scanning
    5
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Intruder features and usability ratings that predict user satisfaction
    9.7
    Has the product been a good partner in doing business?
    Average: 9.2
    8.9
    API / Integrations
    Average: 8.6
    9.5
    Detection Rate
    Average: 8.7
    8.8
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Intruder
    Company Website
    Year Founded
    2015
    HQ Location
    London
    Twitter
    @intruder_io
    970 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    80 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Intruder is an exposure management platform for scaling to mid-market businesses. Over 3000 companies - across all industries - use Intruder to find critical exposures, respond faster and prevent bre

Users
  • CTO
  • Director
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 59% Small-Business
  • 35% Mid-Market
Intruder Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
33
Vulnerability Detection
26
Customer Support
24
Vulnerability Identification
23
Scanning Efficiency
21
Cons
Expensive
10
Licensing Issues
7
Limited Features
6
Pricing Issues
6
Slow Scanning
5
Intruder features and usability ratings that predict user satisfaction
9.7
Has the product been a good partner in doing business?
Average: 9.2
8.9
API / Integrations
Average: 8.6
9.5
Detection Rate
Average: 8.7
8.8
Test Automation
Average: 8.6
Seller Details
Seller
Intruder
Company Website
Year Founded
2015
HQ Location
London
Twitter
@intruder_io
970 Twitter followers
LinkedIn® Page
www.linkedin.com
80 employees on LinkedIn®
(49)4.5 out of 5
Optimized for quick response
Save to My Lists
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — AP

    Users
    No information available
    Industries
    • Financial Services
    • Computer Software
    Market Segment
    • 45% Mid-Market
    • 31% Small-Business
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Akto Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Ease of Use
    20
    API Testing
    18
    Automation Testing
    17
    Security
    17
    API Management
    15
    Cons
    Complex Setup
    7
    Poor Documentation
    7
    API Issues
    6
    Complexity
    6
    Setup Complexity
    6
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Akto features and usability ratings that predict user satisfaction
    9.1
    Has the product been a good partner in doing business?
    Average: 9.2
    8.9
    API / Integrations
    Average: 8.6
    8.1
    Detection Rate
    Average: 8.7
    8.7
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Akto.io
    Company Website
    Year Founded
    2022
    HQ Location
    San Francisco, California
    Twitter
    @Aktodotio
    1,341 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    22 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — AP

Users
No information available
Industries
  • Financial Services
  • Computer Software
Market Segment
  • 45% Mid-Market
  • 31% Small-Business
Akto Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Ease of Use
20
API Testing
18
Automation Testing
17
Security
17
API Management
15
Cons
Complex Setup
7
Poor Documentation
7
API Issues
6
Complexity
6
Setup Complexity
6
Akto features and usability ratings that predict user satisfaction
9.1
Has the product been a good partner in doing business?
Average: 9.2
8.9
API / Integrations
Average: 8.6
8.1
Detection Rate
Average: 8.7
8.7
Test Automation
Average: 8.6
Seller Details
Seller
Akto.io
Company Website
Year Founded
2022
HQ Location
San Francisco, California
Twitter
@Aktodotio
1,341 Twitter followers
LinkedIn® Page
www.linkedin.com
22 employees on LinkedIn®
(67)4.6 out of 5
8th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:$59.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 52% Small-Business
    • 37% Mid-Market
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Indusface WAS Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Vulnerability Detection
    11
    Vulnerability Identification
    8
    Pentesting Efficiency
    5
    Automation
    4
    Customer Support
    4
    Cons
    Expensive
    1
    Lacking Features
    1
    Limited Scope
    1
    Pricing Issues
    1
    Vulnerability Management
    1
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Indusface WAS features and usability ratings that predict user satisfaction
    9.4
    Has the product been a good partner in doing business?
    Average: 9.2
    9.7
    API / Integrations
    Average: 8.6
    9.4
    Detection Rate
    Average: 8.7
    9.4
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Indusface
    Year Founded
    2012
    HQ Location
    Vadodara
    Twitter
    @Indusface
    3,510 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    169 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 52% Small-Business
  • 37% Mid-Market
Indusface WAS Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Vulnerability Detection
11
Vulnerability Identification
8
Pentesting Efficiency
5
Automation
4
Customer Support
4
Cons
Expensive
1
Lacking Features
1
Limited Scope
1
Pricing Issues
1
Vulnerability Management
1
Indusface WAS features and usability ratings that predict user satisfaction
9.4
Has the product been a good partner in doing business?
Average: 9.2
9.7
API / Integrations
Average: 8.6
9.4
Detection Rate
Average: 8.7
9.4
Test Automation
Average: 8.6
Seller Details
Seller
Indusface
Year Founded
2012
HQ Location
Vadodara
Twitter
@Indusface
3,510 Twitter followers
LinkedIn® Page
www.linkedin.com
169 employees on LinkedIn®
(33)4.8 out of 5
13th Easiest To Use in Dynamic Application Security Testing (DAST) software
Save to My Lists
Entry Level Price:Contact Us
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Edgescan is a comprehensive platform for continuous security testing, exposure management, and Penetration Testing as a Service (PTaaS). It is designed to assist organizations in gaining a thorough un

    Users
    No information available
    Industries
    • Computer Software
    Market Segment
    • 39% Mid-Market
    • 33% Enterprise
  • Pros and Cons
    Expand/Collapse Pros and Cons
  • Edgescan Pros and Cons
    How are these determined?Information
    Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
    Pros
    Customer Support
    13
    Ease of Use
    13
    Vulnerability Detection
    13
    Features
    11
    Vulnerability Identification
    10
    Cons
    Dashboard Issues
    4
    Slow Performance
    4
    Inadequate Reporting
    3
    Limited Customization
    3
    Poor Navigation
    3
  • User Satisfaction
    Expand/Collapse User Satisfaction
  • Edgescan features and usability ratings that predict user satisfaction
    9.4
    Has the product been a good partner in doing business?
    Average: 9.2
    8.8
    API / Integrations
    Average: 8.6
    9.2
    Detection Rate
    Average: 8.7
    9.2
    Test Automation
    Average: 8.6
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Edgescan
    Company Website
    Year Founded
    2011
    HQ Location
    Dublin, Dublin
    Twitter
    @edgescan
    2,307 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    91 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Edgescan is a comprehensive platform for continuous security testing, exposure management, and Penetration Testing as a Service (PTaaS). It is designed to assist organizations in gaining a thorough un

Users
No information available
Industries
  • Computer Software
Market Segment
  • 39% Mid-Market
  • 33% Enterprise
Edgescan Pros and Cons
How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Customer Support
13
Ease of Use
13
Vulnerability Detection
13
Features
11
Vulnerability Identification
10
Cons
Dashboard Issues
4
Slow Performance
4
Inadequate Reporting
3
Limited Customization
3
Poor Navigation
3
Edgescan features and usability ratings that predict user satisfaction
9.4
Has the product been a good partner in doing business?
Average: 9.2
8.8
API / Integrations
Average: 8.6
9.2
Detection Rate
Average: 8.7
9.2
Test Automation
Average: 8.6
Seller Details
Seller
Edgescan
Company Website
Year Founded
2011
HQ Location
Dublin, Dublin
Twitter
@edgescan
2,307 Twitter followers
LinkedIn® Page
www.linkedin.com
91 employees on LinkedIn®

Learn More About Dynamic Application Security Testing (DAST) Software

What is Dynamic Application Security Testing (DAST) Software?

Dynamic application security testing (DAST) is one of the many technology groupings of security testing solutions. DAST is a form of black-box security testing, meaning it simulates realistic threats and attacks. This differs from other forms of testing such as static application security testing (SAST), a white-box testing methodology used to examine the source code of an application.

DAST includes a number of testing components that operate while an application is running. Security professionals simulate real-world functionality through testing the application for vulnerabilities and then evaluate the effects on application performance. The methodology is often used to find issues near the end of the software development lifecycle. These issues may be tougher to fix than early flaws and bugs are, but those flaws pose a larger threat to critical components of an application.

DAST can also be thought of as a methodology. It’s a different approach than traditional security testing because once a test is completed, there are still tests to be done. It involves periodic inspections as updates are pushed live or changes are made before release. While a penetration test or code scan might serve as a one-off test for specific vulnerabilities or bugs, dynamic testing can be performed continually throughout the lifecycle of an application.

Key Benefits of Dynamic Application Security Testing (DAST) Software

  • Simulate realistic attacks and threats
  • Discover vulnerabilities not found in source code
  • Flexible and customizable testing options
  • Comprehensive assessment and scalable testing

Why Use Dynamic Application Security Testing (DAST) Software?

There are a number of testing solutions necessary for an all-encompassing approach to security testing and vulnerability discovery. Most start in the early stages of software development and help programmers discover bugs in the code and issues with the underlying framework or design. These tests require access to source code and are often used during development and quality assurance (QA) processes.

While early testing solutions approach testing from the standpoint of the developer, DAST approaches testing from the standpoint of a hacker. These tools simulate real threats to a functional, running application. Security professionals can simulate common attacks such as SQL injection and cross-site scripting or customize tests to threats specific to their product. These tools offer a highly customizable solution for testing during the later stages of development and while applications are deployed.

Flexibility — Users can schedule tests as they please or perform them continuously throughout an application’s or website’s lifecycle. Security professionals can modify environments to simulate their resources and infrastructure to ensure a realistic test and evaluation. They’re often scalable, as well, to see if increased traffic or usage would affect vulnerabilities and protection.

Industries with more specific threats may require more specific testing. Security professionals may identify a threat specific to the health care industry or financial sector and alter tests to simulate the threats most common to them. If performed correctly, these tools offer some of the most realistic and customizable solutions to the threats present in real-world situations.

Comprehensiveness — Threats are continuously evolving and expanding, making the ability to simulate multiple tests more necessary. DAST offers a versatile approach to testing, wherein security professionals can simulate and analyze each threat or attack type individually. These tests deliver comprehensive feedback and actionable insights that security and development teams use to remediate any issues, flaws, and vulnerabilities.

These tools will first perform an initial crawl, or examination, of applications and websites from a third-party perspective. They interact with applications using HTTP, allowing the tools to examine applications built with any programming language or on any framework. The tool will then test for misconfigurations, which expose a greater attack surface than internal vulnerabilities. Additional tests can be run, depending on the solution, but all the results and discoveries can be stored for actionable remediation.

Continuous assessment — Agile teams and other companies relying on frequent updates to applications should use DAST products with continuous assessment capabilities. SAST tools will provide more direct solutions for issues related to continuous integration processes, but DAST tools will provide a better view of how updates and changes will be seen from an outside perspective. Each new update may pose a new threat or unveil a new vulnerability; it is therefore crucial to continue testing even after applications have been completed and deployed.

Unlike SAST, DAST also requires less access to potentially sensitive source code within the application. DAST approaches the situation from an outside perspective as simulated threats attempt to gain access to vulnerable systems or sensitive information. This can make it easier to perform tests continuously without requiring individuals to access source code or other internal systems.

What are the Common Features of Dynamic Application Security Testing (DAST) Software?

Standard functionality is included in most dynamic application security testing (DAST) solutions:

Compliance testing — Compliance testing gives users the ability to test for various requirements from regulatory bodies. This can help ensure information is stored securely and protected from hackers.

Test automation — Test automation is the feature powering continuous testing processes. This functionality operates by running prescripted tests as frequently as required without the need for hands-on or manual testing.

Manual testing — Manual testing gives the user complete control over individual tests. These features allow users to perform hands-on live simulations and penetration tests.

Command-line tools — The command-line interface (CLI) is the language interpreter of a computer. CLI capabilities will allow security testers to simulate threats directly from the terminal host system and input command sequences.

Static code analysis — Static code analysis and static security testing is used to test from the inside out. These tools help security professionals examine application source code for security flaws without executing it.

Issue tracking — Issue tracking helps security professionals and developers document flaws or vulnerabilities as they are discovered. Proper documentation will make it easier to organize the actionable insights provided by the DAST tool.

Reporting and analytics — Reporting capabilities are important to DAST tools because they provide the information necessary to remediate any recently discovered vulnerabilities. Reporting and analytics features can also give teams a better idea of how attacks may affect application availability and performance.

Extensibility — Many applications offer the ability to expand functionality through the use of integrations, APIs, and plugins. These extensible components provide the ability to extend the platform beyond its native feature set to include additional features and functionalities.


Potential Issues with Dynamic Application Security Testing (DAST) Software

Testing coverage — While DAST technologies have come a long way, DAST tools alone are unable to discover the majority of vulnerabilities. This is why most experts suggest pairing them with SAST solutions. Combining the two can decrease the rate at which false positives occur. They can also be used to simplify the continuous testing process for agile teams. While no tool will detect every vulnerability, DAST may be less efficient than other testing tools if used alone.

Late-stage issues — DAST tools will require code to be compiled for each individual test because they rely on simulated functionality to test responses. This can be a roadblock for agile teams constantly integrating new code into an application. Reports are usually static and result from single tests. For agile teams, those reports can become outdated and lose value very quickly. This is just one more reason DAST tools should be used as a component of an all-encompassing security testing stack rather than a standalone solution.

Testing capabilities — Because DAST tools do not access an application's underlying source code, there are a number of flaws DAST tools will be unable to detect. For example, DAST tools are most effective at simulating reflection, or call-and-response, attacks where they can simulate an input and receive a response. They are not, however, highly effective in discovering smaller vulnerabilities or flaws in areas of the application that are rarely touched by users. These issues, as well as vulnerabilities in the original source code, will need to be addressed by additional security testing technologies.