Dynamic Application Security Testing (DAST) Software

  • OWASP Zed Attack Proxy (ZAP) - Web application Scanner - Well suited for CI/CD workflows - Free and Open Source
  • Detectify - Detect vulnerabilities in production as soon as they arise and test beyond the OWASP Top 10 with real hacker payloads.
  • Netsparker - Dramatically reduce your risk of attacks. Get accurate, automated application security testing that scales
  • Veracode - Scans automatically and consistently web applications at scale and taps into deep analytics to understand the entire web attack surface.
  • InsightAppSec - A Rapid7's security suite, providing Dynamic Application Security Testing (DAST) for applications utilizing complex JavaScript frameworks, like React and Angular
  • Appknox DAST simulates actual attacks on our test environment to analyze, detect and plug those pesky vulnerabilities that can fall prey to runtime and network attacks
  • Acunetix - Quickly find and fix the vulnerabilities that put your web applications at risk of attack
  • Burp Suite Enterprise Edition enables automated web vulnerability scanning, removes bottlenecks and saves AppSec teams time with scheduled scans, CI/CD integrations, and intuitive remediation advice and reporting.
  • AppCheck is a leading security scanning platform that automates the discovery of security flaws within your websites, applications, network, and cloud infrastructure.
  • Hdiv detects security bugs in the source code before they are exploited, using a runtime dataflow technique to report the file and line number of the vulnerability.
  • HCL AppScan - Powerful DevSecOps that pinpoints and remediates application vulnerabilities in every phase of the development lifecycle.
  • Checkmarx - Optimize your runtime testing with CxIAST, the solution specifically built for DevOps and your QA automation or CI/CD pipelines.
  • Mister Scanner offers best in the industry vulnerability scanning to identify issues that can lead to security breaches.