Dynamic Application Security Testing (DAST) Tools

Compare the best DAST tools for dynamic application security testing. Evaluate runtime vulnerability scanners with expert reviews and feature comparisons.

Escape

Escape is doing amazing things with their approach to DAST. They thoroughly discover your APIs and schemas by searching your frontend code, and then test those APIs from the outside. They have great scanning support for modern languages, and also in depth testing configurations.

DASTPentest
Hands-on Best for Enterprise
Invicti

Invicti provides a unified suite application security testing tools. Their history is in robust dynamic testing capabilities, which have modernized to support AI red teaming and API testing. Most recently, they've acquired Kondukto to deliver all in one application security testing capabilities, alongside broader ASPM tools.

ASPMDAST
Best for Enterprise
StackHawk

StackHawk is a developer-first DAST, and it shows every step of the way. They're built to scan quickly, in pipeline, and make it easy to attempt to reproduce issues. They're a major player in reshaping modern DAST and have really paved a way for the future with features like fuzzing API specific data.

DASTAPI Security
Open Source Hands-on
ZAP

Acquired by Checkmarx, ZAP (Zed Attack Proxy) is the scanning tool underlying numerous scanners, and if your internal team is up for the challenge, it can be adapted directly to provide most scanning needs.

DAST
Acquired Open Source
Snyk

Snyk was the first to really do DevSecOps - fast, actionable, developer focused CI/CD security scanning. They also were early to consolidate scanners into a single place - IaC, Code, SCA, and Container. There are many platforms with small improvements over them - better reachability, workflows, etc. - but they remain a strong player in the space for having scaled so meaningfully across enterprises.

ASPMSAST
Trending Open Source
Akto

Akto has created an open source flavored approach to next generation DAST and API security with features like looking at log data for API discovery, sensitive data flows, and customized scanning. A uniquely helpful feature is the ability to easily edit and tweak tests from the UI.

DASTAI SecurityAPI Security
Open Source Nerdy Best for Enterprise
Bright

Bright runs a DAST scanner that's focused on API testing via the CLI kicking off cloud based scans in pipeline. They support ingesting the API docs via the pipeline, and are building some interesting features around local fuzzing as a new type of SAST.

DAST
Nerdy Best for MidMarket
Probely

Acquired by Snyk. Probely has created an excellent version of traditional web based DAST that can handle APIs alongside webcrawling. While they currently don't support GraphQL or have a CLI, they have created unique ways to achieve similar outcomes. The team clearly has a passion for the details of getting the vulnerabilities right.

DAST
Acquired Best for Enterprise Best for MidMarket
Pynt

Pynt has created an elegant solution for running DAST type scanning against your APIs by running tests via a local proxy. This helps to bypass a lot of the pain with configuring DAST tools against your endpoints. They also do API discovery, drift detection, and testing via network integrations.

DASTAPI Security
Staris

Staris built a platform for open box pentesting powered by GenAI. They look at your code and your application, build a PoC exploit of findings as a code test, and give you the fixed code. The workflow is wrapped as a pentest - which offers a glimpse into what the future of pentesting will undoubtedly look like. Staris uses GenAI to help find exploits from SAST to runtime.

SASTDAST
Best for MidMarket
Ghost

Ghost Security provides external API first DAST scanning combined with integrations for API discovery. They're leaning more into agentic AI for discovery and fixing.

DASTAPI Security
Best for MidMarket Best for Startups
Nightvision

Nighvision creates API docs based on scanning your code, and then tests those endpoints from the outside based on the docs they created.

DASTAPI Security
Best for Enterprise Best for Startups