Dynamic Application Security Testing (DAST) Tools

Compare the best DAST tools for dynamic application security testing. Evaluate runtime vulnerability scanners with expert reviews and feature comparisons.

Aikido

Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.

ASPMCSPM
Trending Hands-on
Escape

Escape is doing amazing things with their approach to DAST. They thoroughly discover your APIs and schemas by searching your frontend code, and then test those APIs from the outside. They have great scanning support for modern languages, and also in depth testing configurations.

DASTPentest
Hands-on Best for Enterprise
Invicti

Invicti provides a unified suite application security testing tools. Their history is in robust dynamic testing capabilities, which have modernized to support AI red teaming and API testing. Most recently, they've acquired Kondukto to deliver all in one application security testing capabilities, alongside broader ASPM tools.

ASPMDAST
Best for Enterprise
Checkmarx

Checkmarx has adapted well to the DevSecOps model, offering a lighter weight scanner in the Checkmarx One platform, that integrates well into the larger stack. They don't have all the latest features of some newer companies, but they certainly get the job done for diverse enterprises. I would not suggest venturing off Checkmarx One though.

ASPMSAST
Hands-on Best for Enterprise
ZAP

Acquired by Checkmarx, ZAP (Zed Attack Proxy) is the scanning tool underlying numerous scanners, and if your internal team is up for the challenge, it can be adapted directly to provide most scanning needs.

DAST
Acquired Open Source
Qualys

Qualys offers just about every vulnerability scanner you could want from a single vendor - from cloud to on premise to code. They have great vulnerability insights and scanning capabilities in a holistic place, but the platform UX can be difficult compared to more specialized vendors.

CSPMVulnerability Management
Hands-on Best for Enterprise
Tenable

Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.

CNAPPCSPM
Trending Hands-on
Snyk

Snyk was the first to really do DevSecOps - fast, actionable, developer focused CI/CD security scanning. They also were early to consolidate scanners into a single place - IaC, Code, SCA, and Container. There are many platforms with small improvements over them - better reachability, workflows, etc. - but they remain a strong player in the space for having scaled so meaningfully across enterprises.

ASPMSAST
Trending Open Source
Soos

Soos offers holistic ASPM scanners and ingestion, with a special focus on in depth SCA scanning and SBOM generation

ASPMSAST
Hands-on Best for Startups
Intruder

Intruder offers holistic network vulnerability scanner, DAST, and CSPM scanning solutions, a great option for mid size businesses looking for a flexible scanner

CSPMVulnerability ManagementDAST
Best for Startups
Bright

Bright runs a DAST scanner that's focused on API testing via the CLI kicking off cloud based scans in pipeline. They support ingesting the API docs via the pipeline, and are building some interesting features around local fuzzing as a new type of SAST.

DAST
Nerdy Best for MidMarket
Probely

Acquired by Snyk. Probely has created an excellent version of traditional web based DAST that can handle APIs alongside webcrawling. While they currently don't support GraphQL or have a CLI, they have created unique ways to achieve similar outcomes. The team clearly has a passion for the details of getting the vulnerabilities right.

DAST
Acquired Best for Enterprise Best for MidMarket
JIT

JIT built a holistic ASPM scanning solution, and has sense heavily invested in AI workflows. They consolidate scanners and create workflows and prioritization for developers. The JIT scanner is unique in that it's a wrapper for other scanners that you run in your own pipelines - an approach with pros and cons.

ASPMCSPM
Hands-on Best for MidMarket Best for Startups
Oxeye

Acquired by Gitlab, Oxeye was a complete ASPM scanner that emphasized runtime context and API discovery

ASPMSAST
Acquired
FluidAttacks

FluidAttacks offers a combined SAST, SCA, and DAST alongside service offerings for pentesting and code review.

ASPMSAST
Best for Startups
Apona

Apona provides a combination SCA, SAST, and DAST features. Something unique about their SCA is providing a function level fix if one is available to avoid the patch.

SASTDASTSCA
Nerdy Best for Enterprise
Codacy

Codacy is a code quality and scanning toolbox similar to SonarQube for code scanning. They support many languages via open source scanning tools and have a developer focus.

ASPMSAST
Hands-on Best for Startups
Google

GCP offers a robust web security scanner, or DAST equivalent. They've recently augmented the platform with AI Red teaming capabilities as well.

DAST
Included Best for Startups
Ghost

Ghost Security provides external API first DAST scanning combined with integrations for API discovery. They're leaning more into agentic AI for discovery and fixing.

DASTAPI Security
Best for MidMarket Best for Startups
EdgeScan

Edgescan wraps up a lot of services around scanning your endpoints for security issues - from traditional web app crawling, to network scanning, to API scanning.

DAST
Best for Enterprise
Synopsys

Does Synopsys technically do everything you'd need from an ASPM? Yes. Would you ever want to use it? No. They've focused heavily into the semiconductor industry, and their ASPM is heavily patched together from various acquisitions.

ASPMSAST
Open Source
VeraCode

Veracode is a legacy SAST vendor that has done a good job expanding into other categories. They are a great choice for organizations using more legacy or waterfall type development methods, but still don't have an intuitive interface or workflows for modern dev teams.

ASPMSAST
Best for Enterprise
Ethiack

Ethiack is a combination DAST scanner and pentesting platform, using customized scanners to detect issues and working with hackers for either validation or manual pentesting.

DASTPentestAgentic Development Security
Nerdy
HCL AppScan

HCL AppScan is a feature rich local DAST scanner, but the cloud offering and process for managing scans between teams leaves a lot to be desired.

DAST