Dynamic application security testing
DAST · An automated testing method that looks for flaws by sending requests to the running application from outside, as an attacker would.
- 01
Why it matters
Because it tests the running application without seeing the code, it finds problems static analysis cannot see, such as configuration errors, missing security headers and flaws that only appear at runtime. Running it regularly in a test environment stops new releases from bringing back old flaws.
- 02
Example
Whenever a new release reaches the test environment, an automated scan runs and reports that a sign-in page reveals the server version in its error message. The issue is fixed before going live.
- 03
Common mistake
Running dynamic scans against the live system without telling the team and at unlimited speed. Scans can have side effects such as submitting forms and creating data; they should run in a test environment first.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.