Dynamic Application Security Testing (DAST) probes a running application over its exposed interfaces — HTTP endpoints, APIs — attempting injections, authentication bypasses, and misconfiguration exploits. It sees the application exactly as an attacker does: no source code, only behavior.

DAST vs SAST

  • DAST finds what is exploitable in the deployed reality — including server configuration and framework behavior SAST cannot see.
  • SAST finds issues earlier and locates them in code; DAST findings need tracing back to source.
  • DAST requires a running environment, so it lands later in the pipeline.
  • The two overlap little; mature programs treat them as complements, not alternatives.

Operating DAST in CI/CD

DAST typically runs against staging deployments on a schedule or post-deploy trigger. The operational challenges mirror other scanners: knowing which applications are covered, keeping scan configuration current as endpoints change, and feeding results into one policy and posture model rather than another silo.

RELATED CONCEPTS