Dynamic Application Security Testing (DAST) probes a running application over its exposed interfaces — HTTP endpoints, APIs — attempting injections, authentication bypasses, and misconfiguration exploits. It sees the application exactly as an attacker does: no source code, only behavior.
DAST vs SAST
- DAST finds what is exploitable in the deployed reality — including server configuration and framework behavior SAST cannot see.
- SAST finds issues earlier and locates them in code; DAST findings need tracing back to source.
- DAST requires a running environment, so it lands later in the pipeline.
- The two overlap little; mature programs treat them as complements, not alternatives.
Operating DAST in CI/CD
DAST typically runs against staging deployments on a schedule or post-deploy trigger. The operational challenges mirror other scanners: knowing which applications are covered, keeping scan configuration current as endpoints change, and feeding results into one policy and posture model rather than another silo.

