Home/Best lists/DAST Tools
StatWharf best list · 10 vendors compared
Best DAST Tools (2026): Top 10 Compared
Comparison of DAST tools with verified pricing, best-for guidance and pros and cons for each scanner. Updated September 2026.
Jump to:1Burp Suite (PortSwigger) · Best overall2Invicti · Runner-up3OWASP ZAP · Also strong
DAST Tools compared on features, ease of use and value. Pricing is read from each vendor's public pricing page and dated; entries marked "verified" were confirmed with the vendor.
Editor's top picks
Same scan engine used by manual testers and pipelines
Best for: Penetration testers and appsec teams wanting manual plus automated testing
Proof-based scanning that confirms exploitable findings automatically
Best for: Enterprises governing large web and API application portfolios
No licence cost at any scale, with a full automation API
Best for: Teams needing a free scanner they can script and self-host
Comparison table
| # | Vendor | Best for | Pricing | Standout | Score |
|---|---|---|---|---|---|
| 1 | Burp Suite (PortSwigger)specialist | Penetration testers and appsec teams wanting manual plus automated testing | From $499/user/year (checked Sep 2026) | Same scan engine used by manual testers and pipelines | 9.1/10 |
| 2 | Invictienterprise | Enterprises governing large web and API application portfolios | Quote-based (checked Sep 2026) | Proof-based scanning that confirms exploitable findings automatically | 8.9/10 |
| 3 | OWASP ZAPopen-source | Teams needing a free scanner they can script and self-host | Free and open source (checked Sep 2026) | No licence cost at any scale, with a full automation API | 8.5/10 |
| 4 | Rapid7 InsightAppSecenterprise | Security teams wanting predictable per-application DAST pricing | From $175/mo per app, billed annually (checked Sep 2026) | Attack Replay lets developers reproduce a finding directly | 8.3/10 |
| 5 | StackHawkmid-market | Developer teams running security tests inside CI and coding agents | From $10/user/mo (checked Sep 2026) | Runs as a skill inside AI coding agents before the pull request | 8.0/10 |
| 6 | Detectifymid-market | Companies scanning an external attack surface continuously | Free tier; paid from EUR 2,500/year billed annually (checked Sep 2026) | Crowdsourced hacker research feeds the payload library | 7.8/10 |
| 7 | Veracode Dynamic Analysisenterprise | Regulated enterprises consolidating DAST, SAST and SCA reporting | Quote-based (checked Sep 2026) | Dynamic findings reported alongside static and composition results | 7.6/10 |
| 8 | Tenable Web App Scanningenterprise | Organisations already running Tenable vulnerability management | From $3,578/year for 5 FQDNs (checked Sep 2026) | Web findings merge into the Tenable One exposure view | 7.4/10 |
| 9 | Intrudersmb | Lean security teams covering infrastructure, cloud and web together | Free tier; paid plans quote-based (checked Sep 2026) | One console for external network, cloud and web app scanning | 7.1/10 |
| 10 | Appknoxspecialist | Enterprises testing mobile applications before store release | Quote-based (checked Sep 2026) | Mobile-specific dynamic testing with optional manual pentests | 6.8/10 |
Dynamic application security testing tools assess an application while it runs. Rather than reading source code, the scanner crawls the deployed system, enumerates pages, parameters and API endpoints, then sends crafted requests and interprets the responses. The result is a view of what an attacker reaches from outside the perimeter, including flaws introduced by configuration and infrastructure rather than by code alone.
The market divides into four groups. Enterprise platforms such as Invicti, Veracode and Rapid7 sell dynamic testing inside a wider application security suite, with portfolio reporting, on-premises engines and quote-based contracts. Exposure management vendors, including Tenable and Intruder, fold web scanning into infrastructure and cloud coverage for teams that manage risk as one programme. Developer-oriented tools such as StackHawk and Detectify sell smaller, published subscriptions aimed at pipelines and external attack surfaces. Burp Suite and OWASP ZAP anchor the specialist and open source ends. Scores below weight feature depth at 40 percent, ease of adoption at 30 percent and value for money at 30 percent, judged relative to the other tools in this category.
Vendor reviews
1Burp Suite (PortSwigger)
specialistBest overallBurp Suite is made by PortSwigger and exists in three main editions. Burp Suite Community is a free manual toolkit, Burp Suite Professional is the per-user product aimed at penetration testers, and Burp Suite DAST is the enterprise edition intended for scheduled and pipeline-driven scanning across an application portfolio. All three share the same underlying scanning engine, which is the main reason the product line dominates hands-on web security testing.
The Professional edition combines an intercepting proxy, repeater, intruder, sequencer and an integrated vulnerability scanner, so a tester can move between automated crawling and manual request manipulation without changing tools. Extensibility is a large part of the appeal: the BApp store lists over 300 extensions, and custom logic can be written as BChecks and Bambdas rather than full extensions. Burp Suite DAST adds a browser-powered Chromium crawler for JavaScript-heavy applications, native scanning of Postman collections, OpenAPI, GraphQL and SOAP definitions, role-based access control, SAML single sign-on and audit trails. It can be run as PortSwigger-hosted cloud, self-hosted, or on Kubernetes, and connects to CI/CD systems and issue trackers.
Pricing splits cleanly. The Professional edition is listed at $499 on the product page and is licensed per user per year. Burp Suite DAST has a pricing page, but no figures are published there; subscriptions are described as customised to the size of the application portfolio, so buyers must request a quote. Community edition remains free but excludes the automated scanner.
Burp Suite fits organisations that employ security specialists and want the same engine used for exploratory testing to also run in the pipeline. It fits less well where the primary buyer is a development team with no security staff, because the manual tooling that justifies the price goes unused and lighter, opinionated scanners are quicker to operate. Buyers evaluating the enterprise tier should also account for the infrastructure cost of self-hosting or running on Kubernetes, which is not part of the subscription quote.
Pros
- Deepest manual testing toolkit in the category
- Large extension ecosystem via the BApp store
- Published per-user price for the Professional edition
Cons
- Enterprise DAST tier is quote-based only
- Steep learning curve for non-specialists
2Invicti
enterpriseInvicti is an application security platform sold by Invicti Security, which also owns Acunetix. The Invicti platform positions dynamic testing as the anchor of a wider suite that includes static analysis, software composition analysis, API security testing, container scanning and application security posture management, so that findings from several scan types arrive in one inventory rather than several consoles.
The differentiator the company promotes is proof-based scanning, in which the scanner attempts safe exploitation of a candidate finding and attaches evidence when it succeeds. Findings confirmed this way can be routed to developers without a manual triage step, which is the main operational argument for the platform in portfolios where the volume of unconfirmed findings is the bottleneck. API testing covers REST, SOAP and GraphQL with automated discovery of endpoints, and the platform advertises more than 110 integrations with development, ticketing and CI/CD tools. Deployment is available as cloud or on-premises, and the product is marketed for governance of portfolios exceeding a thousand applications, including regulated sectors such as government, finance, healthcare and telecommunications.
The plans page lists four packages: Agentic Pentest, Web + API, AppSec Core and AppSec Flex. Only Agentic Pentest carries a published figure, capped at $500 per pentest. The other three route to a quote request, and Invicti also offers proof-of-concept licences for evaluation before purchase. Price therefore depends on the number of applications and targets in scope rather than on seats.
Invicti suits security organisations that own many applications, need on-premises scanning options, and can absorb a procurement cycle. It is a poor fit for a small engineering team that wants a card-payment subscription and a scan running the same afternoon, since neither the pricing model nor the onboarding path is designed for that buyer. Organisations wanting the same scanning engine at a smaller scale often look at Acunetix, the other product in the Invicti Security portfolio, which targets smaller estates.
Pros
- Automatic confirmation of many findings reduces triage time
- Covers DAST, SAST, SCA, API and container scanning
- Cloud and on-premises deployment both supported
Cons
- No public list pricing for the main packages
- Platform breadth exceeds the needs of small teams
3OWASP ZAP
open-sourceZAP, the Zed Attack Proxy, is an independent open source web application scanner maintained by the ZAP Dev Team and backed by Checkmarx. It describes itself as the most widely used web application scanner, and it is developed publicly on GitHub with community contributions. The project offers both an interactive desktop application and a headless mode designed for automation.
Functionally, ZAP provides an intercepting proxy, a spider and an AJAX spider for JavaScript-driven pages, passive scanning that flags issues as traffic passes through the proxy, and an active scanner that sends attack payloads against discovered endpoints. Add-ons distributed through the ZAP marketplace extend coverage to areas such as GraphQL, OpenAPI import and advanced authentication handling. The automation framework and the REST API allow scans to be defined as configuration files and executed from a pipeline, and the project publishes stable, bare, weekly and nightly Docker images for that purpose.
Distribution is broad. Release 2.17.0 ships as desktop installers for Windows, Linux and macOS on both Intel and Apple Silicon, as cross-platform packages, and through Homebrew Cask, the Windows Package Manager, Flathub, Snapcraft, Scoop, Chocolatey and FreeBSD ports. There is no licence fee and no paid tier, so the cost of ownership is entirely the engineering time spent configuring authentication, tuning scan policies and reviewing output.
ZAP fits teams that have the skills to run and tune a scanner themselves, organisations that cannot send application traffic to a hosted service, and educational or budget-constrained settings. It fits less well where a compliance programme requires vendor support, formal service levels, or portfolio-level dashboards, because those responsibilities remain with the operator rather than a supplier. A common compromise is to run ZAP in the pipeline for routine coverage while a commercial scanner handles portfolio reporting and the smaller set of applications subject to formal audit obligations.
Pros
- No licence cost regardless of number of applications
- Docker images and automation framework suit CI pipelines
- Large community and long release history
Cons
- Tuning and false-positive triage fall entirely on the team
- No vendor support contract or managed service
4Rapid7 InsightAppSec
enterpriseInsightAppSec is Rapid7's dynamic application security testing product, sold as part of the wider Insight platform. It performs black-box testing of running web applications and APIs, then supports triage and remediation workflows inside the same console. Rapid7 states coverage of more than 95 attack types and uses a component it calls the Universal Translator to normalise application traffic before discovery and attack phases, which is how the product handles varied frameworks and payload formats.
Operationally, the product supports unlimited and concurrent scanning, scan schedules and blackout periods so that testing avoids business-critical windows, and both cloud-hosted and on-premises scan engines for applications that are not reachable from the internet. Attack Replay is the notable developer-facing feature: a finding can be replayed against the application so an engineer can observe the request and response that produced it rather than working from a written description. Compliance reporting covers PCI DSS, HIPAA and the OWASP Top Ten, and integrations connect to Atlassian Jira and other parts of a DevOps toolchain.
Pricing is unusually transparent for an enterprise DAST product. The pricing page lists a starting figure of $175 per month per application when billed annually, in US dollars, with international pricing varying. That entry price includes the cloud and on-premises engines, unlimited concurrent scanning, the Universal Translator, scheduling and reporting. A managed service is offered separately, and custom quotes are available beyond the standard per-application model.
InsightAppSec suits security teams with a defined and moderately sized application list who value budget predictability and already run other Rapid7 products. It suits large portfolios less well, because the per-application unit multiplies quickly, and organisations preferring seat-based or unlimited-target licensing will find the arithmetic unfavourable at scale. Counting applications carefully before quoting matters, because microservice architectures can inflate the unit count well beyond what the business regards as a single application.
Pros
- Per-application list price published on the pricing page
- Cloud and on-premises scan engines included
- Compliance reporting for PCI DSS, HIPAA and OWASP Top Ten
Cons
- Per-application model becomes costly across large portfolios
- Most valuable when other Rapid7 Insight products are in use
5StackHawk
mid-marketStackHawk is a developer-first dynamic testing platform built around HawkScan, a scanner configured from a YAML file that lives in the application repository. The design intent is that application security testing runs where the code is written and merged, rather than as a separate scanning programme operated by a security team after release.
The platform performs runtime testing against a running application, including REST, GraphQL and SOAP APIs, and reports issues such as SQL injection, insecure direct object references and broken authentication. More recent positioning centres on AI coding agents: StackHawk ships agent skills for Claude Code, Cursor, Codex, Antigravity and GitHub Copilot, so that a security test can run before a pull request is opened and the same agent can apply a fix with full source context, then re-run the test to confirm the fix holds. A second skill exposes the StackHawk API so agents can adjust scan configuration and triage findings. Because configuration is version controlled, scan definitions follow branches and environments in the way other pipeline configuration does.
Pricing has two published tiers. Wingman by StackHawk is listed at $10 per user per month and is aimed at individuals and teams working with AI coding agents, with a 14-day free trial. StackHawk Scale is quote-based and intended for security teams that need coverage across the whole organisation, with pricing shaped by team size and scope.
StackHawk fits engineering organisations that already treat testing as a pipeline concern and want vulnerabilities caught before code review. It fits less well where the requirement is external attack surface discovery, unauthenticated scanning of production estates, or a broad compliance reporting pack, since the product concentrates on applications a team owns and can run in a test environment. Teams should also confirm that their staging environments can be stood up reliably in the pipeline, because the scanner needs a running target before it can report anything.
Pros
- Lowest published entry price among commercial scanners here
- Configuration lives in the repository as code
- Fits pre-merge testing rather than post-release scanning
Cons
- Organisation-wide Scale tier is quote-based
- Narrower coverage than broad exposure-management platforms
6Detectify
mid-marketDetectify is a Swedish application security vendor whose platform is organised around three products. Surface Monitoring discovers and maps external assets such as domains, subdomains, IP addresses and detected technologies, and runs payload-based tests against everything it finds. Application Scanning performs deeper authenticated dynamic testing using crawling and fuzzing. API Scanning tests API endpoints with the same payload-driven approach and picks up new endpoints as they appear.
The research model is the distinguishing feature. Detectify operates Crowdsource, a community it describes as more than 400 ethical hackers who submit vulnerability research that is converted into scanner modules. The company states that 99 percent of the vulnerabilities it finds are not covered by a CVE, which reflects an emphasis on misconfigurations, exposed interfaces and logic issues rather than version matching. That research is combined with internal researchers and an AI component the company calls Alfred, and the fuzzing engine rotates proprietary payloads between scans instead of repeating a static checklist. Detectify reports more than 2,100 customer organisations.
Pricing is published as annual figures. Starter is listed at EUR 0 per year and covers up to five users in one team, with REST and GraphQL API scanning and email support. Standard is EUR 2,500 per year for up to ten users and adds single sign-on and dedicated support. Professional is EUR 5,000 per year with unlimited users across two teams and CI/CD integration. Enterprise is EUR 15,000 per year with unlimited users and teams, custom terms and service level agreements. Additional assets, domains, environments and IP ranges attract further fees on every tier.
Detectify fits organisations whose main risk is an external estate that changes faster than the inventory does. It fits less well as a pipeline scanner for internal applications that are never exposed publicly, and the per-asset surcharges mean that estates with many small domains should model the total cost rather than reading the tier price alone. The free Starter plan makes that modelling straightforward before any commitment.
Pros
- Published annual list prices across all tiers
- Combines asset discovery with payload-based testing
- Free Starter tier for evaluation
Cons
- Extra assets, domains and IP ranges are charged separately
- CI/CD integration reserved for the Professional tier
7Veracode Dynamic Analysis
enterpriseVeracode Dynamic Analysis is the DAST component of Veracode's application security platform. The company sells static analysis, software composition analysis, container security, a remediation product and an application risk manager alongside it, and the dynamic scanner is generally purchased as part of that portfolio rather than on its own.
The product is cloud-native and designed for scheduled, repeatable scanning across large application estates. Veracode states an industry-low false positive rate below five percent for the dynamic engine, and describes scanning as production-safe, which matters where a scan may touch a live environment. Assets behind a corporate firewall can be reached through an internal scanning arrangement, so the same programme can cover both public and private applications. Scans are configurable in depth, from lightweight checks intended to run often to full assessments, and can be automated or scheduled. API security testing covers endpoints and multi-step workflows, and an external attack surface management capability discovers exposures that are not on the known inventory. Integration into CI/CD pipelines is advertised as a task of around ten minutes, and results are presented with remediation guidance rather than raw findings alone.
The value case rests on unified reporting. Dynamic results appear in the same views as static analysis and software composition analysis, which supports policy scoring and audit evidence across a portfolio without stitching several tools together. The pricing page does not publish tier names or figures for any product line, including dynamic analysis; buyers are directed to a demo or a contact form, and a free trial is offered.
This product fits enterprises with formal application security policies, audit obligations and an existing Veracode footprint. It fits poorly where a team wants only dynamic scanning, a transparent price and a short procurement path. Because the platform is normally licensed as a bundle, the effective cost of the dynamic component is difficult to isolate when comparing it against scanners sold on their own.
Pros
- Unified reporting across dynamic, static and composition analysis
- Production-safe engine scans assets behind the firewall
- Long track record with compliance-driven programmes
Cons
- No published pricing for any tier
- Dynamic analysis is rarely sold as a standalone product
8Tenable Web App Scanning
enterpriseTenable Web App Scanning is the dynamic application testing module of Tenable's exposure management line. It crawls a running application through the front end to build a site map of pages, links and forms, then tests what it finds. Tenable frames the workflow in three stages: map the application, uncover vulnerabilities, and resolve them by priority.
Coverage targets the OWASP Top 10, including cross-site scripting and SQL injection, and extends to known vulnerabilities in third-party components used by the application. Predefined templates also check for cyber hygiene issues such as SSL and TLS certificate problems and server misconfigurations, which reflects the product's origin in an infrastructure scanning company. Modern applications, including single-page applications, are supported, and Tenable states that basic assessments can complete in under two minutes. Role-based access controls govern who can run and view scans. Deployment is available as SaaS or on-premises through Tenable Security Center, and the module plugs into Tenable One so that web application findings sit in the same dashboards as IT and cloud vulnerabilities.
Licensing is based on fully qualified domain names rather than applications or users. The evaluation page shows a worked example of five FQDNs priced at $3,578, and quantities can be adjusted before purchase, so the entry cost for a small estate is knowable without a sales conversation. Larger or more complex requirements still route through Tenable's sales process.
The product fits organisations that already own Tenable Vulnerability Management or Tenable One and want web application coverage folded into an existing exposure programme. It fits less well as a standalone purchase for application security specialists, who will find deeper crawling, authentication handling and manual tooling elsewhere. Estates that spread applications across many distinct domains should price the FQDN count first, since that figure, rather than the number of applications, determines the subscription.
Pros
- List price published and purchasable by FQDN count
- Findings combine with infrastructure and cloud exposure data
- SaaS or on-premises through Tenable Security Center
Cons
- FQDN-based licensing suits estates with few large domains
- Depth trails scanners built purely for application testing
9Intruder
smbIntruder is a vulnerability management platform that presents external network scanning, cloud security posture checks and web application testing through one interface. The company positions the product for lean security and IT teams that need continuous coverage without operating several specialist tools, and its customers span enterprises, mid-market companies, healthcare, education and government.
Application coverage is described as dynamic application security testing with more than 140,000 checks, running alongside infrastructure vulnerability scanning, asset discovery, API security testing, container image scanning, secrets detection and internal scanning for employee devices. Cloud posture management covers AWS, Azure and Google Cloud with daily misconfiguration checks. The platform also includes an assistant the company calls GregAI, and offers an AI-driven pentesting service as a separate purchase. Emerging threat scans are triggered when a significant new vulnerability is published, which is the feature most often cited by buyers who want reactive coverage without running their own scanning schedule.
The pricing page lists four tiers. Free is permanently free and includes weekly external vulnerability scans, cloud checks for one account, container image scans for two images and three users. Cloud is marked as best value and adds emerging threat scans, daily cloud checks for three accounts, web application and API testing, and GregAI, but the monthly and annual figures are not displayed. Pro extends to ten cloud accounts and agent-based internal scanning, also without a displayed figure. Enterprise is custom. Annual billing is stated to save 20 percent, prices are subject to VAT, and AI-powered pentesting starts at $3,500 per test.
Intruder fits smaller organisations wanting broad coverage from one subscription. It fits poorly where deep authenticated application testing is the primary requirement, since the application checks are one component of a broad platform rather than its centre of gravity. The free tier makes evaluation cheap, but the absence of listed figures on the paid tiers means budgeting still requires a sales conversation.
Pros
- Free forever tier with weekly external scans
- Covers infrastructure, cloud and application checks in one product
- Simple interface suited to teams without specialists
Cons
- Cloud and Pro tier prices are not shown on the pricing page
- Application testing depth is lighter than dedicated DAST tools
10Appknox
specialistAppknox is a mobile application security testing platform. Where most tools in this category test web applications and APIs from the outside, Appknox takes a compiled Android or iOS binary and analyses it, then exercises the running application to find issues that only appear at runtime, such as insecure data storage, weak transport security and flawed authentication handling.
The platform combines several methods. Static analysis inspects the binary, dynamic analysis runs the application on instrumented devices, and API testing covers the backend services the application calls. Manual penetration testing is offered as a service layer on top of the automated scans, which is common in mobile security because store submission deadlines create fixed points at which a human review is expected. Adjacent products include Storeknox for monitoring published applications on app stores, software bill of materials generation, and privacy compliance assessment. Scanning can be auto-triggered so that each new build is assessed without manual submission. Appknox presents separate workflows for developers, security teams and DevSecOps engineers, and states that more than 100 global enterprises use the platform, naming customers including Unilever, Samsung, Infosys and PayTM across banking, financial services, healthcare, retail and government.
The pricing page names three tiers: Starter for small businesses, Professional for organisations with up to 20 applications, and Advanced for businesses shipping continuous updates. No figures are shown. Pricing is described as flexible and usage-based on a pay-as-you-go footing, with volume discounts for enterprises and a free first application scan, and buyers are directed to contact the company for a tailored quote.
Appknox fits organisations whose risk is concentrated in published mobile applications, particularly in regulated industries. It is not a substitute for a web application scanner and would normally be bought alongside one. The usage-based model favours companies that ship a small number of applications on a predictable release cadence, and is harder to budget for teams releasing continuously across many builds.
Pros
- Purpose-built for mobile binaries rather than web applications
- Combines automated scanning with manual penetration testing
- Usage-based model suits irregular release schedules
Cons
- No published prices on the pricing page
- Not applicable to conventional web application testing
Frequently asked questions
What does a DAST tool do?
Dynamic application security testing tools examine a running application from the outside, in the way an attacker would. The scanner crawls the application to build a map of pages, forms, parameters and API endpoints, then sends crafted requests to each one and studies the responses for evidence of flaws such as injection, cross-site scripting, broken authentication or insecure configuration. Because testing happens at runtime, findings reflect the deployed system, including its server, framework and configuration, rather than source code alone.
How does DAST differ from SAST?
Static application security testing reads source code or compiled artefacts without executing them, so it can point at the exact line responsible for a flaw and run before an application is deployable. Dynamic testing runs against a live instance and therefore sees configuration, runtime dependencies and integration behaviour, but reports at the level of a request rather than a line of code. The two produce different false positive and false negative profiles, which is why several vendors listed here sell both and report the results together.
Is an open source scanner sufficient on its own?
OWASP ZAP is capable and carries no licence cost, and many organisations run it as their only scanner. The cost moves to staff time: configuring authentication, tuning scan policies, maintaining pipeline jobs and triaging output all become internal work. Commercial products bundle vendor support, service levels, research teams and portfolio dashboards, and some automatically confirm findings before reporting them. The choice depends on whether an organisation has skills to spare and whether audit requirements name a supported product.
How much do DAST tools cost?
Published prices in this comparison range from free to several thousand pounds a year. StackHawk lists $10 per user per month, Burp Suite Professional is $499 per user per year, Rapid7 InsightAppSec starts at $175 per month per application billed annually, Detectify publishes annual tiers beginning at EUR 2,500 after a free Starter plan, and Tenable shows $3,578 per year for five domains. Invicti, Veracode and Appknox publish no figures and quote against the size of the portfolio.
Which licensing model is most economical?
It depends on the shape of the estate. Per-application pricing, as used by Rapid7, is predictable when the application count is small and stable, but multiplies across a large portfolio. Per-user pricing, as used by Burp Suite and StackHawk, favours organisations with many applications and few testers. Domain-based licensing, as used by Tenable, suits estates concentrated under a handful of fully qualified domain names. Quote-based enterprise agreements usually become competitive only at high volume.
Can DAST scanners test APIs?
Most modern scanners can, though the mechanism differs. Several products accept a specification file, such as an OpenAPI document, a Postman collection or a GraphQL schema, and use it to enumerate endpoints rather than relying on a crawler to discover them. Burp Suite DAST, Invicti, Detectify, StackHawk and Veracode all describe specification-driven API testing. Without a specification, coverage depends on whether the crawler observes API traffic during the scan, which usually leaves endpoints untested.
Is it safe to run a DAST scan against production?
Active scanning sends attack payloads, which can create records, trigger workflows, send email or degrade performance. Several vendors describe production-safe engines and offer blackout periods and rate controls to limit disruption. Common practice is to run full authenticated scans against a staging environment that mirrors production, and to run lighter, unauthenticated checks against production for coverage of what is publicly exposed. Any production scan should be scheduled with the team that operates the application.
How does DAST fit into a CI/CD pipeline?
The application must be running before it can be tested, so a pipeline scan usually deploys the build to an ephemeral or staging environment, runs the scanner against it, and fails the job when findings exceed a threshold. Tools designed for this pattern keep scan configuration in the repository and provide container images or command line runners. StackHawk and OWASP ZAP are built around that workflow; enterprise platforms support it, though scan durations often push full scans onto a nightly schedule instead.
What causes false positives, and how do vendors reduce them?
A scanner infers a vulnerability from response behaviour, so timing variation, error handling and unusual frameworks can all produce misleading signals. Vendors reduce this in different ways. Invicti attempts safe exploitation and attaches evidence when it succeeds, so confirmed findings need no manual verification. Rapid7 provides replay of the exact request and response so a developer can reproduce a finding. Veracode publishes a false positive rate below five percent. Manual verification remains necessary for logic flaws and authorisation issues.
Do these tools cover mobile applications?
Most do not. Web scanners test HTTP endpoints, so they can assess the backend APIs a mobile application calls but cannot inspect the compiled binary or its runtime behaviour on a device. Mobile testing requires a platform that analyses the package and executes it on instrumented hardware, checking areas such as local data storage, certificate handling and inter-process communication. Appknox is the mobile-focused option in this comparison, and it is normally bought alongside a web scanner rather than instead of one.
Not listed?
Vendors in this category can request a verified profile — pricing, positioning and a dated announcement page — by emailing [email protected]. See how listings work.