AiVibe

Cybersecurity & Compliance

Dynamic Application Security Testing (DAST)

A black-box testing method that examines a running application from the outside, sending crafted requests and analysing responses to find vulnerabilities such as injection, cross-site scripting and misconfiguration.

A DAST scanner first crawls the application or imports a definition of it, such as an OpenAPI description, to discover pages, parameters and endpoints. It then sends modified requests containing attack payloads and inspects responses, timing and behaviour for evidence of vulnerabilities. Because it needs no access to source code, DAST works across languages and frameworks and also exercises the web server, configuration and deployed components.

DAST is typically run against test or staging environments in CI/CD pipelines and before releases, and periodically against production with care. It finds issues that only appear at runtime, such as missing security headers, weak TLS settings, session-handling flaws and server misconfiguration. The open-source Zed Attack Proxy (ZAP), originally an OWASP project, is a widely used example.

DAST cannot point to the vulnerable line of code, may miss functionality it cannot reach, and struggles with complex authentication and multi-step workflows unless configured carefully. Scans can create data or load in the target, so test accounts and agreed testing windows are needed. It is combined with SAST, IAST and manual penetration testing for fuller coverage.

Key points

Where AiVibe comes in

AiVibe's code security analysis services cover SAST, DAST, IAST and SCA.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to Dynamic Application Security Testing (DAST)

Ask AiMuruga can explain Dynamic Application Security Testing (DAST) for your plant, product or security programme, and draw how it fits.