Dynamic Application Security Testing

Dynamic Application Security Testing (DAST) tools for dynamic application security testing that identify vulnerabilities in running web applications and APIs through automated scanning.

Explore 56 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

IronBee Logo

IronBee is an open source web application security sensor framework that provides detection and prevention capabilities for web application vulnerabilities.

0
postMessage-tracker Logo

Track postMessage usage with this Chrome Extension

0
InsightAppSec Logo

Dynamic application security testing tool for identifying and fixing web application vulnerabilities.

0
CorsMe Logo

CorsMe is a specialized scanner that identifies Cross-Origin Resource Sharing (CORS) misconfigurations in web applications and provides remediation recommendations.

0
Autorize Logo

Automatic authorization enforcement detection extension for Burp Suite

0
Rexsser Logo

A Burp Suite plugin that extracts keywords from HTTP responses using regex patterns and tests for reflected XSS vulnerabilities within the target scope.

0
Tplmap Logo

Tplmap is a command-line tool that detects and exploits server-side template injection vulnerabilities in web applications across multiple template engines.

0
MCIR Logo

MCIR is a unified framework for building code injection vulnerability testbeds that combines SQL, XML, shell, and XSS injection testing tools with shared functionality and template-based extensibility.

0
Naxsi Logo

NAXSI is a third-party nginx module that prevents XSS and SQL injection attacks by filtering HTTP traffic based on predefined security rules.

0
Dockerfiles for Testing Logo

Container image definitions that create standardized testing environments for software applications with consistent dependencies and configurations.

0
Acunetix Vulnerability Scanner Logo

A comprehensive web application security testing solution that offers built-in vulnerability assessment and management, as well as integration options with popular software development tools.

0
Introspy-Android Logo

Introspy-Android is a dynamic analysis framework that hooks Android APIs at runtime to monitor application behavior and identify security vulnerabilities on rooted devices.

0
PortSwigger Logo

A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.

0
N-Stalker Logo

A web security tool that scans for vulnerabilities and known attacks.

0
DOMPurify Logo

DOMPurify is a fast XSS sanitizer for HTML, MathML, and SVG.

0
GAUNTLT Logo

GAUNTLT - Security and Rugged Testing tool

0
Xss-Sql-Fuzz Logo

A Burp Suite plugin for automatically adding XSS and SQL payload to fuzz

0
w3af Logo

w3af is an open source web application security scanner that identifies over 200 types of vulnerabilities including XSS, SQL injection, and OS commanding in web applications.

0
CakeFuzzer Logo

CakeFuzzer is an automated vulnerability discovery tool specifically designed for identifying security issues in CakePHP web applications with minimal false positives.

0
Yara-Scanner Logo

A Python-based Burp Suite extension that integrates Yara scanning capabilities for detecting patterns and signatures in web application traffic using custom Yara rules.

0
ConDroid Logo

ConDroid is a concolic execution framework for Android applications that automates dynamic analysis by driving execution to specific code locations without manual interaction.

0
Burp-Yara-Rules Logo

A collection of Yara rules for the Burp Yara-Scanner extension that helps identify malicious software and infected web pages during web application security assessments.

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →