Static Application Security Testing

Static Application Security Testing (SAST) tools for static code analysis that detect security vulnerabilities and coding flaws in source code during development.

Explore 130 curated cybersecurity tools, with 15,426 visitors searching for solutions

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

Get Featured

Feature your product and reach thousands of professionals.

Black Duck Coverity Static Analysis Logo

SAST tool for finding code quality & security defects in large-scale software

0
Black Duck Polaris Platform Logo

Cloud platform for automated AST with SAST, SCA, and DAST capabilities

0
The Code Registry Technical Due Diligence Logo

AI-powered code analysis platform for technical due diligence and audits

0
Sec1 ProSAST Logo

SAST tool that identifies vulnerabilities in source code across 30+ languages

0
Software Improvement Group Sigrid® Logo

Software portfolio governance platform for code quality and security analysis

0
BoostSecurity Secrets Detection Logo

Scans source code and containers for 130+ types of hardcoded secrets

0
BoostSecurity Continuous AppSec Testing Logo

Continuous AppSec testing platform with zero-touch provisioning for CI/CD

0
Snyk DeepCode AI Logo

AI-powered SAST tool for code vulnerability detection and automated fixing

0
SonarSource Advanced Security Logo

SAST and SCA platform for code security analysis with taint analysis

0
Sonarsource SonarQube IDE Logo

IDE plugin for real-time code quality and security issue detection

0
GrammaTech Bug-Injector Logo

Generates test cases by injecting known bugs into code for testing DevSecOps.

0
GrammaTech Tbdisasm Logo

Trace-based disassembler for analyzing obfuscated and packed binaries

0
GrammaTech HALucinator Logo

Firmware analysis and emulation platform using High-Level Emulation (HLE)

0
Variegate Variegate Logo

Source code diversification tool that creates program variants with diversity

0
DARPA Bin2Math Logo

Extracts mathematical algorithms from binary programs for CPS analysis.

0
Fluid Attacks Reverse Engineering Logo

Reverse engineering service for identifying vulnerabilities in software

0
Fluid Attacks Secure Code Review (SCR) Logo

Manual secure code review service with continuous SAST and zero-day detection

0
Fluid Attacks SAST Logo

SAST tool for continuous source code vulnerability scanning and remediation

0
Qwiet AI Secrets Detection Logo

Detects secrets and credentials in code using AI/ML and Code Property Graph

0
Qwiet AI AutoFix Logo

AI-powered automated vulnerability fixing for code security

0
Qwiet AI SAST Logo

AI-powered SAST tool for scanning code vulnerabilities with low false positives

0
Apiiro Deep Code Analysis Logo

Code analysis tool that maps software architecture and components via AST.

0
DerSecur DerScanner Logo

SAST tool that scans source code and binaries for security vulnerabilities

0
Offensive 360 Logo

SAST tool using virtual compilers to analyze source code for vulnerabilities

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

7
TestSavant AI Security Assurance Platform Logo

AI security assurance platform for red-teaming, guardrails & compliance

5
OSINTLeak Real-time OSINT Leak Intelligence Logo

Real-time OSINT monitoring for leaked credentials, data, and infrastructure

5
Mandos Brief Logo

Weekly cybersecurity newsletter covering security incidents, AI, and leadership

5
View Popular Tools →

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

Static Application Security Testing Tools - FAQ

Common questions about Static Application Security Testing tools including selection guides, pricing, and comparisons.

Static Application Security Testing (SAST) tools for static code analysis that detect security vulnerabilities and coding flaws in source code during development.

Have more questions? Browse our categories or search for specific tools.