Definition · Known Vulnerabilities (CVEs)
What is DAST?
DAST (dynamic application security testing) is a black-box testing approach that probes a running application the way an attacker would — sending crafted HTTP requests and analysing the responses for signs of vulnerability. Because it needs no access to source code, DAST works against any web application or API, regardless of language or framework.
What DAST finds
DAST tools are effective at detecting vulnerabilities that manifest at runtime:
- Injection flaws (SQL injection, command injection, cross-site scripting)
- Authentication and session management weaknesses
- Server misconfigurations, missing security headers, and verbose error messages
- Known CVEs in exposed software, identified via version detection and vulnerability templates such as Nuclei
DAST vs SAST
SAST analyses source code without running it; DAST tests the running application without seeing the code. SAST finds flaws earlier in development and can pinpoint the offending line, while DAST finds issues that only appear in a deployed environment — misconfigurations, integration bugs, and exposed endpoints. Mature programmes use both.
DAST and the external attack surface
Because DAST operates outside-in, it pairs naturally with external attack surface management: EASM discovers which applications are exposed, and dynamic testing assesses how vulnerable they are.