# Best Dynamic Application Security Testing (DAST) Software

## How Many Dynamic Application Security Testing (DAST) Software Products Does G2 Track?

**Total Products under this Category:** 95

### Category Stats (Aug 2026)

- **Average Rating:** 4.56/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** AppSentinels (+1.05%) - Among all products in this category, AppSentinels recorded the largest rating increase compared to last month

_Last updated: August 02, 2026_

## How Does G2 Rank Dynamic Application Security Testing (DAST) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 4,100+ Authentic Reviews
- 95+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Dynamic Application Security Testing (DAST) Software
 ![G2 Grid® for Dynamic Application Security Testing (DAST) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/dynamic-application-security-testing-dast/grids.png?focus%5B%5D=1259627&focus%5B%5D=154599&focus%5B%5D=32486&focus%5B%5D=1332841&focus%5B%5D=19003&focus%5B%5D=32484&focus%5B%5D=32494&focus%5B%5D=100655)

Highlighted products: Aikido Security, Astra Pentest, Burp Suite, Qodex.ai, GitLab, Invicti (formerly Netsparker), Tenable Nessus, and Harness Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/dynamic-application-security-testing-dast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=astra-pentest&focus%5B%5D=burp-suite&focus%5B%5D=qodex-ai&focus%5B%5D=gitlab&focus%5B%5D=invicti-formerly-netsparker&focus%5B%5D=tenable-nessus&focus%5B%5D=harness-platform)

**Sponsored**

### Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1521&secure%5Bchosen_at%5D=2026-08-02T15%3A59%3A11Z&secure%5Bdisplayable_resource_id%5D=1521&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1521&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1259627&secure%5Bresource_id%5D=1521&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fdynamic-application-security-testing-dast&secure%5Btoken%5D=9c8711e48b9975a81734a2e0c17e99cd97a4004cabcaf204ddcaf6bc4e8385f3&secure%5Burl%5D=https%3A%2F%2Fwww.aikido.dev%2Fattack%2Fsurface-monitoring-dast%3Futm_source%3Dg2%26utm_campaign%3Dg2-promoted-listing-dast%26utm_medium%3Dcpc&secure%5Burl_type%5D=custom_url)

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 254

#### How Do G2 Users Rate Aikido Security?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.3/10 (Category avg: 8.6/10)
- **Detection Rate:** 10.0/10 (Category avg: 8.7/10)
- **Test Automation:** 10.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

### [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews)

Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.

**Average Rating:** 4.6/5.0

**Total Reviews:** 222

#### How Do G2 Users Rate Astra Pentest?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.3/10 (Category avg: 8.6/10)
- **Detection Rate:** 8.9/10 (Category avg: 8.7/10)
- **Test Automation:** 8.8/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Astra Pentest?

- **Seller:** [ASTRA IT, Inc.](https://www.g2.com/sellers/astra-it-inc)
- **Company Website:** www.getastra.com
- **Year Founded:** 2018
- **HQ Location:** New Delhi, IN
- **Twitter:** @getastra  
694 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fbe109060085ad9c09016ddbb00bd4f363004bed188f1fd0e5a11ea004d08c89&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgetastra%2F&secure%5Burl_type%5D=linkedin_company_website)  
130 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CTO, CEO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 67% Small, 28% Medium

#### What Do G2 Reviewers Say About Astra Pentest?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **responsive customer support** of Astra Pentest, enhancing their experience and ensuring smooth collaboration.
- Users value the **comprehensive vulnerability management features** of Astra Pentest, enhancing their ability to address security issues effectively.
- Users love the **ease of use** of Astra Pentest, appreciating its intuitive design and accessible features.
- Users commend Astra Pentest for its **efficient penetration testing** , enabling swift execution and effective communication throughout the process.
- Users value the **thorough vulnerability identification** of Astra Pentest, enhancing confidence and security in their development processes.

##### Cons

- Users experience **poor customer support** , citing slow responses and difficulties with account setup and vulnerability inquiries.
- Users find the **poor interface design** of Astra Pentest to be clunky and not user-friendly, affecting usability.
- Users experience **slow performance** with Astra Pentest, affecting testing speed and response times for results.
- Users feel that the **UX could be improved** for a smoother experience, as navigation can sometimes be confusing.
- Users face a **lack of information** with Astra Pentest, as documentation and updates are often insufficient or slow to arrive.

#### What Are Recent G2 Reviews of Astra Pentest?

**["Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls"](https://www.g2.com/survey_responses/astra-pentest-review-13001206)**

**Rating:** 5.0/5.0 stars

_— Sivakumar S._

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-13001206)

**["Exceptional VAPT Solution with Prompt Support"](https://www.g2.com/survey_responses/astra-pentest-review-9603864)**

**Rating:** 5.0/5.0 stars

_— Nikhil Ajit S._

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-9603864)

#### What Are G2 Users Discussing About Astra Pentest?

- [What is Astra Pentest used for?](https://www.g2.com/discussions/what-is-astra-pentest-used-for) - 2 comments

### [Burp Suite](https://www.g2.com/products/burp-suite/reviews)

Burp Suite is a complete ecosystem for web application and API security testing, combining two products: Burp Suite DAST - a best-of-breed, precision DAST solution that automates runtime testing, and Burp Suite Professional - the industry-standard toolkit for manual penetration testing. Developed by PortSwigger, more than 85,000 security professionals rely on Burp Suite to find, verify, and understand vulnerabilities across complex modern web applications. Burp Suite DAST is PortSwigger’s enterprise dynamic application security testing (DAST) solution, purpose-built for continuous, automated scanning of web applications and APIs. Unlike many DAST solutions, which are part of a wider AST offering, Burp Suite DAST is not a bolt-on tool - instead it’s precision-built from over 20 years of dynamic testing experience. Burp Suite DAST reveals the runtime issues that static analysis tools miss, such as authentication flaws, configuration drift, and chained vulnerabilities. Built on the same proprietary scanning engine that powers Burp Suite Professional, it delivers precise, low-noise results that security teams trust. Key capabilities of Burp Suite DAST include: Continuous, automated scanning of web applications and APIs, integration with CI/CD pipelines and vulnerability management tools, flexible deployment across cloud, and on-premise environments, shared scanning logic and configurations between automated and manual testing, accurate, low-noise detection informed by PortSwigger Research. Burp Suite Professional complements DAST with deep manual testing capability. It’s the industry-standard toolkit for penetration testers, consultants, and AppSec engineers who need complete insight and flexibility when validating or exploring vulnerabilities. Findings discovered by DAST can be investigated and verified in Burp Suite Professional, ensuring every result is accurate, contextual, and actionable. Together, Burp Suite DAST and Burp Suite Professional create a unified ecosystem that delivers automation at breadth and manual depth where it counts. Burp Suite is built for AppSec teams who need scalable, trustworthy coverage across web and API environments, enabling a seamless handoff between automated and manual testing.

**Average Rating:** 4.8/5.0

**Total Reviews:** 126

#### How Do G2 Users Rate Burp Suite?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.3/10 (Category avg: 8.6/10)
- **Detection Rate:** 7.2/10 (Category avg: 8.7/10)
- **Test Automation:** 7.5/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Burp Suite?

- **Seller:** [PortSwigger](https://www.g2.com/sellers/portswigger)
- **Company Website:** www.portswigger.net
- **Year Founded:** 2008
- **HQ Location:** Knutsford, GB
- **Twitter:** @Burp\_Suite  
138,186 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=89be7395b22b93d4e5529122592390dc29238f493eef5dbfe060e81d512f33b1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fportswigger-web-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
345 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Cyber Security Analyst
- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 41% Medium, 31% Small

#### What Do G2 Reviewers Say About Burp Suite?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Burp Suite, enabling quick setup for both beginners and advanced professionals.
- Users appreciate the **user-friendly interface** of Burp Suite, making penetration testing straightforward and accessible for all levels.
- Users value the **deep automation and manual testing capabilities** of Burp Suite for effective web and Android security testing.
- Users admire the **user-friendly interface** and seamless integration of Burp Suite, enhancing both navigation and testing efficiency.
- Users love the **clear interface** of Burp Suite, enabling effortless traffic interception and easy navigation.

##### Cons

- Users find Burp Suite **expensive** , especially students, limiting accessibility to its powerful features and community support.
- Users report **slow performance** with Burp Suite, particularly on low-spec systems and during resource-intensive scans.
- Users find the **steep learning curve** of Burp Suite challenging, especially for beginners navigating its complex features.
- Users struggle with the **steep learning curve** of Burp Suite, finding it challenging, especially for beginners.
- Users find the **limited customization options** in Burp Suite restrict their ability to tailor the tool to their needs.

#### What Are Recent G2 Reviews of Burp Suite?

**["Complete Control Over Web Requests with Burp Suite"](https://www.g2.com/survey_responses/burp-suite-review-12677559)**

**Rating:** 5.0/5.0 stars

_— Arish B._

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12677559)

**["Burp Suite Pro: A Powerful, All-in-One Platform for Web App Pen Testing"](https://www.g2.com/survey_responses/burp-suite-review-12818180)**

**Rating:** 4.5/5.0 stars

_— Aryan S._

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12818180)

#### What Are G2 Users Discussing About Burp Suite?

- [What are the benefits and challenges of using BurpSuite for web application security?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-burpsuite-for-web-application-security)
- [What is BurpSuite used for?](https://www.g2.com/discussions/burpsuite-what-is-burpsuite-used-for)
- [What types of vulnerabilities can Burp Suite detect?](https://www.g2.com/discussions/what-types-of-vulnerabilities-can-burp-suite-detect)
- [What is Burp Suite Professional?](https://www.g2.com/discussions/what-is-burp-suite-professional) - 1 comment
- [Is BurpSuite free?](https://www.g2.com/discussions/is-burpsuite-free) - 2 comments

### [Qodex.ai](https://www.g2.com/products/qodex-ai/reviews)

Qodex is a continuous testing platform that runs your test scenarios against your real app on every pull request and deploy, then shows you exactly what broke with the failing request, response, and screenshot.

**Average Rating:** 4.9/5.0

**Total Reviews:** 60

#### How Do G2 Users Rate Qodex.ai?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.3/10 (Category avg: 8.6/10)
- **Detection Rate:** 8.3/10 (Category avg: 8.7/10)
- **Test Automation:** 10.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Qodex.ai?

- **Seller:** [QodexAI](https://www.g2.com/sellers/qodexai)
- **Company Website:** www.qodex.ai
- **Year Founded:** 2023
- **HQ Location:** San Francisco, California
- **LinkedIn® Page:** [linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d038e99b692165644ae7d01154b91132e72eb2c204e81cb300af5f1c72c22ce8&secure%5Burl%5D=https%3A%2F%2Flinkedin.com%2Fcompany%2Fqodexai&secure%5Burl_type%5D=linkedin_company_website)  
13 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 75% Small, 20% Medium

#### What Do G2 Reviewers Say About Qodex.ai?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of Qodex.ai, making it accessible for both technical and non-technical teams.
- Users value the **automation capabilities** of Qodex.ai, significantly enhancing efficiency in managing API testing processes.
- Users value the **ease of test case writing** with Qodex.ai, enhancing efficiency for developers and product managers.
- Users value the **high testing efficiency** of Qodex.ai, achieving 90% code coverage with minimal manual effort.
- Users find Qodex.ai **incredibly helpful** for quick integration and effective scenario analysis, boosting efficiency significantly.

##### Cons

- Users experience **slow loading** times with the chatbot and reports, affecting overall efficiency and responsiveness.
- Users find the **poor documentation** a barrier to fully leverage Qodex.ai’s capabilities in advanced testing scenarios.
- Users experience **slow performance** with delayed chatbot responses and longer load times for reports on larger projects.
- Users report **bug issues** including repeated test cases and suggest improvements for bug reporting and flagging accuracy.
- Users report **bug reporting issues** , suggesting improvements for tagging and accuracy of critical and non-critical bugs.

#### What Are Recent G2 Reviews of Qodex.ai?

**["Effortless AI Testing Automation That Accelerates Development"](https://www.g2.com/survey_responses/qodex-ai-review-12088697)**

**Rating:** 4.5/5.0 stars

_— Abhilash S._

[Read full review](https://www.g2.com/survey_responses/qodex-ai-review-12088697)

**["Effortless Automation and Insightful AI Testing with Qodex.ai"](https://www.g2.com/survey_responses/qodex-ai-review-12065938)**

**Rating:** 4.5/5.0 stars

_— Anshuk K._

[Read full review](https://www.g2.com/survey_responses/qodex-ai-review-12065938)

### [GitLab](https://www.g2.com/products/gitlab/reviews)

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

**Average Rating:** 4.5/5.0

**Total Reviews:** 884

#### How Do G2 Users Rate GitLab?

- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.2/10)
- **API / Integrations:** 9.2/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.0/10 (Category avg: 8.7/10)
- **Test Automation:** 9.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind GitLab?

- **Seller:** [GitLab Inc.](https://www.g2.com/sellers/gitlab-inc)
- **Company Website:** about.gitlab.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @gitlab  
171,534 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a712a3bc9d0c8f9d0d986490c4b4786dfb8085e13a770fa4c99cd9d01137c372&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5101804%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,473 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 37% Medium, 37% Small

#### What Do G2 Reviewers Say About GitLab?

_AI-generated summary from verified user reviews_

##### Pros

- Users enjoy the **ease of use** of GitLab, thanks to its unified interface and streamlined CI/CD integrations.
- Users value the **all-in-one platform** of GitLab, which streamlines development processes and enhances team collaboration.
- Users praise GitLab for its **powerful CI/CD integration** , which simplifies automation and enhances pipeline efficiency.
- Users value GitLab's **s seamless integrations** allowing streamlined workflows without the need for multiple tools.
- Users value GitLab's **seamless CI/CD integration** , which simplifies automation and enhances overall development efficiency.

##### Cons

- Users find the **complexity** of GitLab's group structure and management challenging, particularly for newcomers and infrastructure.
- Users face a **difficult learning curve** with GitLab, especially for those unfamiliar with its unique structure and features.
- Users find the **confusing interface** of GitLab overwhelming, especially new users navigating its complex functionalities and settings.
- Users find the **complex user interface** of GitLab requires significant effort to master and is not always intuitive.
- Users find the **steep learning curve** of GitLab challenging, especially when adapting to its comprehensive features and UI.

#### What Are Recent G2 Reviews of GitLab?

**["GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning"](https://www.g2.com/survey_responses/gitlab-review-12864830)**

**Rating:** 5.0/5.0 stars

_— mani s._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12864830)

**["All-in-One DevOps Platform That Streamlines CI/CD and Collaboration"](https://www.g2.com/survey_responses/gitlab-review-12894467)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12894467)

#### What Are G2 Users Discussing About GitLab?

- [What is GitLab used for?](https://www.g2.com/discussions/what-is-gitlab-used-for) - 2 comments
- [Why GitLab is better than Jenkins?](https://www.g2.com/discussions/why-gitlab-is-better-than-jenkins) - 1 comment
- [Is GitLab paid?](https://www.g2.com/discussions/is-gitlab-paid) - 5 comments, 2 upvotes
- [Is GitLab free software?](https://www.g2.com/discussions/is-gitlab-free-software) - 4 comments, 1 upvote
- [What can GitLab do?](https://www.g2.com/discussions/what-can-gitlab-do) - 2 comments

### [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews)

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

**Average Rating:** 4.5/5.0

**Total Reviews:** 69

#### How Do G2 Users Rate Invicti (formerly Netsparker)?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.2/10 (Category avg: 8.6/10)
- **Detection Rate:** 8.6/10 (Category avg: 8.7/10)
- **Test Automation:** 8.5/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Invicti (formerly Netsparker)?

- **Seller:** [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)
- **Company Website:** www.invicti.com
- **Year Founded:** 2018
- **HQ Location:** Austin, Texas
- **Twitter:** @InvictiSecurity  
2,557 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3c6c2278d6d9ef248056074aabb5416f9e0b5bf217ea8a7bfb87419d2894bc76&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Finvicti-security%2Fpeople%2F&secure%5Burl_type%5D=linkedin_company_website)  
335 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 46% Large, 29% Medium

#### What Do G2 Reviewers Say About Invicti (formerly Netsparker)?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of Invicti, appreciating its user-friendly setup and quick installation process.
- Users value the **efficient scanning technology** of Invicti, enhancing workflow with hassle-free monthly website tests.
- Users commend Invicti's **accurate vulnerability detection and excellent integration with DevOps tools** , enhancing their security testing efficiency.
- Users value the **high-quality reporting** of Invicti, making it ideal for certifications and simplifying compliance processes.
- Users value the **effective vulnerability detection** of Invicti, appreciating its ease of use and accurate reporting.

##### Cons

- Users find the **customer support lacking** , with slow responses and inadequate solutions for technical issues.
- Users experience **slow performance** during scans, setup, and upgrades, impacting the overall efficiency of Invicti.
- Users find that **slow scanning** can hinder efficiency, especially when setup is tricky and API scanning is limited.
- Users face **API issues** with Invicti, making it unsuitable for scanning purposes despite good support.
- Users find the **complex setup** challenging initially, impacting their experience before they can effectively utilize the product.

#### What Are Recent G2 Reviews of Invicti (formerly Netsparker)?

**["Efficient Scanning, Superb Usability"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)**

**Rating:** 4.5/5.0 stars

_— Zach G._

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)

**["Scalable Enterprise Security: Deep Endpoint Coverage via Invicti"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)

#### What Are G2 Users Discussing About Invicti (formerly Netsparker)?

- [What is Invicti (formerly Netsparker) used for?](https://www.g2.com/discussions/what-is-invicti-formerly-netsparker-used-for) - 1 comment
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/invicti-formerly-netsparker-what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost-a1ecffa4-a216-4bcc-affd-40dc140f3e27)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost)

### [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews)

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly and easily identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations - across a variety of operating systems, devices, and applications. With features such as pre-built policies and templates, customizable reporting, group “snooze” functionality, and real-time updates, Nessus is designed to make vulnerability assessment simple, easy, and intuitive. The result: less time and effort to assess, prioritize, and remediate issues.

**Average Rating:** 4.5/5.0

**Total Reviews:** 290

#### How Do G2 Users Rate Tenable Nessus?

- **Has the product been a good partner in doing business?:** 8.7/10 (Category avg: 9.2/10)

#### Who Is the Company Behind Tenable Nessus?

- **Seller:** [Tenable](https://www.g2.com/sellers/tenable)
- **Company Website:** www.tenable.com
- **HQ Location:** Columbia, MD
- **Twitter:** @TenableSecurity  
87,752 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=029266d223c06e6b09e6d209209f15aad3bbad59d05069b38d5ec2757e74adef&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F25452%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,350 employees on LinkedIn®
- **Ownership:** NASDAQ: TENB

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, Network Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 40% Medium, 34% Large

#### What Do G2 Reviewers Say About Tenable Nessus?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **vulnerability identification** capabilities of Tenable Nessus, highlighting its accuracy and comprehensive coverage for security management.
- Users value the **advanced vulnerability detection** capabilities of Tenable Nessus, enhancing their security risk management effectively.
- Users value the **ease of use** of Tenable Nessus, appreciating its simple setup and user-friendly interface.
- Users value the **automated scanning** capabilities of Tenable Nessus, benefiting from its comprehensive and up-to-date vulnerability checks.
- Users commend the **comprehensive scanning capabilities** of Tenable Nessus, alongside its robust reporting and automation features.

##### Cons

- Users note the **slow scanning** process, especially in large environments, significantly impacting resource usage and production times.
- Users find the **cost of running and maintaining Tenable Nessus** to be extensively high and burdensome.
- Users find **limited features** in Tenable Nessus, including restrictions on hosts, scans, and mobile application testing.
- Users find the **complexity** of Tenable Nessus challenging, especially with advanced features requiring significant technical knowledge.
- Users report that Nessus generates **false positives** , resulting in extra workload and hindering effective security management.

#### What Are Recent G2 Reviews of Tenable Nessus?

**["Self-Contained Nessus Scanning with Full Control in Offline Environments"](https://www.g2.com/survey_responses/tenable-nessus-review-12937668)**

**Rating:** 4.0/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/tenable-nessus-review-12937668)

**["Reliable and Efficient Vulnerability Management Tool"](https://www.g2.com/survey_responses/tenable-nessus-review-12989192)**

**Rating:** 5.0/5.0 stars

_— Mohsin H._

[Read full review](https://www.g2.com/survey_responses/tenable-nessus-review-12989192)

#### What Are G2 Users Discussing About Tenable Nessus?

- [What is Nessus used for?](https://www.g2.com/discussions/what-is-nessus-used-for) - 1 comment
- [What types of vulnerabilities are scanned by Nessus?](https://www.g2.com/discussions/what-types-of-vulnerabilities-are-scanned-by-nessus)
- [Is there a free version of Nessus?](https://www.g2.com/discussions/is-there-a-free-version-of-nessus) - 2 comments
- [What is an advantage of using Nessus?](https://www.g2.com/discussions/what-is-an-advantage-of-using-nessus)
- [What does Nessus scan for?](https://www.g2.com/discussions/what-does-nessus-scan-for) - 1 comment

### [Harness Platform](https://www.g2.com/products/harness-platform/reviews)

Simplify your developer experience with the world's first AI-augmented software delivery platform. Upgrade your software delivery with Harness' innovative CI/CD, Feature Flags, Infrastructure as Code Management, and Chaos Engineering tools. We are a software delivery platform that helps developers and infrastructure engineers build and ship code for cloud and on-premise projects. We automate the continuous integration and continuous delivery (CI/CD) process to help teams build faster, ship more frequently, and improve quality, efficiency, and governance. We help companies in four key areas: Number one, we accelerate innovation through DevOps modernization. We provide an approach for software delivery that automates processes, reduces manual interventions, consolidates tools, and accelerates time-to-market for new products, features, and fixes. Number two, we improve developer experience. We give you the ability to attract, retain, and onboard high-caliber engineering talent while fostering a culture of continuous innovation and improvement. Number three, we secure software delivery. We give you the ability to integrate security into every phase of the SDLC. And last but not least is, we optimize cloud costs. We give you the ability to eliminate waste and to ensure that appropriate cloud resources are allocated at the right place at the right time.

**Average Rating:** 4.6/5.0

**Total Reviews:** 301

#### How Do G2 Users Rate Harness Platform?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)

#### Who Is the Company Behind Harness Platform?

- **Seller:** [Harness](https://www.g2.com/sellers/harness-25016f40-e80f-4417-bea8-39412055d17a)
- **Company Website:** harness.io
- **Year Founded:** 2018
- **HQ Location:** San Francisco
- **Twitter:** @HarnessWealth  
1,389 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fbec562b1d7a892f3293de88d17cc0509949905a19856805c612616710bc3a7d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fharnessinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,701 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 43% Large, 37% Medium

#### What Do G2 Reviewers Say About Harness Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Harness Platform, making implementation and configuration seamless and efficient.
- Users value the **ease of use and flexibility** in targeting features within the Harness Platform.
- Users appreciate the **user-friendly interface** of Harness Platform for easily managing and deploying feature flags.
- Users find the **easy setup** of Harness Platform quick and efficient, leading to immediate cost savings and satisfaction.
- Users value the **easy integrations** with SSO and tools that streamline software delivery on the Harness Platform.

##### Cons

- Users note a **lack of multiple filters** in Harness Platform, limiting flexibility for advanced customization and usability.
- Users face **limitations in configuration management** , including issues with renaming and deleting toggles that complicate usability.
- Users note a **lack of multiple filters** and missing features in the Harness Platform, limiting its overall usability.
- Users find the **steep learning curve** challenging, particularly due to complicated settings and insufficient documentation.
- Users find the **UI complex and clunky** , which can complicate the overall user experience with the platform.

#### What Are Recent G2 Reviews of Harness Platform?

**["Harness - World of automation"](https://www.g2.com/survey_responses/harness-platform-review-11792426)**

**Rating:** 4.5/5.0 stars

_— Sunil A._

[Read full review](https://www.g2.com/survey_responses/harness-platform-review-11792426)

**["End-to-End DevOps Automation with Powerful, Flexible CI/CD Pipelines"](https://www.g2.com/survey_responses/harness-platform-review-13164505)**

**Rating:** 4.5/5.0 stars

_— Ravindra N._

[Read full review](https://www.g2.com/survey_responses/harness-platform-review-13164505)

#### What Are G2 Users Discussing About Harness Platform?

- [What is Harness Continuous Delivery used for?](https://www.g2.com/discussions/what-is-harness-continuous-delivery-used-for) - 1 comment
- [What is Propelo used for?](https://www.g2.com/discussions/what-is-propelo-used-for)
- [What is Harness Cloud Cost Management used for?](https://www.g2.com/discussions/what-is-harness-cloud-cost-management-used-for)
- [What is the difference between harness and Jenkins?](https://www.g2.com/discussions/what-is-the-difference-between-harness-and-jenkins) - 1 comment
- [What is streaming Split IO?](https://www.g2.com/discussions/what-is-streaming-split-io) - 1 comment

### [Intruder](https://www.g2.com/products/intruder/reviews)

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

**Average Rating:** 4.8/5.0

**Total Reviews:** 209

#### How Do G2 Users Rate Intruder?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.9/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.5/10 (Category avg: 8.7/10)
- **Test Automation:** 8.8/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Intruder?

- **Seller:** [Intruder](https://www.g2.com/sellers/intruder)
- **Company Website:** www.intruder.io
- **Year Founded:** 2015
- **HQ Location:** London
- **Twitter:** @intruder\_io  
979 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f067752387faaf8e51f29bfa65216c4d098142c0465fc0e1e9614d24e55d97f8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F6443623%2F&secure%5Burl_type%5D=linkedin_company_website)  
83 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CTO, Director
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 57% Small, 36% Medium

#### What Do G2 Reviewers Say About Intruder?

_AI-generated summary from verified user reviews_

##### Pros

- Users find the **ease of use** of Intruder perfect for configuring and scanning cloud resources efficiently.
- Users appreciate the **easy configuration of vulnerability detection** , making it simple to secure cloud resources efficiently.
- Users value the **exceptional customer support** from Intruder, highlighting quick responses and friendliness during their experience.
- Users value Intruder's **easy-to-use interface** and seamless integration, enhancing their cybersecurity management experience significantly.
- Users value the **easy configuration** of Intruder, allowing timely identification of vulnerabilities across cloud resources.

##### Cons

- Users find the service to be **expensive** , suggesting improvements in pricing models for better value.
- Users report **slow scanning** as Intruder misses some vulnerabilities and lacks integration with comprehensive testing tools.
- Users struggle with the **licensing model** of Intruder, finding it complex and not immediately intuitive.
- Users experience **false positives** from Intruder, leading to confusion between critical and lower-risk vulnerabilities.
- Users find the **limited features** of Intruder frustrating, especially regarding reporting flexibility and license understanding.

#### What Are Recent G2 Reviews of Intruder?

**["Reliable Service with Flexible Plans and Strong Support"](https://www.g2.com/survey_responses/intruder-review-13110046)**

**Rating:** 4.0/5.0 stars

_— Ossama M._

[Read full review](https://www.g2.com/survey_responses/intruder-review-13110046)

**["Revolutionized Our Vulnerability Management with Real-Time Insights"](https://www.g2.com/survey_responses/intruder-review-13100568)**

**Rating:** 4.5/5.0 stars

_— Verified User_

[Read full review](https://www.g2.com/survey_responses/intruder-review-13100568)

#### What Are G2 Users Discussing About Intruder?

- [Who developed intruder?](https://www.g2.com/discussions/who-developed-intruder)
- [What is an intruder in cyber security?](https://www.g2.com/discussions/what-is-an-intruder-in-cyber-security)
- [Is intruder IO safe?](https://www.g2.com/discussions/is-intruder-io-safe) - 1 comment
- [What is intruder software?](https://www.g2.com/discussions/what-is-intruder-software) - 1 comment

### [Pynt - API Security Testing](https://www.g2.com/products/pynt-api-security-testing/reviews)

Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly secured APIs, before hackers do.

**Average Rating:** 4.8/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Pynt - API Security Testing?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **API / Integrations:** 9.5/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.3/10 (Category avg: 8.7/10)
- **Test Automation:** 9.2/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Pynt - API Security Testing?

- **Seller:** [Pynt](https://www.g2.com/sellers/pynt)
- **Year Founded:** 2022
- **HQ Location:** Tel Aviv, IL
- **Twitter:** @pynt\_io  
361 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=98dcfdb7470a5a3fa5185235cf6c5c65f8b19a7355c4784b35f8dfbedbe3fa0f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpynt&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Computer & Network Security
- **Company Size:** 57% Small, 23% Large

#### What Do G2 Reviewers Say About Pynt - API Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Pynt for its **auto-generation of security tests** , making vulnerability detection accessible for all development teams.
- Users commend Pynt for its **impressive security engine** that effectively identifies critical API vulnerabilities quickly.
- Users value the **seamless integration** of Pynt into CI/CD pipelines for automated API security testing and vulnerability identification.
- Users appreciate the **easy integration** of Pynt with their SDLC, enhancing automated API security without disrupting workflows.
- Users highlight the **automation capabilities** of Pynt, streamlining API security tasks and enhancing efficiency in development workflows.

##### Cons

- Users find the **complex setup** of Pynt challenging, often requiring support which complicates the initial experience.
- Users find the **setup complexity** challenging, often needing support and seeking a more user-friendly interface.
- Users experience **limited features** in Pynt, particularly in reporting, dashboard options, and onboarding processes for complex APIs.
- Users find the **user interface challenging** , especially beginners who struggle with navigation and setup.
- Users find the **user interface challenging** , suggesting improvements for a more user-friendly experience in Pynt.

#### What Are Recent G2 Reviews of Pynt - API Security Testing?

**["Comprehensive Review of Pynt Tool"](https://www.g2.com/survey_responses/pynt-api-security-testing-review-10046930)**

**Rating:** 5.0/5.0 stars

_— Vijayaraghavan (Vijay) V._

[Read full review](https://www.g2.com/survey_responses/pynt-api-security-testing-review-10046930)

**["Performance and Usability Review of pynt G2"](https://www.g2.com/survey_responses/pynt-api-security-testing-review-11135423)**

**Rating:** 5.0/5.0 stars

_— Devanggiri G._

[Read full review](https://www.g2.com/survey_responses/pynt-api-security-testing-review-11135423)

### [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews)

Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in continuous offensive security testing grounded in human expertise. The Cobalt Offensive Security Platform spans the full spectrum of offensive security, from targeted, human-led pentesting to high-frequency, AI-driven autonomous security testing. Only Cobalt brings together the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry's largest dataset of real-world pentest results. Thousands of customers and hundreds of partners rely on Cobalt and its global network of 500+ vetted security experts to continuously identify, prioritize, and remediate exploitable risk with the speed, flexibility, and precision today's organizations require.

**Average Rating:** 4.5/5.0

**Total Reviews:** 179

#### How Do G2 Users Rate Cobalt?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.6/10 (Category avg: 8.6/10)
- **Detection Rate:** 8.6/10 (Category avg: 8.7/10)
- **Test Automation:** 8.9/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Cobalt?

- **Seller:** [Cobalt](https://www.g2.com/sellers/cobalt-33275b9c-c870-4949-8fd5-a68eb12f96bb)
- **Company Website:** cobalt.io
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California
- **Twitter:** @cobalt\_io  
8,462 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ed9f585b23d4060fb4049f4e12e0029f88ad6480cba48b930678edf3b5b77c33&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcobalt_io%2F&secure%5Burl_type%5D=linkedin_company_website)  
557 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 52% Medium, 23% Small

#### What Do G2 Reviewers Say About Cobalt?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **pentesting efficiency** of Cobalt due to its seamless process and prompt report generation.
- Users commend Cobalt for its **exceptional customer support** , providing expertise and assistance throughout the pentesting process.
- Users value the **ease of use** of Cobalt, praising its seamless setup and quick reporting for pentests.
- Users value the **constant communication** during the process, enhancing collaboration and transparency throughout their experience with Cobalt.
- Users value the **immediate and comprehensive reports** from Cobalt, simplifying pentesting and ensuring compliance.

##### Cons

- Users find Cobalt to be **expensive** , particularly for small organizations and due to costly credit requirements.
- Users find the **limited scope** of Cobalt's functionality inadequate, lacking depth in testing and real-world application coverage.
- Users find the **lack of detail** in instructions frustrating, as it complicates the setup process for tests.
- Users find Cobalt's **pricing model confusing** , suggesting revisions for clarity and integration costs.
- Users experience **inaccuracy in audits** with Cobalt, leading to confusion and inefficient resource allocation in security assessments.

#### What Are Recent G2 Reviews of Cobalt?

**["Simple, Fast, Flexible and Reliable Security Testing with Cobalt"](https://www.g2.com/survey_responses/cobalt-review-12516150)**

**Rating:** 5.0/5.0 stars

_— Shivendu T._

[Read full review](https://www.g2.com/survey_responses/cobalt-review-12516150)

**["Collaborative, Real-World Pentesting with Actionable Findings"](https://www.g2.com/survey_responses/cobalt-review-12683090)**

**Rating:** 5.0/5.0 stars

_— Arpit G._

[Read full review](https://www.g2.com/survey_responses/cobalt-review-12683090)

#### What Are G2 Users Discussing About Cobalt?

- [How do you use Cobalt?](https://www.g2.com/discussions/how-do-you-use-cobalt)
- [What is cobalt database?](https://www.g2.com/discussions/what-is-cobalt-database)
- [What is a cobalt developer?](https://www.g2.com/discussions/what-is-a-cobalt-developer)
- [Is cobalt an operating system?](https://www.g2.com/discussions/is-cobalt-an-operating-system)

### [Edgescan](https://www.g2.com/products/edgescan/reviews)

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

**Average Rating:** 4.6/5.0

**Total Reviews:** 58

#### How Do G2 Users Rate Edgescan?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **API / Integrations:** 8.0/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.7/10)
- **Test Automation:** 9.3/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Edgescan?

- **Seller:** [Edgescan](https://www.g2.com/sellers/edgescan)
- **Company Website:** www.edgescan.com
- **Year Founded:** 2017
- **HQ Location:** Dublin, Dublin
- **Twitter:** @edgescan  
2,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=51edeb949934c6f870f2d6720fefabf6632464f3895af4d8276b3c60c0fe37db&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2928425%2F&secure%5Burl_type%5D=linkedin_company_website)  
89 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 38% Large, 28% Medium

#### What Do G2 Reviewers Say About Edgescan?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate Edgescan's **ease of use** , enjoying its intuitive interface and streamlined navigation for effective vulnerability management.
- Users value the **automated vulnerability detection** with intuitive reports, timely alerts, and effective risk management features.
- Users value the **excellent customer support** from Edgescan, praising the team's responsiveness and proactive assistance.
- Users value the **thorough vulnerability identification** features of Edgescan, enhancing risk management and resolution efficiency.
- Users value the **robust features** of Edgescan, which streamline security assessments and enhance ease of use.

##### Cons

- Users find the **complex UI** challenging initially, with navigation issues and a need for improved dashboard functionality.
- Users highlight **limited customization** options in Edgescan, particularly regarding filtering and admin functionalities.
- Users find the **poor interface design** of Edgescan challenging, affecting usability and data accessibility.
- Users report experiencing **slow performance** as scans can take longer due to manual review processes.
- Users find the **UI not user friendly** , lacking intuitiveness and advanced features for better navigation and data accessibility.

#### What Are Recent G2 Reviews of Edgescan?

**["Efficient Vulnerability Scanning with Easy Navigation"](https://www.g2.com/survey_responses/edgescan-review-12218850)**

**Rating:** 5.0/5.0 stars

_— Simon L._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12218850)

**["Edgescan: Easy Setup, Clear Insights, and Expert Security Support"](https://www.g2.com/survey_responses/edgescan-review-12224347)**

**Rating:** 5.0/5.0 stars

_— Matt W._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12224347)

#### What Are G2 Users Discussing About Edgescan?

- [What is edgescan used for?](https://www.g2.com/discussions/what-is-edgescan-used-for) - 1 comment

### [BugDazz API Scanner](https://www.g2.com/products/bugdazz-api-scanner/reviews)

BugDazz API Security Scanner by SecureLayer7 is a comprehensive tool designed to automatically detect vulnerabilities, misconfigurations, and security gaps in API endpoints, aiding security teams in protecting digital assets against increasing API-related threats and potential exploits. It offers real-time scanning capabilities, enabling the automatic detection of vulnerabilities as they arise. It supports authentication and access control management, allowing for the management of API controls within a single platform. BugDazz assists in achieving compliance by accelerating the generation of reports for standards such as PCI DSS and HIPAA. It integrates seamlessly with existing CI/CD pipelines, facilitating the acceleration of product rollouts. The scanner goes beyond standard OWASP Top 10 vulnerabilities, providing comprehensive protection against critical API security risks.

**Average Rating:** 4.9/5.0

**Total Reviews:** 11

#### How Do G2 Users Rate BugDazz API Scanner?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **API / Integrations:** 10.0/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.3/10 (Category avg: 8.7/10)
- **Test Automation:** 10.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind BugDazz API Scanner?

- **Seller:** [SecureLayer7](https://www.g2.com/sellers/securelayer7)
- **Year Founded:** 2012
- **HQ Location:** Pune, Maharshtra
- **Twitter:** @SecureLayer7  
2,522 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8b8189801caf1b9cec58a9830e92f5c5cdcf4e45b42aed859cc538551531692d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsecurelayer7%2F&secure%5Burl_type%5D=linkedin_company_website)  
127 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 91% Small, 9% Medium

#### What Do G2 Reviewers Say About BugDazz API Scanner?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accuracy of results** from BugDazz, facilitating productive discussions and efficient workflows.
- Users appreciate the **smoother CI/CD integration** of BugDazz API Scanner, enhancing security scans without impacting build speed.
- Users appreciate the **seamless CI/CD integration** of BugDazz API Scanner, ensuring efficiency in security scans without delays.
- Users appreciate the **ease of use** of BugDazz API Scanner, seamlessly integrating into CI/CD pipelines and handling authentication effortlessly.
- Users value the **fast and accurate scanning technology** of BugDazz API Scanner, enhancing efficiency in CI/CD workflows.

##### Cons

- Users find the **poor documentation** of BugDazz API Scanner lacking in clarity and guidance, hindering effective use.
- Users note a **difficult learning curve** with BugDazz API Scanner, requiring time to optimize scanning for various scenarios.
- Users feel the **lack of guidance** in documentation hinders their ability to utilize the BugDazz API Scanner effectively.
- Users feel that the **lack of information** in documentation hinders effective use of BugDazz API Scanner.
- Users find the **learning curve** in tuning scans somewhat challenging, though it's manageable with time and experience.

#### What Are Recent G2 Reviews of BugDazz API Scanner?

**["Good tool for security teams"](https://www.g2.com/survey_responses/bugdazz-api-scanner-review-12300254)**

**Rating:** 4.5/5.0 stars

_— Khaja moinuddin F._

[Read full review](https://www.g2.com/survey_responses/bugdazz-api-scanner-review-12300254)

**["Effective scanner and fits well into our release workflow"](https://www.g2.com/survey_responses/bugdazz-api-scanner-review-12381013)**

**Rating:** 4.5/5.0 stars

_— Kabilesh kumar K._

[Read full review](https://www.g2.com/survey_responses/bugdazz-api-scanner-review-12381013)

### [Indusface WAS](https://www.g2.com/products/indusface-was/reviews)

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily monitoring for web applications, checking for systems and application vulnerabilities, and malware. Indusface WAS with its automated scans & manual pentesting done by certified security experts ensures none of the OWASP Top10, business logic vulnerabilities, and malware go unnoticed. With zero false-positive guarantee and comprehensive reporting with remediation guidance, Indusface web app scanning ensures developers to quickly fix vulnerabilities seamlessly.

**Average Rating:** 4.6/5.0

**Total Reviews:** 64

#### How Do G2 Users Rate Indusface WAS?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **API / Integrations:** 9.7/10 (Category avg: 8.6/10)
- **Detection Rate:** 9.4/10 (Category avg: 8.7/10)
- **Test Automation:** 9.4/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Indusface WAS?

- **Seller:** [Indusface](https://www.g2.com/sellers/indusface)
- **Year Founded:** 2012
- **HQ Location:** Vadodara
- **Twitter:** @Indusface  
3,472 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9613ad8a5510ef7df5fb28a0b29c05b6ca59b70efc760d78e0637371a3103092&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Findusface%2F&secure%5Burl_type%5D=linkedin_company_website)  
180 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 53% Small, 37% Medium

#### What Do G2 Reviewers Say About Indusface WAS?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **effective vulnerability detection** of Indusface WAS, ensuring rapid prioritization and reliable remediation support.
- Users value the **consistent and reliable vulnerability detection** of Indusface WAS, ensuring secure deployments with ease.
- Users commend the **excellent customer support** of Indusface WAS, ensuring timely responses and effective issue resolution.
- Users value the **scanning efficiency** of Indusface WAS for detailed vulnerability reports and timely updates after deployments.
- Users value the **thorough security scans** from Indusface WAS, enhancing their vulnerability identification and accreditation processes.

##### Cons

- Users feel that the pricing for Indusface WAS is **expensive** , especially regarding staging and development environment scans.
- Users find the **confusing interface** of Indusface WAS somewhat dated and in need of improvements for better usability.
- Users find the **lack of features** for staging and development environments limits their testing in Indusface WAS.
- Users find the **limited scope of pricing for staging environments** restricts functionality and increases testing challenges.
- Users find the **interface design outdated and unintuitive** , often wishing for a more user-friendly experience.

#### What Are Recent G2 Reviews of Indusface WAS?

**["Streamlined, Intuitive Portal with Great Support"](https://www.g2.com/survey_responses/indusface-was-review-13148466)**

**Rating:** 4.5/5.0 stars

_— Harshit G._

[Read full review](https://www.g2.com/survey_responses/indusface-was-review-13148466)

**["Great support Given by shivani"](https://www.g2.com/survey_responses/indusface-was-review-11074325)**

**Rating:** 5.0/5.0 stars

_— Sai N._

[Read full review](https://www.g2.com/survey_responses/indusface-was-review-11074325)

#### What Are G2 Users Discussing About Indusface WAS?

- [What is Indusface WAS used for?](https://www.g2.com/discussions/what-is-indusface-was-used-for)

### [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews)

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

**Average Rating:** 4.1/5.0

**Total Reviews:** 100

#### How Do G2 Users Rate Acunetix by Invicti?

- **Has the product been a good partner in doing business?:** 8.2/10 (Category avg: 9.2/10)
- **API / Integrations:** 7.9/10 (Category avg: 8.6/10)
- **Detection Rate:** 8.7/10 (Category avg: 8.7/10)
- **Test Automation:** 8.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Acunetix by Invicti?

- **Seller:** [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)
- **Company Website:** www.invicti.com
- **Year Founded:** 2018
- **HQ Location:** Austin, Texas
- **Twitter:** @InvictiSecurity  
2,557 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3c6c2278d6d9ef248056074aabb5416f9e0b5bf217ea8a7bfb87419d2894bc76&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Finvicti-security%2Fpeople%2F&secure%5Burl_type%5D=linkedin_company_website)  
335 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 40% Large, 34% Medium

#### What Do G2 Reviewers Say About Acunetix by Invicti?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accurate and fast vulnerability detection** of Acunetix, enhancing security with minimal false positives.
- Users value the **ease of use** of Acunetix, making vulnerability scanning and integration into workflows seamless.
- Users value Acunetix for its **robust security capabilities** , effectively enhancing web application safety with automatic vulnerability detection.
- Users commend the **accurate vulnerability identification** of Acunetix, enhancing web application security and ease of use.
- Users commend the **accuracy of results** from Acunetix, enhancing web application security with reliable vulnerability detection.

##### Cons

- Users find Acunetix to be **expensive** , especially challenging for smaller teams or projects with limited budgets.
- Users find the **complexity in setup and resource consumption** of Acunetix challenging, especially for large applications.
- Users find the **complex setup** of Acunetix challenging, especially for initial configurations and tool integrations.
- Users find the **slow scanning** process frustrating, especially during extensive audits of large web applications.
- Users find **difficult customization** to be a challenge, requiring technical expertise and patience for effective integration and setup.

#### What Are Recent G2 Reviews of Acunetix by Invicti?

**["Powerful Security Scanning Made Easy with Acunetix"](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11964967)**

**Rating:** 5.0/5.0 stars

_— Deepesh V._

[Read full review](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11964967)

**["Effortless Vulnerability Detection That Fits Seamlessly into DevSecOps"](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11909125)**

**Rating:** 5.0/5.0 stars

_— Ranit D._

[Read full review](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11909125)

#### What Are G2 Users Discussing About Acunetix by Invicti?

- [How has Acunetix supported your web security efforts, and what features do you rely on most?](https://www.g2.com/discussions/how-has-acunetix-supported-your-web-security-efforts-and-what-features-do-you-rely-on-most)
- [What is Acunetix by Invicti used for?](https://www.g2.com/discussions/what-is-acunetix-by-invicti-used-for)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/dynamic-application-security-testing-dast?order=g2_score&page=2#product-list)
- [3](/categories/dynamic-application-security-testing-dast?order=g2_score&page=3#product-list)
- [4](/categories/dynamic-application-security-testing-dast?order=g2_score&page=4#product-list)
- [5](/categories/dynamic-application-security-testing-dast?order=g2_score&page=5#product-list)
- [6](/categories/dynamic-application-security-testing-dast?order=g2_score&page=6#product-list)
- [7](/categories/dynamic-application-security-testing-dast?order=g2_score&page=7#product-list)
- [Next &rsaquo;Next ›](/categories/dynamic-application-security-testing-dast?order=g2_score&page=2#product-list)

Spotlight Categories

[Managed Detection and Response (MDR) Software](https://www.g2.com/categories/managed-detection-and-response-mdr)

[Lead Intelligence Software](https://www.g2.com/categories/lead-intelligence)

[Customer Service Automation Software](https://www.g2.com/categories/customer-service-automation)

[Virtual Data Room Software](https://www.g2.com/categories/virtual-data-room-vdr)

[Sales Tax and VAT Compliance Software](https://www.g2.com/categories/sales-tax-and-vat-compliance)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Dynamic Application Security Testing (DAST) Themes](/categories/dynamic-application-security-testing-dast/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated October 3, 2024

Dynamic application security testing (DAST) tools automate security tests for a variety of real-world threats. These tools typically test HTTP and HTML interfaces of web applications. DAST is a black-box testing method, meaning it is performed from the outside. Companies use these tools to identify vulnerabilities in their applications from an external perspective to better simulate threats most easily accessed by hackers outside their organization. There are similarities between DAST tools and other application security and vulnerability management solutions, but most other technologies perform internal tests and code analysis instead of focusing on black-box testing.

[SAST vs DAST](https://research.g2.com/blog/sast-vs-dast) — Learn the difference

To qualify for inclusion in the Dynamic Application Security Testing (DAST) category, a product must:

- Test applications in their operational state
- Perform external black-box security tests
- Trace penetrations and exploits to their sources

Top Tools at a Glance

| 

 | 

Low-noise DAST with unified AppSec scanning

 | 

User Review

"Enterprise Security Without an Enterprise Security Team"

 |
| 

 | 

Validated DAST with human-verified remediation workflows

 | 

User Review

"Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls"

 |
| 

 | 

Proxy-intercept DAST with manual exploit depth

 | 

User Review

"Complete Control Over Web Requests with Burp Suite"

 |
| 

 | 

AI-automated API security testing with self-healing

 | 

User Review

"Effortless AI Testing Automation That Accelerates Development"

 |
| 

 | 

Pipeline-embedded DAST with unified DevSecOps

 | 

User Review

"GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning"

 |
| 

 | 

Proof-based DAST with CI/CD integration

 | 

User Review

"Efficient Scanning, Superb Usability"

 |
| 

 | 

Credentialed network vulnerability scanning with remediation guidance

 | 

User Review

"Self-Contained Nessus Scanning with Full Control in Offline Environments"

 |
| 

 | 

Continuous external attack surface scanning with auto-remediation

 | 

User Review

"Reliable Service with Flexible Plans and Strong Support"

 |
| 

 | 

API-first DAST with CI/CD-native discovery

 | 

User Review

"Comprehensive Review of Pynt Tool"

 |

* * *

Show More

* * *

## How Do You Choose the Right Dynamic Application Security Testing (DAST) Software?

### What You Should Know About Dynamic Application Security Testing (DAST)﻿ Software

### What is Dynamic Application Security Testing (DAST) Software?

Dynamic application security testing (DAST) is one of the many technology groupings of security testing solutions. DAST is a form of black-box security testing, meaning it simulates realistic threats and attacks. This differs from other forms of testing such as static application security testing (SAST), a white-box testing methodology used to examine the source code of an application.

DAST includes a number of testing components that operate while an application is running. Security professionals simulate real-world functionality through testing the application for vulnerabilities and then evaluate the effects on application performance. The methodology is often used to find issues near the end of the software development lifecycle. These issues may be tougher to fix than early flaws and bugs are, but those flaws pose a larger threat to critical components of an application.

DAST can also be thought of as a methodology. It’s a different approach than traditional security testing because once a test is completed, there are still tests to be done. It involves periodic inspections as updates are pushed live or changes are made before release. While a penetration test or code scan might serve as a one-off test for specific vulnerabilities or bugs, dynamic testing can be performed continually throughout the lifecycle of an application.

Key Benefits of Dynamic Application Security Testing (DAST) Software

- Simulate realistic attacks and threats
- Discover vulnerabilities not found in source code
- Flexible and customizable testing options
- Comprehensive assessment and scalable testing

### Why Use Dynamic Application Security Testing (DAST) Software?

There are a number of testing solutions necessary for an all-encompassing approach to security testing and vulnerability discovery. Most start in the early stages of software development and help programmers discover bugs in the code and issues with the underlying framework or design. These tests require access to source code and are often used during development and quality assurance (QA) processes.

While early testing solutions approach testing from the standpoint of the developer, DAST approaches testing from the standpoint of a hacker. These tools simulate real threats to a functional, running application. Security professionals can simulate common attacks such as SQL injection and cross-site scripting or customize tests to threats specific to their product. These tools offer a highly customizable solution for testing during the later stages of development and while applications are deployed.

**Flexibility —** Users can schedule tests as they please or perform them continuously throughout an application’s or website’s lifecycle. Security professionals can modify environments to simulate their resources and infrastructure to ensure a realistic test and evaluation. They’re often scalable, as well, to see if increased traffic or usage would affect vulnerabilities and protection.

Industries with more specific threats may require more specific testing. Security professionals may identify a threat specific to the health care industry or financial sector and alter tests to simulate the threats most common to them. If performed correctly, these tools offer some of the most realistic and customizable solutions to the threats present in real-world situations.

**Comprehensiveness —** Threats are continuously evolving and expanding, making the ability to simulate multiple tests more necessary. DAST offers a versatile approach to testing, wherein security professionals can simulate and analyze each threat or attack type individually. These tests deliver comprehensive feedback and actionable insights that security and development teams use to remediate any issues, flaws, and vulnerabilities.

These tools will first perform an initial crawl, or examination, of applications and websites from a third-party perspective. They interact with applications using HTTP, allowing the tools to examine applications built with any programming language or on any framework. The tool will then test for misconfigurations, which expose a greater attack surface than internal vulnerabilities. Additional tests can be run, depending on the solution, but all the results and discoveries can be stored for actionable remediation.

**Continuous assessment —** Agile teams and other companies relying on frequent updates to applications should use DAST products with continuous assessment capabilities. SAST tools will provide more direct solutions for issues related to continuous integration processes, but DAST tools will provide a better view of how updates and changes will be seen from an outside perspective. Each new update may pose a new threat or unveil a new vulnerability; it is therefore crucial to continue testing even after applications have been completed and deployed.

Unlike SAST, DAST also requires less access to potentially sensitive source code within the application. DAST approaches the situation from an outside perspective as simulated threats attempt to gain access to vulnerable systems or sensitive information. This can make it easier to perform tests continuously without requiring individuals to access source code or other internal systems.

### What are the Common Features of Dynamic Application Security Testing (DAST) Software?

Standard functionality is included in most dynamic application security testing (DAST) solutions:

**Compliance testing —** Compliance testing gives users the ability to test for various requirements from regulatory bodies. This can help ensure information is stored securely and protected from hackers.

**Test automation —** Test automation is the feature powering continuous testing processes. This functionality operates by running prescripted tests as frequently as required without the need for hands-on or manual testing.

**Manual testing —** Manual testing gives the user complete control over individual tests. These features allow users to perform hands-on live simulations and penetration tests.

**Command-line tools —** The command-line interface (CLI) is the language interpreter of a computer. CLI capabilities will allow security testers to simulate threats directly from the terminal host system and input command sequences.

**Static code analysis —** Static code analysis and static security testing is used to test from the inside out. These tools help security professionals examine application source code for security flaws without executing it.

**Issue tracking —** Issue tracking helps security professionals and developers document flaws or vulnerabilities as they are discovered. Proper documentation will make it easier to organize the actionable insights provided by the DAST tool.

**Reporting and analytics —** Reporting capabilities are important to DAST tools because they provide the information necessary to remediate any recently discovered vulnerabilities. Reporting and analytics features can also give teams a better idea of how attacks may affect application availability and performance.

**Extensibility —** Many applications offer the ability to expand functionality through the use of integrations, APIs, and plugins. These extensible components provide the ability to extend the platform beyond its native feature set to include additional features and functionalities.

### Potential Issues with Dynamic Application Security Testing (DAST) Software

**Testing coverage —** While DAST technologies have come a long way, DAST tools alone are unable to discover the majority of vulnerabilities. This is why most experts suggest pairing them with SAST solutions. Combining the two can decrease the rate at which false positives occur. They can also be used to simplify the continuous testing process for agile teams. While no tool will detect every vulnerability, DAST may be less efficient than other testing tools if used alone.

**Late-stage issues —** DAST tools will require code to be compiled for each individual test because they rely on simulated functionality to test responses. This can be a roadblock for agile teams constantly integrating new code into an application. Reports are usually static and result from single tests. For agile teams, those reports can become outdated and lose value very quickly. This is just one more reason DAST tools should be used as a component of an all-encompassing security testing stack rather than a standalone solution.

**Testing capabilities —** Because DAST tools do not access an application's underlying source code, there are a number of flaws DAST tools will be unable to detect. For example, DAST tools are most effective at simulating reflection, or call-and-response, attacks where they can simulate an input and receive a response. They are not, however, highly effective in discovering smaller vulnerabilities or flaws in areas of the application that are rarely touched by users. These issues, as well as vulnerabilities in the original source code, will need to be addressed by additional security testing technologies.

### Software and Services Related to Dynamic Application Security Testing (DAST) Software

Most security software focuses on the vulnerabilities of networks and devices. Not all, but some, are used specifically for testing. But there are many different ways to tackle the topic, and using a combination of tools and testing methods is always more effective than relying on one tool alone. These are a few security tools used for various testing purposes.

[**Static application security testing (SAST) software**](https://www.g2.com/categories/static-application-security-testing-sast) **—** SAST tools are used to inspect the underlying source code of an application, making them the perfect complement to DAST tools. Using the tools in tandem is often referred to as interactive application security testing (IAST). This can help combine the black-box nature of DAST and the white-box nature of SAST to both find errors in source code as well as errors in functionality and third-party components of an application.

[**Vulnerability scanners**](https://www.g2.com/categories/vulnerability-scanner) **—** Some people use the term vulnerability scanner to describe DAST tools, but in reality DAST is just one component of most vulnerability scanners. DAST tools are application-specific, while vulnerability scanners typically provide a larger set of features for vulnerability management, risk assessment, and continuous testing.

[**Static code analysis software**](https://www.g2.com/categories/static-code-analysis) **—** Static code analysis tools are more similar to SAST than DAST, in that they’re used to evaluate an application’s source code. These tools are less directed towards security but may provide SAST capabilities. They’re typically used to scan code for a number of flaws that include bugs, security vulnerabilities, performance issues, and any other issue that may present itself if source code is not tested and optimized.