Dynamic Application Security Testing (DAST) Software Resources
Articles, Discussions, and Reports to expand your knowledge on Dynamic Application Security Testing (DAST) Software
Resource pages are designed to give you a cross-section of information we have on specific categories. You'll find articles from our experts, discussions from users like you, and reports from industry data.
Dynamic Application Security Testing (DAST) Software Articles
Vulnerability Scanners: Types, Benefits, And Top 5 Scanners
G2 Launches Interactive Application Security Testing (IAST) Software Category
What Is DevSecOps, and How Is It Different from DevOps?
SAST vs. DAST: Application Security Testing Explained
Dynamic Application Security Testing (DAST) Software Discussions
Is GitLab paid?
A good source of community curated CI/CD templates will be a good source of implementing all best practices.
Hey everyone,
I’ve been helping a few DevSecOps teams evaluate DAST (Dynamic Application Security Testing) tools designed for cloud-native applications — microservices, APIs, containers, serverless. I looked through G2’s DAST category and review data, plus vendor features, to identify which platforms perform strongly in modern cloud/native stacks.
Here’s what stood out (based on G2 Grid order):
- Tenable Nessus: the category leader; great for vulnerability scanning across cloud workloads, containers, and dynamic app environments.
- Jit: built for DevSecOps workflows; integrates directly into CI/CD pipelines for automated runtime and API testing in cloud-native stacks.
- Aikido Security: strong for modern app architectures; automates scanning across cloud deployments with simple setup and actionable reporting.
- Akto: API-first DAST designed for microservices and distributed systems; ideal for testing cloud-based REST and GraphQL endpoints.
- Astra Pentest: combines automated DAST with manual testing for hybrid and multi-cloud environments; solid for ongoing app security validation.
I based this on G2 satisfaction and feature-level data, plus user reviews focused on cloud-native coverage, automation depth, and integration flexibility. Anyone here using these tools? Can you share your experience?
Which DAST tools have actually handled your cloud-native workloads well — especially for scanning APIs, containers, or microservices without breaking the pipeline?




