Dynamic Application Security Testing
Security testing that probes a running application from the outside to identify exploitable behavior without relying solely on source inspection.
Security Context
Dynamic application security testing probes a running application and can expose failures that depend on runtime state, authentication flows, input handling, or deployment configuration. Its effective coverage is limited to the paths and interfaces that the crawler, test account, and attack model can reach.
Analysis Boundary
DAST does not provide source-level path coverage and cannot replace static analysis. Conversely, static findings alone cannot reproduce every runtime configuration or externally observable behavior.