openskills.info
Course Preview

Dynamic Application Security Testing

Dynamic Application Security Testing, or DAST, checks a running application for security weaknesses by interacting with it the way an attacker would, without looking at its source code. A DAST tool sends unexpected or malicious input to a live app and watches how it responds, which catches problems like injection flaws or broken login checks that only show up once the software is actually running.

itOffensive security and application security

Don't Panic - Dynamic Application Security Testing

Dynamic Application Security Testing (DAST) finds weaknesses by interacting with an application while it runs. A DAST tool talks through the front end the way a browser or API client would. It crawls, observes normal responses, then probes inputs and compares behavior to vulnerable patterns. It does not read your source. It only knows what the running interfaces expose and how they respond to unusual input.

Place DAST beside SAST and software composition analysis rather than ranking them. SAST inspects code without execution. DAST inspects reachable runtime behavior. Composition analysis watches third-party libraries. Each covers a different slice. Judge a DAST engagement by attack surface reached, especially behind authentication, not by how many requests were sent.

The scan lifecycle usually moves through discovery and crawling, passive inspection of observed traffic, active probing with attack payloads, then human verification and triage. Active scanning is a real attack against a real system. Run it only with authorization, preferably on staging that mirrors production. Authentication configuration is the hard part: without a stable logged-in session, the scanner never sees the workflows that matter.

Treat alerts as hypotheses until replayed and confirmed. Tune scope, policy, and auth before you compare tools on alert count alone.

Read the Intro for the black-box model and scan phases. Use the Cheatsheet when you need the coverage and auth checklist. Landscape places DAST among related application-security testing practices; Updates tracks OWASP ZAP releases, the reference tool this course uses for the crawl and scan workflow.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources

  • https://devguide.owasp.org/en/06-verification/02-tools/01-dast/
  • https://owasp.org/www-project-security-culture/v11/7-Security_Testing/
  • https://owasp.org/www-project-devsecops-guideline/latest/02b-Dynamic-Application-Security-Testing
  • https://owasp.org/www-project-web-security-testing-guide/
  • https://owasp.org/www-project-web-security-testing-guide/stable/
  • https://www.zaproxy.org/
  • https://www.zaproxy.org/getting-started/
  • https://www.zaproxy.org/docs/desktop/start/features/authentication/
  • https://portswigger.net/web-security
  • https://portswigger.net/burp/
  • https://github.com/enaqx/awesome-pentest
  • https://cirt.net/nikto/
  • https://projectdiscovery.io/nuclei
  • https://sqlmap.org/
  • https://wpscan.com/
  • https://wapiti-scanner.github.io/
  • https://github.com/fuzzdb-project/fuzzdb