Parameter

What is DAST?

Dynamic application security testing

What DAST is, how it tests running applications and APIs from the outside, and why agent-driven testing finds what crawlers miss.

01Introduction

Code can look safe and still be exploitable once it is deployed behind a real load balancer, with real sessions and real data. DAST tests the application an attacker actually sees.

02What is DAST?

Dynamic application security testing (DAST) is black-box testing of a running web application or API. It sends crafted requests and inspects responses for signs of vulnerabilities such as injection, cross-site scripting, broken authentication and misconfigured headers.

DAST complements SAST, which reads code without running it, and overlaps with penetration testing, which adds human-style reasoning about how to chain what it finds.

03How DAST works

A DAST run moves from discovery to attack.

  1. 1.

    Discover

    Crawl the app and import OpenAPI or GraphQL schemas to map endpoints, parameters and forms.

  2. 2.

    Authenticate

    Log in with test accounts so protected routes are in scope, ideally with more than one role.

  3. 3.

    Attack

    Send payloads for each vulnerability class and watch for errors, reflections, timing differences and unexpected data.

  4. 4.

    Confirm

    Re-run the request that triggered the finding to rule out noise, then report it with the evidence.

04Threats and risks

Traditional DAST struggles with how modern apps are built.

  • Shallow crawling

    Single-page apps and multi-step flows hide most of the attack surface from a link crawler.

  • Lost sessions

    Scanners log themselves out, hit MFA or break CSRF tokens and quietly test nothing.

  • Logic flaws

    A payload list cannot notice that user A can read user B's invoice. See broken access control.

  • API gaps

    Undocumented endpoints never get tested. See API security.

05How Parameter helps

Parameter AI Pentesting is DAST done the way an attacker would do it.

  • Agents, not crawlers

    Hundreds of agents map endpoints, parameters and auth flows from your code, your OpenAPI specs or just the live app.

  • Multi-role testing

    Agents hold several accounts at once to test authorization between users and tenants. See web application pentesting.

  • Only proven findings

    Every issue is reproduced before it is reported, with impact, repro steps and a fix.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your DAST program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.