01Introduction
Code can look safe and still be exploitable once it is deployed behind a real load balancer, with real sessions and real data. DAST tests the application an attacker actually sees.
02What is DAST?
Dynamic application security testing (DAST) is black-box testing of a running web application or API. It sends crafted requests and inspects responses for signs of vulnerabilities such as injection, cross-site scripting, broken authentication and misconfigured headers.
DAST complements SAST, which reads code without running it, and overlaps with penetration testing, which adds human-style reasoning about how to chain what it finds.
03How DAST works
A DAST run moves from discovery to attack.
- 1.
Discover
Crawl the app and import OpenAPI or GraphQL schemas to map endpoints, parameters and forms.
- 2.
Authenticate
Log in with test accounts so protected routes are in scope, ideally with more than one role.
- 3.
Attack
Send payloads for each vulnerability class and watch for errors, reflections, timing differences and unexpected data.
- 4.
Confirm
Re-run the request that triggered the finding to rule out noise, then report it with the evidence.
04Threats and risks
Traditional DAST struggles with how modern apps are built.
Shallow crawling
Single-page apps and multi-step flows hide most of the attack surface from a link crawler.
Lost sessions
Scanners log themselves out, hit MFA or break CSRF tokens and quietly test nothing.
Logic flaws
A payload list cannot notice that user A can read user B's invoice. See broken access control.
API gaps
Undocumented endpoints never get tested. See API security.
05How Parameter helps
Parameter AI Pentesting is DAST done the way an attacker would do it.
Agents, not crawlers
Hundreds of agents map endpoints, parameters and auth flows from your code, your OpenAPI specs or just the live app.
Multi-role testing
Agents hold several accounts at once to test authorization between users and tenants. See web application pentesting.
Only proven findings
Every issue is reproduced before it is reported, with impact, repro steps and a fix.

