DAST
Abbreviation · Security & Infosec
Definitions
Dynamic Application Security Testing — testing a running application by sending crafted requests to discover vulnerabilities from the outside (black-box testing). Finds issues that SAST misses: misconfigured headers, CORS issues, authentication bypasses, and runtime injection vulnerabilities. Tools include OWASP ZAP, Burp Suite, and Nuclei.
In plain English: Testing a running application for security holes by attacking it from the outside, like a real hacker would.
Example: "The DAST scan found missing security headers and an open redirect — issues that wouldn't show up in static code analysis."
Related Terms
- Authentication
- OTP
- CORS Preflight
- Secret Scanning
- SAST
- Shift Left
- Supply Chain Security
- Threat Modeling
- Anti-Forensics
- Anti-Malware
- Authentication Bypass
- Bluetooth Sniffing
- Bug Bounty Program
- Burp Suite
- Business Email Compromise
- Credential Harvesting
- Credential Replay
- Dynamic Application Security Testing
- Email Bombing
- Ethical Hacking
- Fault Injection
- Fuzz Testing
- ICMP Tunneling
- IDS Evasion
- Log Forging
- Log Tampering
- Multi-Factor Authentication Bypass
- OAuth Token Theft
- Offensive Security
- Adversary Simulation
- Attack Emulation
- Black Box Fuzzing
- Cloud Penetration Testing
- Dynamic Analysis
- Fuzzer