Runtime Security
Dynamic Application Security Testing (DAST). Language-agnostic runtime vulnerability detection by simulating real-world attacks.
Capabilities
Web application crawling
API testing (REST, GraphQL, gRPC)
Authenticated scanning
Injection testing (SQL, XSS, Command)
Authentication bypass detection
Security misconfiguration detection
SAST+DAST correlation
DAST is coming in Phase 3
The DAST engine will provide black-box testing capabilities with full OWASP coverage, CI/CD integration, and combined SAST+DAST API inventory.