Skill · 03
← All skills
Security

DAST

Dynamic testing that probes running apps like an attacker.

At a glance
25%
Faster remediation turnaround
Runtime
Risks caught pre-release
Capabilities
5
Tools & platforms
5
Discipline
Security
Overview

Validate running applications and APIs from the outside in — combining automated dynamic scanning in CI with manual penetration testing to surface vulnerabilities that only appear at runtime.

Capabilities
5 areas
  • Automated DAST scanning integrated into CI/CD
  • Manual web and API penetration testing
  • Authentication, session and access-control testing
  • Business-logic and chained-vulnerability validation
  • Remediation guidance and re-test verification
Software & Tools

The stack behind the work.

The tools I reach for day to day — with a rough sense of where my depth sits.

Expert
Advanced
Proficient

Burp Suite

Expert

Manual web app pentesting & interception

OWASP ZAP

Advanced

Automated DAST scanning in CI

Nuclei

Proficient

Template-based vulnerability scanning

Postman

Advanced

API security & abuse-case testing

SQLMap

Proficient

Injection discovery & validation

Let's work together

Have a project that needs DAST?