data:image/s3,"s3://crabby-images/ed59a/ed59ab2d2cedd39b8c4b418a0e675f96be05ac67" alt="DAST vs SAST – Dynamic Application Security Testing vs Static"
In security testing, much like most things technical there are two very contrary methods, Dynamic Application Security Testing or DAST and Static Application Security Testing or SAST.
Dynamic testing relying on a black-box external approach, attacking the application in it’s running state as a regular malicious attacker would.
Static testing is more white-box looking at the source-code of the application for potential flaws.
Personally, I don’t see them as ‘vs’ each other, but more like they compliment each other – it’s easy to have SAST tests as part of your CI/CD pipeline with tools like Code Climate.