Introduction to Dynamic Application Security Testing
In November 2023, Veracode rolled out a beta of its Automated Dynamic Application Security Testing (DAST) product known as DAST Essentials. The tool is heavily engineered with an eye toward highly effective integration with the integrated development environment (IDE). This means it represents a more efficient and streamlined way by which developers can find security vulnerabilities during the actual process of development.
Features and Capabilities of Veracode DAST Essentials
DAST Essentials makes security testing more accessible and proactive by scanning web applications in real-time as they are developed. With this tool, it is guaranteed that the IDEs integrate it, meaning security checks are performed on a continuous basis, and there is a lesser chance of overlooking vulnerabilities late in the development process. Other companies have developed similar DAST tools.
Besides DAST Essentials, Veracode also developed a Veracode GitHub application that enhances the automation and integration capabilities of the security testing suite. This application allows users to configure Veracode's DAST tool to automatically scan code as it is committed to a repository. It's particularly helpful to DevOps teams that use GitHub since it will ensure that the security testing gets integrated into their CI/CD pipeline. Through automatic security scans that are conducted with each update of code, developers can immediately identify and fix vulnerabilities before such code is merged into the main branch.
