DAST Scan: Running Application Vulnerability Scanner - Checkmarx

New IDC report: How Security Can Catch Up With AI-generated Code 

Get the Report

Checkmarx One

Dynamic Application Security Testing (DAST)

Enterprise DAST with effortless setup, smart runtime coverage, comprehensive API protection, and actionable insights on the Checkmarx One platform.

image_Hero_DAST

What Makes Checkmarx DAST Different?

Effortless authentication, comprehensive API security, AI-ready runtime protection, and unified platform experience make enterprise DAST simple, powerful, and always ready to run.

Risk-based Prioritization

ASPM Integration

Advanced ASPM integration consolidates security data into unified risk scores, enabling teams to prioritize vulnerabilities effectively across the entire application lifecycle. 

Faster and Simpler Onboarding

Onboarding Wizard

See immediate value with a streamlined setup process that automates configuration and YAML generation, enabling  new users to hit the ground running. 

Authentication Made Simple

Authentication

Facilitate any authentication flow to ensure your apps are tested: browser recording captures complex logins, 2FA support included, immediate verification, plus detailed reporting for complete visibility. 

Seamless Integration With the SDLC

CD integration

Integrate directly into the CI/CD pipeline, automating testing across development and pre-production, to surface vulnerabilities instantly, before they reach production. 

Enhance Compliance

Compliance

Map vulnerabilities directly to compliance requirements. Know which applications introduce compliance risk. 

Complete API Security

API Scanning

Test endpoints and APIs in live environments including REST, SOAP, and gRPC APIs, while centralizing all SAST and DAST API discoveries in one unified inventory. 

  • Risk-based Prioritization

    Advanced ASPM integration consolidates security data into unified risk scores, enabling teams to prioritize vulnerabilities effectively across the entire application lifecycle. 

  • Faster and Simpler Onboarding

    See immediate value with a streamlined setup process that automates configuration and YAML generation, enabling  new users to hit the ground running. 

  • Authentication Made Simple

    Facilitate any authentication flow to ensure your apps are tested: browser recording captures complex logins, 2FA support included, immediate verification, plus detailed reporting for complete visibility. 

  • Seamless Integration With the SDLC

    Integrate directly into the CI/CD pipeline, automating testing across development and pre-production, to surface vulnerabilities instantly, before they reach production. 

  • Enhance Compliance

    Map vulnerabilities directly to compliance requirements. Know which applications introduce compliance risk. 

  • Complete API Security

    Test endpoints and APIs in live environments including REST, SOAP, and gRPC APIs, while centralizing all SAST and DAST API discoveries in one unified inventory. 

ASPM Integration
Onboarding Wizard
Authentication
CD integration
Compliance
API Scanning
Mid Page CTA Background

The AppSec Platform That Protects From Code
to Runtime

See how DAST on Checkmarx One will help secure
your live applications and APIs.

Ready to Start?

Enterprise-Grade DAST That Delivers

The enterprise-proven platform developers actually want to use: lightning-fast authentication, instant onboarding, smart remediation with policy correlation, plus governance that scales.

Save Time

Fast AppSec

See results fast: with quick and simple onboarding, authenticate automatically, and see everything you need in one unified view with Checkmarx One.

Manage Dashboard

True Platform Integration

Experience true unified security with native DAST integration in Checkmarx One that eliminates tool fragmentation. Unified dashboards, seamless workflows, and complete visibility in one place

Security without Compromise  

Enterprise Authentication Made Simple

Handle any authentication flow including 2FA, SSO, and complex multi-step logins. Browser recording, script uploads, and instant verification eliminate authentication barriers completely.

Meet Developers AI

Secure AI-Generated Code at Runtime

Protect against rising vulnerability rates introduced by AI-generated code and vibe coding. Test undocumented APIs, business logic flaws, and unexpected behaviors that traditional tools miss.

Simplified Vulnerability Management 

Enhanced Remediation Through Policy Correlation

Intelligent policy correlation streamlines vulnerability prioritization and remediation workflows, helping security and development teams focus on the most critical threats first.

API

Comprehensive API Security

Test APIs of live applications to discover what other tools miss. Discover shadow APIs and see everything—SAST and DAST findings—in one centralized inventory.

What Our Customers Say About Us

Learn why a growing list of enterprises rely on our approach to application security

“We view Checkmarx as our trusted partner. They’ve elevated our security posture by consolidating our SAST, SCA, and API Security into a unified platform, Checkmarx One, enabling us to achieve vulnerability remediation, reduce noise, and benefit from strong support.”

“Incorporating Checkmarx’s technology has revolutionized our development culture. It’s more than just technology; it serves as the foundation of our security strategy, ensuring that our applications are secure by design.”

“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”

“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by Checkmarx managed services. Our mission revolves around providing secure and compliant lottery and gaming applications and services to our clients around the globe, and with Checkmarx SAST, SCA and associated components enhanced by their stellar service support, we deliver on this promise with confidence and certainty.”

“After nearly nine years of using Checkmarx’s SAST, CGI’s journey has been one of seamless integration and consistent satisfaction. The last three years have been particularly smooth, reflecting the solution’s reliability and our successful partnership.”

“After reviewing the Checkmarx platform, I’m not sure how Veracode is able to exist while being at a similar price point.”

“Checkmarx’s execution is impressive; it’s brought all the products under one cloud platform.”

“By Far The Best AppSec Tooling Decision We Have Made!!”

“We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and medium-risk issues.”

“Checkmarx made security team and developers life easier.”

FAQ

What other solutions does Checkmarx have in addition to DAST?

Checkmarx DAST is part of the Checkmarx One application security platform. This allows a complete AppSec program to be run on a single platform, reducing total cost of ownership and allowing for correlation and better actionable insights. 

The Checkmarx One platform includes: 

  • SAST 
  • DAST 
  • SCA 
  • SCS 
  • API Security 
  • IaC Security 
  • Container Security 

 

Why should I have a DAST tool on a unified platform?

By maintaining a unified cloud-native AppSec platform such as Checkmarx One, organizations can consolidate their AppSec tooling. Besides lowering TCO, it also reduces learning curves among the team and allows for a unified view of your entire application security posture. This makes it easier to analyze and prioritize vulnerabilities across multiple solutions, such as SAST, DAST, and API Security 

What is the cost? How can I learn more about pricing?

Every organization has unique needs and sizes. For a price quote, please be in touch. DAST is an add-on to Checkmarx One.  

If you are a current Checkmarx customer, please reach out to your account manager or contact us here 

Where can I explore DAST documentation?

You can explore all Checkmarx’ documentation here.

Checkmarx One

Enterprise Application Security Platform

Everything enterprises need to secure application development from code to cloud on a unified platform.

Explore Checkmarx One Packaging & Pricing

Application Security Posture
Management (ASPM) Consolidated, correlated, prioritized insights to help your team manage risk

Code

AI Powered
  • SAST

    Conduct fast and accurate scans to identify risk in your custom code.

  • DAST

    Identify vulnerabilities only seen in production and assess their behavior.

  • API Security

    Eliminate shadow and zombie APls and mitigate API-specific risks.

Supply Chain

AI Powered
  • SCA

    Easily identify, prioritize, remediate, and manage open source security and license risks.

  • Malicious Package Protection

    Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.

  • AI Security

    Built to accelerate AppSec teams and help developers secure applications from the first line of code.

  • Secrets Detection

    Minimize risk by quickly identifying and eliminating exposed secrets.

  • Repository Health

    Reduce security risks by health-scoring the code repositories used in your applications.

Cloud

AI Powered
  • Container Security

    Scan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.

  • IaC Security

    Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.

Dev Enablement

  • Codebashing

    Secure code training to upskill your developers and reduce risk from the first line of code.

DevSecOps

  • 75+ Languages

  • 100+ Frameworks

  • 75+ Technologies

  • SDLC Integrations

Services

  • Premium Support

    Maximize ROI with prioritized technical support, metrics monitoring, and operational assistance.

  • Premium Services

    Augment your security team with Checkmarx services to ensure the success of your AppSec program.

  • Maturity Assessment

    Assess the current state of your AppSec program, benchmark against peers, and get actionable next steps for improvement.

Dev Enablement

  • Codebashing

    Codebashing

    Secure code training to upskill your developers and reduce risk from the first line of code.

DevSecOps

  • 75+ Languages

    75+ Languages

  • 100+ Frameworks

    100+ Frameworks

  • 75+ Technologies

    75+ Technologies

  • SDLC Integrations

    SDLC Integrations

Unified Dashboard, Reporting & Risk Management

Application Security Posture
Management (ASPM)

Consolidated, correlated, prioritized insights to help your team manage risk

AI Powered

Code

  • SAST

    Static Application Security Testing (SAST)

    Conduct fast and accurate scans to identify risk in your custom code.

  • DAST

    Dynamic Application Security Testing (DAST)

    Identify vulnerabilities only seen in production and assess their behavior.

  • API Security

    API Security

    Eliminate shadow and zombie APls and mitigate API-specific risks.

Supply Chain

  • SCA

    Software Composition Analysis (SCA)

    Easily identify, prioritize, remediate, and manage open source security and license risks.

  • Malicious Package Protection

    Malicious Package Protection

    Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.

  • AI Security

    AI Security

    Built to accelerate AppSec teams and help developers secure applications from the first line of code.

  • Secrets Detection

    Secrets Detection

    Minimize risk by quickly identifying and eliminating exposed secrets.

  • Repository Health

    Repository Health

    Reduce security risks by health-scoring the code repositories used in your applications.

Cloud

  • Container Security

    Container Security

    Scan container images, configurations, and identify open source packages and vulnerabilities preproduction and runtime.

  • IaC Security

    IaC Security

    Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.

Services

  • Premium Support

    Premium Support

    Maximize ROI with prioritized technical support, metrics monitoring, and operational assistance.

  • Premium Services

    Premium Services

    Augment your security team with Checkmarx services to ensure the success of your AppSec program.

  • Maturity Assessment

    Maturity Assessment

    Assess the current state of your AppSec program, benchmark against peers, and get actionable next steps for improvement.

Get a Demo

Want to See DAST in Action?

Find out how Checkmarx’ DAST helps organizations find vulnerabilities in live applications.

Securing the applications driving our world