Is
#DAST Dead?
Or if not dead then dying, as per this tweet from my
@OWASP colleague (and friend) Jim Manico:
x.com/manicode/status/166148…
The reality, as Jim should know, is much more complex and subtle...
A 🧵
Without installing agents, reading log files, or monitoring network activity, DAST is horribly bad at microservice security review. DAST is useless at showing me intra-service activity which is why I suggest most API shops drop DAST completely and focus on other assessment tech.