SAST-DAST-TOOLS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Comprehensive comparison of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools with CI/CD integration guidance.
SAST TOOLS (STATIC APPLICATION SECURITY TESTING)#
SAST analyzes source code or binaries without executing the application.
Best for: finding vulnerabilities early in development (shift-left).
SonarQube:
Type: SAST + Code Quality
Languages: 29+ (Java, Python, JS, C#, Go, PHP, C/C++, etc.)
License: Community (free), Developer, Enterprise, Data Center
Strengths: Code quality + security, CI/CD integration, large community
Weaknesses: Community edition limited rules, can be noisy
Quick start:
docker run -d --name sonarqube -p 9000:9000 sonarqube:community
CI Integration (GitHub Actions):
- name: SonarQube Scan
uses: sonarsource/sonarqube-scan-action@v2
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
Semgrep:
Type: SAST (pattern-based)
Languages: 30+ (Python, Java, JS/TS, Go, Ruby, PHP, C, etc.)
License: OSS (free CLI), Teams, Enterprise
Strengths: Fast, easy custom rules, low false positives, CI-friendly
Weaknesses: Pattern-based (not full dataflow in OSS)
Quick start:
pip install semgrep
semgrep --config auto . # auto-detect rules
semgrep --config p/owasp-top-ten . # OWASP rules
semgrep --config p/security-audit . # security audit
semgrep --config r/python.django . # Django-specific
Custom rule example:
rules:
- id: hardcoded-secret
patterns:
- pattern: $KEY = "..."
- metavariable-regex:
metavariable: $KEY
regex: (password|secret|api_key|token)
message: Possible hardcoded secret
severity: WARNING
languages: [python]
CodeQL (GitHub):
Type: SAST (semantic, query-based)
Languages: C/C++, C#, Go, Java, JavaScript/TypeScript, Python, Ruby, Swift
License: Free for open source (GitHub), Enterprise
Strengths: Deep dataflow analysis, custom queries, GitHub integration
Weaknesses: Slow on large codebases, learning curve for custom queries
GitHub Actions integration (automatic):
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: javascript, python
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
CLI usage:
codeql database create mydb --language=python --source-root=.
codeql database analyze mydb codeql/python-queries --format=sarif-latest
Checkmarx:
Type: SAST (enterprise)
Languages: 30+ languages
License: Commercial only
Strengths: Deep analysis, compliance reporting, IDE plugins
Weaknesses: Expensive, can be slow, higher false positive rate
Best for: Large enterprises with compliance requirements
Snyk Code:
Type: SAST (AI-powered)
Languages: Java, JS/TS, Python, C#, Go, PHP, Ruby, C/C++
License: Free tier (limited), Team, Enterprise
Strengths: Fast, AI-assisted, good IDE integration, low noise
Weaknesses: Limited customization in free tier
Quick start:
npm install -g snyk
snyk auth
snyk code test # SAST scan
snyk test # SCA scan (dependencies)
DAST TOOLS (DYNAMIC APPLICATION SECURITY TESTING)#
DAST tests running applications by sending crafted requests.
Best for: finding runtime vulnerabilities, misconfigurations, auth issues.
OWASP ZAP (Zaproxy):
Type: DAST (open source)
License: Free (Apache 2.0)
Strengths: Free, extensible, API support, active community
Weaknesses: Can be slow on large apps, noisy on default settings
Quick start:
# Docker baseline scan
docker run -t zaproxy/zap-stable zap-baseline.py -t https://target.com
# Full scan
docker run -t zaproxy/zap-stable zap-full-scan.py -t https://target.com
# API scan
docker run -t zaproxy/zap-stable zap-api-scan.py \
-t https://target.com/openapi.json -f openapi
CI/CD (GitHub Actions):
- name: ZAP Baseline Scan
uses: zaproxy/action-baseline@v0.12.0
with:
target: 'https://target.com'
API usage:
# Start ZAP daemon
zap.sh -daemon -port 8080
# Use REST API
curl "http://localhost:8080/JSON/ascan/action/scan/?url=https://target.com"
Burp Suite:
Type: DAST (manual + automated)
License: Community (free, limited), Professional, Enterprise
Strengths: Industry standard, extensive extensions, great for manual testing
Weaknesses: Pro/Enterprise is expensive, not ideal for CI/CD (Community)
Enterprise CI/CD:
# Burp Suite Enterprise REST API
curl -X POST "https://burp-enterprise/api/scans" \
-H "Authorization: Bearer <token>" \
-d '{"scan_configurations": [{"type": "NamedConfiguration", "name": "Audit checks - all except JavaScript analysis"}], "urls": ["https://target.com"]}'
Nuclei:
Type: DAST (template-based vulnerability scanner)
License: Free (MIT)
Strengths: Fast, huge template library, easy custom templates, CI-friendly
Weaknesses: Template-dependent (no fuzzing/crawling)
Quick start:
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
nuclei -u https://target.com # all templates
nuclei -u https://target.com -t cves/ # CVE templates only
nuclei -u https://target.com -t exposures/ # sensitive file exposure
nuclei -u https://target.com -severity critical,high
nuclei -l urls.txt -t technologies/ # tech detection
nuclei -u https://target.com -t http/misconfiguration/
Custom template example:
id: custom-api-check
info:
name: Custom API Key Exposure
severity: high
requests:
- method: GET
path:
- "{{BaseURL}}/api/config"
matchers:
- type: word
words:
- "api_key"
- "secret"
condition: or
Nikto:
Type: DAST (web server scanner)
License: Free (GPL)
Strengths: Fast, 7000+ checks, good for server misconfig
Weaknesses: Noisy, no authentication support, dated approach
Quick start:
nikto -h https://target.com
nikto -h https://target.com -Tuning x6 # specific test types
nikto -h https://target.com -output report.html -Format htm
SCA TOOLS (SOFTWARE COMPOSITION ANALYSIS)#
SCA identifies vulnerabilities in third-party dependencies.
Best for: finding known CVEs in open-source libraries.
Dependabot (GitHub):
Type: SCA + automated PRs
License: Free (GitHub-native)
Strengths: Automatic PRs for updates, GitHub-native, zero config
Weaknesses: GitHub only, limited to supported ecosystems
.github/dependabot.yml:
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
Snyk:
Type: SCA + SAST + Container
License: Free tier, Team, Enterprise
Strengths: Fix advice, PR checks, container scanning, IaC scanning
Weaknesses: Free tier limits, commercial for full features
Quick start:
snyk test # test dependencies
snyk monitor # continuous monitoring
snyk container test <image> # container scan
snyk iac test # IaC scan
Trivy:
Type: SCA + Container + IaC + SBOM
License: Free (Apache 2.0)
Strengths: All-in-one, fast, container-native, SBOM generation
Weaknesses: Less polish than commercial tools
Quick start:
# Install
brew install aquasecurity/trivy/trivy
# Scan filesystem (SCA)
trivy fs .
trivy fs --severity HIGH,CRITICAL .
# Scan container image
trivy image nginx:latest
trivy image --severity CRITICAL myapp:latest
# Scan IaC
trivy config ./terraform/
# Generate SBOM
trivy sbom --format cyclonedx .
# CI/CD (GitHub Actions)
- name: Trivy Scan
uses: aquasecurity/trivy-action@master
with:
scan-type: 'fs'
severity: 'CRITICAL,HIGH'
OWASP Dependency-Check:
Type: SCA
License: Free (Apache 2.0)
Strengths: Free, NIST NVD integration, multiple language support
Weaknesses: Slower than commercial tools, higher false positives
Quick start:
dependency-check --project myapp --scan ./src --format HTML
COMPARISON TABLE#
Tool | Type | Cost | CI/CD | Speed | FP Rate -------------------|----------|----------|-------|--------|-------- SonarQube CE | SAST | Free | Good | Medium | Medium Semgrep OSS | SAST | Free | Great | Fast | Low CodeQL | SAST | Free* | Great | Slow | Low Checkmarx | SAST | $$$ | Good | Slow | Medium Snyk Code | SAST | Freemium | Great | Fast | Low OWASP ZAP | DAST | Free | Good | Medium | Medium Burp Enterprise | DAST | $$$ | Good | Medium | Low Nuclei | DAST | Free | Great | Fast | Low Nikto | DAST | Free | Basic | Fast | High Dependabot | SCA | Free | Native| Fast | Low Snyk | SCA/SAST | Freemium | Great | Fast | Low Trivy | SCA/Cont | Free | Great | Fast | Low Dep-Check | SCA | Free | Good | Slow | Medium * CodeQL free for open-source repos on GitHub
WHEN TO USE EACH#
Development phase: IDE -> Snyk Code, SonarLint, Semgrep (IDE extensions) Pre-commit -> Semgrep, gitleaks (secrets), trufflehog PR/CI -> CodeQL, Semgrep, Snyk, Trivy, Dependabot Staging -> OWASP ZAP, Nuclei, Burp Production -> Nuclei (scheduled), bug bounty, monitoring Project type: Web app -> SAST + DAST + SCA API -> SAST + DAST (API scan) + SCA Mobile app -> SAST + MobSF + SCA Microservices -> SAST + Container scanning (Trivy) + SCA Infrastructure -> Trivy config, tfsec, checkov
CI/CD INTEGRATION PIPELINE#
Recommended pipeline stages:
1. Pre-commit hooks:
- gitleaks (prevent secret commits)
- semgrep (quick pattern checks)
2. Build stage:
- SAST scan (Semgrep or CodeQL)
- SCA scan (Snyk or Trivy)
- Container image scan (Trivy)
- IaC scan (Trivy config or tfsec)
3. Test stage:
- DAST scan (ZAP baseline or Nuclei)
- API security scan (ZAP API scan)
4. Gate criteria:
- No critical/high SAST findings
- No critical CVEs in dependencies
- DAST baseline passes
- Secrets scan clean
Example GitHub Actions workflow:
name: Security Pipeline
on: [push, pull_request]
jobs:
sast:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Semgrep
uses: returntocorp/semgrep-action@v1
with:
config: p/security-audit
sca:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Trivy FS Scan
uses: aquasecurity/trivy-action@master
with:
scan-type: 'fs'
severity: 'CRITICAL,HIGH'
exit-code: '1'
dast:
runs-on: ubuntu-latest
needs: [sast, sca]
steps:
- name: ZAP Baseline
uses: zaproxy/action-baseline@v0.12.0
with:
target: 'https://staging.example.com'
secrets:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Gitleaks
uses: gitleaks/gitleaks-action@v2
SECRET SCANNING TOOLS#
gitleaks: gitleaks detect --source=. --verbose gitleaks protect --staged # pre-commit hook trufflehog: trufflehog git file://. --only-verified trufflehog github --org=<org> detect-secrets: detect-secrets scan > .secrets.baseline detect-secrets audit .secrets.baseline
REFERENCES#
- OWASP Testing Guide: https://owasp.org/www-project-web-security-testing-guide/ - OWASP ZAP: https://www.zaproxy.org/ - Semgrep: https://semgrep.dev/ - Trivy: https://aquasecurity.github.io/trivy/ - Nuclei: https://nuclei.projectdiscovery.io/ - NIST SAST/DAST Guidelines: https://csrc.nist.gov/