← All cheat sheets

SAST-DAST-TOOLS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Comprehensive comparison of Static Application Security Testing (SAST),
Dynamic Application Security Testing (DAST), and Software Composition
Analysis (SCA) tools with CI/CD integration guidance.

SAST TOOLS (STATIC APPLICATION SECURITY TESTING)#

SAST analyzes source code or binaries without executing the application.
Best for: finding vulnerabilities early in development (shift-left).

SonarQube:
  Type:       SAST + Code Quality
  Languages:  29+ (Java, Python, JS, C#, Go, PHP, C/C++, etc.)
  License:    Community (free), Developer, Enterprise, Data Center
  Strengths:  Code quality + security, CI/CD integration, large community
  Weaknesses: Community edition limited rules, can be noisy

  Quick start:
    docker run -d --name sonarqube -p 9000:9000 sonarqube:community

  CI Integration (GitHub Actions):
    - name: SonarQube Scan
      uses: sonarsource/sonarqube-scan-action@v2
      env:
        SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
        SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}

Semgrep:
  Type:       SAST (pattern-based)
  Languages:  30+ (Python, Java, JS/TS, Go, Ruby, PHP, C, etc.)
  License:    OSS (free CLI), Teams, Enterprise
  Strengths:  Fast, easy custom rules, low false positives, CI-friendly
  Weaknesses: Pattern-based (not full dataflow in OSS)

  Quick start:
    pip install semgrep
    semgrep --config auto .                    # auto-detect rules
    semgrep --config p/owasp-top-ten .         # OWASP rules
    semgrep --config p/security-audit .        # security audit
    semgrep --config r/python.django .         # Django-specific

  Custom rule example:
    rules:
      - id: hardcoded-secret
        patterns:
          - pattern: $KEY = "..."
          - metavariable-regex:
              metavariable: $KEY
              regex: (password|secret|api_key|token)
        message: Possible hardcoded secret
        severity: WARNING
        languages: [python]

CodeQL (GitHub):
  Type:       SAST (semantic, query-based)
  Languages:  C/C++, C#, Go, Java, JavaScript/TypeScript, Python, Ruby, Swift
  License:    Free for open source (GitHub), Enterprise
  Strengths:  Deep dataflow analysis, custom queries, GitHub integration
  Weaknesses: Slow on large codebases, learning curve for custom queries

  GitHub Actions integration (automatic):
    - name: Initialize CodeQL
      uses: github/codeql-action/init@v3
      with:
        languages: javascript, python
    - name: Perform CodeQL Analysis
      uses: github/codeql-action/analyze@v3

  CLI usage:
    codeql database create mydb --language=python --source-root=.
    codeql database analyze mydb codeql/python-queries --format=sarif-latest

Checkmarx:
  Type:       SAST (enterprise)
  Languages:  30+ languages
  License:    Commercial only
  Strengths:  Deep analysis, compliance reporting, IDE plugins
  Weaknesses: Expensive, can be slow, higher false positive rate
  Best for:   Large enterprises with compliance requirements

Snyk Code:
  Type:       SAST (AI-powered)
  Languages:  Java, JS/TS, Python, C#, Go, PHP, Ruby, C/C++
  License:    Free tier (limited), Team, Enterprise
  Strengths:  Fast, AI-assisted, good IDE integration, low noise
  Weaknesses: Limited customization in free tier

  Quick start:
    npm install -g snyk
    snyk auth
    snyk code test                           # SAST scan
    snyk test                                # SCA scan (dependencies)

DAST TOOLS (DYNAMIC APPLICATION SECURITY TESTING)#

DAST tests running applications by sending crafted requests.
Best for: finding runtime vulnerabilities, misconfigurations, auth issues.

OWASP ZAP (Zaproxy):
  Type:       DAST (open source)
  License:    Free (Apache 2.0)
  Strengths:  Free, extensible, API support, active community
  Weaknesses: Can be slow on large apps, noisy on default settings

  Quick start:
    # Docker baseline scan
    docker run -t zaproxy/zap-stable zap-baseline.py -t https://target.com

    # Full scan
    docker run -t zaproxy/zap-stable zap-full-scan.py -t https://target.com

    # API scan
    docker run -t zaproxy/zap-stable zap-api-scan.py \
      -t https://target.com/openapi.json -f openapi

  CI/CD (GitHub Actions):
    - name: ZAP Baseline Scan
      uses: zaproxy/action-baseline@v0.12.0
      with:
        target: 'https://target.com'

  API usage:
    # Start ZAP daemon
    zap.sh -daemon -port 8080
    # Use REST API
    curl "http://localhost:8080/JSON/ascan/action/scan/?url=https://target.com"

Burp Suite:
  Type:       DAST (manual + automated)
  License:    Community (free, limited), Professional, Enterprise
  Strengths:  Industry standard, extensive extensions, great for manual testing
  Weaknesses: Pro/Enterprise is expensive, not ideal for CI/CD (Community)

  Enterprise CI/CD:
    # Burp Suite Enterprise REST API
    curl -X POST "https://burp-enterprise/api/scans" \
      -H "Authorization: Bearer <token>" \
      -d '{"scan_configurations": [{"type": "NamedConfiguration", "name": "Audit checks - all except JavaScript analysis"}], "urls": ["https://target.com"]}'

Nuclei:
  Type:       DAST (template-based vulnerability scanner)
  License:    Free (MIT)
  Strengths:  Fast, huge template library, easy custom templates, CI-friendly
  Weaknesses: Template-dependent (no fuzzing/crawling)

  Quick start:
    go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
    nuclei -u https://target.com                    # all templates
    nuclei -u https://target.com -t cves/           # CVE templates only
    nuclei -u https://target.com -t exposures/      # sensitive file exposure
    nuclei -u https://target.com -severity critical,high
    nuclei -l urls.txt -t technologies/             # tech detection
    nuclei -u https://target.com -t http/misconfiguration/

  Custom template example:
    id: custom-api-check
    info:
      name: Custom API Key Exposure
      severity: high
    requests:
      - method: GET
        path:
          - "{{BaseURL}}/api/config"
        matchers:
          - type: word
            words:
              - "api_key"
              - "secret"
            condition: or

Nikto:
  Type:       DAST (web server scanner)
  License:    Free (GPL)
  Strengths:  Fast, 7000+ checks, good for server misconfig
  Weaknesses: Noisy, no authentication support, dated approach

  Quick start:
    nikto -h https://target.com
    nikto -h https://target.com -Tuning x6          # specific test types
    nikto -h https://target.com -output report.html -Format htm

SCA TOOLS (SOFTWARE COMPOSITION ANALYSIS)#

SCA identifies vulnerabilities in third-party dependencies.
Best for: finding known CVEs in open-source libraries.

Dependabot (GitHub):
  Type:       SCA + automated PRs
  License:    Free (GitHub-native)
  Strengths:  Automatic PRs for updates, GitHub-native, zero config
  Weaknesses: GitHub only, limited to supported ecosystems

  .github/dependabot.yml:
    version: 2
    updates:
      - package-ecosystem: "npm"
        directory: "/"
        schedule:
          interval: "weekly"
      - package-ecosystem: "pip"
        directory: "/"
        schedule:
          interval: "weekly"

Snyk:
  Type:       SCA + SAST + Container
  License:    Free tier, Team, Enterprise
  Strengths:  Fix advice, PR checks, container scanning, IaC scanning
  Weaknesses: Free tier limits, commercial for full features

  Quick start:
    snyk test                               # test dependencies
    snyk monitor                            # continuous monitoring
    snyk container test <image>             # container scan
    snyk iac test                           # IaC scan

Trivy:
  Type:       SCA + Container + IaC + SBOM
  License:    Free (Apache 2.0)
  Strengths:  All-in-one, fast, container-native, SBOM generation
  Weaknesses: Less polish than commercial tools

  Quick start:
    # Install
    brew install aquasecurity/trivy/trivy

    # Scan filesystem (SCA)
    trivy fs .
    trivy fs --severity HIGH,CRITICAL .

    # Scan container image
    trivy image nginx:latest
    trivy image --severity CRITICAL myapp:latest

    # Scan IaC
    trivy config ./terraform/

    # Generate SBOM
    trivy sbom --format cyclonedx .

    # CI/CD (GitHub Actions)
    - name: Trivy Scan
      uses: aquasecurity/trivy-action@master
      with:
        scan-type: 'fs'
        severity: 'CRITICAL,HIGH'

OWASP Dependency-Check:
  Type:       SCA
  License:    Free (Apache 2.0)
  Strengths:  Free, NIST NVD integration, multiple language support
  Weaknesses: Slower than commercial tools, higher false positives

  Quick start:
    dependency-check --project myapp --scan ./src --format HTML

COMPARISON TABLE#

Tool               | Type     | Cost     | CI/CD | Speed  | FP Rate
-------------------|----------|----------|-------|--------|--------
SonarQube CE       | SAST     | Free     | Good  | Medium | Medium
Semgrep OSS        | SAST     | Free     | Great | Fast   | Low
CodeQL             | SAST     | Free*    | Great | Slow   | Low
Checkmarx          | SAST     | $$$      | Good  | Slow   | Medium
Snyk Code          | SAST     | Freemium | Great | Fast   | Low
OWASP ZAP          | DAST     | Free     | Good  | Medium | Medium
Burp Enterprise    | DAST     | $$$      | Good  | Medium | Low
Nuclei             | DAST     | Free     | Great | Fast   | Low
Nikto              | DAST     | Free     | Basic | Fast   | High
Dependabot         | SCA      | Free     | Native| Fast   | Low
Snyk               | SCA/SAST | Freemium | Great | Fast   | Low
Trivy              | SCA/Cont | Free     | Great | Fast   | Low
Dep-Check          | SCA      | Free     | Good  | Slow   | Medium

* CodeQL free for open-source repos on GitHub

WHEN TO USE EACH#

Development phase:
  IDE         -> Snyk Code, SonarLint, Semgrep (IDE extensions)
  Pre-commit  -> Semgrep, gitleaks (secrets), trufflehog
  PR/CI       -> CodeQL, Semgrep, Snyk, Trivy, Dependabot
  Staging     -> OWASP ZAP, Nuclei, Burp
  Production  -> Nuclei (scheduled), bug bounty, monitoring

Project type:
  Web app        -> SAST + DAST + SCA
  API            -> SAST + DAST (API scan) + SCA
  Mobile app     -> SAST + MobSF + SCA
  Microservices  -> SAST + Container scanning (Trivy) + SCA
  Infrastructure -> Trivy config, tfsec, checkov

CI/CD INTEGRATION PIPELINE#

Recommended pipeline stages:

1. Pre-commit hooks:
   - gitleaks (prevent secret commits)
   - semgrep (quick pattern checks)

2. Build stage:
   - SAST scan (Semgrep or CodeQL)
   - SCA scan (Snyk or Trivy)
   - Container image scan (Trivy)
   - IaC scan (Trivy config or tfsec)

3. Test stage:
   - DAST scan (ZAP baseline or Nuclei)
   - API security scan (ZAP API scan)

4. Gate criteria:
   - No critical/high SAST findings
   - No critical CVEs in dependencies
   - DAST baseline passes
   - Secrets scan clean

Example GitHub Actions workflow:
  name: Security Pipeline
  on: [push, pull_request]
  jobs:
    sast:
      runs-on: ubuntu-latest
      steps:
        - uses: actions/checkout@v4
        - name: Semgrep
          uses: returntocorp/semgrep-action@v1
          with:
            config: p/security-audit

    sca:
      runs-on: ubuntu-latest
      steps:
        - uses: actions/checkout@v4
        - name: Trivy FS Scan
          uses: aquasecurity/trivy-action@master
          with:
            scan-type: 'fs'
            severity: 'CRITICAL,HIGH'
            exit-code: '1'

    dast:
      runs-on: ubuntu-latest
      needs: [sast, sca]
      steps:
        - name: ZAP Baseline
          uses: zaproxy/action-baseline@v0.12.0
          with:
            target: 'https://staging.example.com'

    secrets:
      runs-on: ubuntu-latest
      steps:
        - uses: actions/checkout@v4
        - name: Gitleaks
          uses: gitleaks/gitleaks-action@v2

SECRET SCANNING TOOLS#

gitleaks:
  gitleaks detect --source=. --verbose
  gitleaks protect --staged                # pre-commit hook

trufflehog:
  trufflehog git file://. --only-verified
  trufflehog github --org=<org>

detect-secrets:
  detect-secrets scan > .secrets.baseline
  detect-secrets audit .secrets.baseline

REFERENCES#

- OWASP Testing Guide: https://owasp.org/www-project-web-security-testing-guide/
- OWASP ZAP: https://www.zaproxy.org/
- Semgrep: https://semgrep.dev/
- Trivy: https://aquasecurity.github.io/trivy/
- Nuclei: https://nuclei.projectdiscovery.io/
- NIST SAST/DAST Guidelines: https://csrc.nist.gov/