🛡️ AppSec — Application Security
SAST · DAST · SCA · IAST · RASP · OWASP Top 10 · Threat Modeling · Secure SDLC
📊 Testing Method Comparison
| Method | When to Run | Access Needed | Speed | False Positive Rate | Best For |
|---|---|---|---|---|---|
| SAST | Commit / PR review | Source code | ⚡ Fast | 🔴 High | Code-level bugs early in SDLC |
| DAST | Staging pre-release | Running app only | 🐢 Slow | 🟡 Medium | Runtime vulns, OWASP Top 10 in live app |
| SCA | Every build | Package manifests | ⚡ Fast | 🟡 Medium (transitive) | Open-source dependency CVEs, SBOM |
| IAST | QA / functional test run | Runtime agent | ⚡ Passive | 🟢 Very Low | Reachable vulns with zero false positives |
| RASP | Production | Runtime agent | ⚡ Real-time | 🟢 Low | Production attack blocking, compensating control |
| Pen Test | Pre-release / annual | Black/gray/white box | 🐢 Days/weeks | 🟢 Very Low | Business logic flaws, chained attack scenarios |