Onam Security

Dynamic testing (DAST)

Dynamic testing exercises a running web application or API from the outside, the way an attacker would.

Discover, test, report
Discover, test, report
Only test applications you own or are explicitly authorised to test. The payloads are real injection attempts. Use a staging environment that mirrors production.

Starting a test

  • Console: add a DAST Target URL in the New Security Scan dialog. The test runs alongside the repository scan.
  • API: POST /api/v1/secops/dast/scan with the target URL, a profile and optional authentication.
SettingOptions
Profilequick (default), normal, deep
Authenticationnone, basic, bearer token, cookie, OAuth2, custom header

Targets on private networks are refused by default.

Discovery

The scanner builds an endpoint inventory from link and form crawling, analysis of the app's JavaScript, an OpenAPI description if the app publishes one, and common path patterns. Requests are rate-limited. Full browser rendering of single-page apps is not part of the deployed scanner, so publishing an OpenAPI description gives the most complete coverage.

Checks

KindChecks
InjectionSQL (error-based and time-based blind), NoSQL, command, server-side template injection, cross-site scripting
Server-sidePath traversal, XXE, SSRF
Application logicOpen redirect, file upload handling, parameter and method tampering, forced browsing
PassiveSecurity headers, cookie flags, CSRF protection, error and stack-trace disclosure

Results

Each finding records the endpoint, vulnerability type, severity, CVSS and a description. Results show on the DAST tab and the DAST scan page (total findings, critical and high, endpoints, attacks sent). Reports are available as JSON, HTML or SARIF from GET /api/v1/secops/dast/scan/{scan_id}/report?format=json|html|sarif.

Credentials for the target

Authentication details are passed to the scan job that tests your app. Use a dedicated test account with the least access the test needs.

DAST findings are about endpoints, not source files, so they are not traced to a line of code and AI Code Fix does not apply to them.