<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sast on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/sast/</link><description>Recent content in Sast on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:19:31 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/sast/index.xml" rel="self" type="application/rss+xml"/><item><title>SAST vs DAST: Static vs Dynamic Application Security Testing</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-sast-vs-dast-static-vs-dynamic-application-security-testing/</link><pubDate>Mon, 03 Aug 2026 04:19:31 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-sast-vs-dast-static-vs-dynamic-application-security-testing/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;SAST scans an application&amp;rsquo;s &lt;strong class="kw"&gt;source code&lt;/strong&gt; at rest to catch insecure patterns before the app ever runs, while DAST attacks a &lt;strong class="kw"&gt;running application&lt;/strong&gt; from the outside to find exploitable flaws in its live behavior. Teams use both because each catches vulnerability classes the other structurally cannot see.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="150" y="40" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;SAST&lt;/text&gt;&lt;text x="150" y="60" text-anchor="middle" style="fill:var(--secondary)" font-size="12"&gt;source code, no execution&lt;/text&gt;&lt;rect x="60" y="80" width="180" height="180" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="72" y="102" style="fill:var(--content)" font-size="11" font-family="monospace"&gt;function login(u,p) {&lt;/text&gt;&lt;text x="72" y="120" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; const q =&lt;/text&gt;&lt;rect x="68" y="128" width="162" height="18" rx="3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="72" y="141" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; "SELECT..+p";&lt;/text&gt;&lt;text x="72" y="159" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; db.exec(q);&lt;/text&gt;&lt;text x="72" y="177" style="fill:var(--content)" font-size="11" font-family="monospace"&gt;}&lt;/text&gt;&lt;circle cx="215" cy="137" r="16" style="fill:none;stroke:var(--compare-a)" stroke-width="2.5"/&gt;&lt;line x1="226" y1="148" x2="238" y2="160" style="stroke:var(--compare-a)" stroke-width="2.5" stroke-linecap="round"/&gt;&lt;text x="150" y="290" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;reads code, flags line 128&lt;/text&gt;&lt;text x="150" y="308" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;e.g. unsanitized SQL concat&lt;/text&gt;&lt;text x="490" y="40" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;DAST&lt;/text&gt;&lt;text x="490" y="60" text-anchor="middle" style="fill:var(--secondary)" font-size="12"&gt;running app, black-box&lt;/text&gt;&lt;rect x="400" y="80" width="180" height="120" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="490" y="110" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Live App&lt;/text&gt;&lt;text x="490" y="128" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;/login endpoint&lt;/text&gt;&lt;circle cx="490" cy="160" r="14" style="fill:none;stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;path d="M484 160 L496 160 M490 154 L490 166" style="stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;rect x="430" y="235" width="120" height="36" rx="5" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="490" y="258" text-anchor="middle" style="fill:var(--content)" font-size="10" font-family="monospace"&gt;POST u=' OR 1=1--&lt;/text&gt;&lt;path d="M490 205 L490 232" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrow)"/&gt;&lt;path d="M460 235 Q 460 210 480 202" style="stroke:var(--compare-b);fill:none" stroke-width="1.5"/&gt;&lt;text x="490" y="300" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;sends live requests, observes response&lt;/text&gt;&lt;text x="490" y="318" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;e.g. auth bypass returned&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;SAST&lt;/th&gt;
&lt;th&gt;DAST&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;What it examines&lt;/td&gt;
&lt;td&gt;Source code, bytecode, or binaries at rest&lt;/td&gt;
&lt;td&gt;A running, deployed application from outside&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Access level&lt;/td&gt;
&lt;td&gt;White-box — full visibility into code internals&lt;/td&gt;
&lt;td&gt;Black-box — only sees inputs and outputs like an attacker&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;When in SDLC&lt;/td&gt;
&lt;td&gt;Early, during coding and in CI on every commit&lt;/td&gt;
&lt;td&gt;Later, once a build is deployed to a test or staging environment&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Environment needed&lt;/td&gt;
&lt;td&gt;None — analyzes files directly, no app needs to run&lt;/td&gt;
&lt;td&gt;A live, reachable instance of the application&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Vulnerability classes found&lt;/td&gt;
&lt;td&gt;Insecure code patterns: SQL string building, hardcoded secrets, unsafe deserialization&lt;/td&gt;
&lt;td&gt;Exploitable runtime behavior: auth bypass, injection responses, misconfigured headers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Language/stack dependency&lt;/td&gt;
&lt;td&gt;Tied to the language and framework being parsed&lt;/td&gt;
&lt;td&gt;Language-agnostic — probes over HTTP/HTTPS regardless of stack&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;False positive tendency&lt;/td&gt;
&lt;td&gt;Higher — flags patterns that may not be reachable or exploitable&lt;/td&gt;
&lt;td&gt;Lower — findings are confirmed by actual exploit attempts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remediation output&lt;/td&gt;
&lt;td&gt;Exact file and line number to fix&lt;/td&gt;
&lt;td&gt;Vulnerable URL, parameter, and request/response evidence&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAST inspects &lt;strong class="kw"&gt;source code&lt;/strong&gt; without running it; DAST attacks a &lt;strong class="kw"&gt;live instance&lt;/strong&gt; without seeing its internals&lt;/li&gt;
&lt;li&gt;SAST fits early into &lt;strong class="kw"&gt;CI pipelines&lt;/strong&gt; per-commit; DAST needs a &lt;strong class="kw"&gt;deployed build&lt;/strong&gt; to test against&lt;/li&gt;
&lt;li&gt;SAST pinpoints the exact &lt;strong class="kw"&gt;line number&lt;/strong&gt;; DAST reports the vulnerable &lt;strong class="kw"&gt;endpoint&lt;/strong&gt; and payload&lt;/li&gt;
&lt;li&gt;SAST is prone to &lt;strong class="kw"&gt;false positives&lt;/strong&gt; from unreachable code paths; DAST confirms via &lt;strong class="kw"&gt;actual exploitation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;SAST misses &lt;strong class="kw"&gt;runtime configuration&lt;/strong&gt; flaws that DAST catches, like missing security headers or session issues&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;SAST&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>