HostedScan

use case

DAST Vulnerability Scanner

Dynamic Application Security Testing: scan live web applications and APIs for security vulnerabilities

Developer testing a live web application for vulnerabilities

Introducing HostedScan

A powerful online DAST scanner

HostedScan makes it easy to run industry-standard dynamic application security testing (DAST) tools. No installations or downloads required. We manage the complex software for you, so that you can start securing applications immediately.

HostedScan dashboard showing health score, detected risks, recent scans and discovered domains

Ready to run a DAST scan?

Full-stack security

Secure your external attack surface area

HostedScan provides a full set of DAST security tools to protect both your web applications and the infrastructure they run on.

Web Applications

Scan websites and web applications with the ZAP scanner

  • Crawl applications to discover pages, APIs, and input forms.
  • Check for security issues such as insecure headers, CSP policies, and information leaks.
  • Test inputs and APIs for SQL injections, cross-site scripting, and other vulnerabilities.

APIs

Protect your customer data

  • Map API routes for testing using the website crawler.
  • Or provide an OpenAPI or Swagger template with the exact API specs for testing.

Servers

Secure your infrastructure

  • Test servers for tens of thousands of CVE vulnerabilities.
  • Vulnerability feed updated daily to detect the latest threats.

Networks

Detect bugs and misconfigurations

  • Ensure firewalls and networks are configured correctly.
  • Discover publicly exposed ports and services.

Better with HostedScan

Enable your team to move faster

Scheduling & notifications

Always-on protection, without the noise

Run scheduled scans for continuous security monitoring and protection. Cut out the noise and alert your team only for new and unexpected findings.

Security

Ready for SOC 2, ISO-27001, and more

Running a vulnerability scan is just the first step in your compliance journey. HostedScan has all the features you need to set up a full-scale vulnerability management program. Run scans on recurring schedules, alert your team for new vulnerabilities, create rules to reduce noise, prioritize findings, track remediation SLAs, automate evidence collection, and deliver audit-ready reports.

Reporting

Comprehensive reports, that always look good

Get an executive PDF to share. See at a glance the vulnerabilities detected across all your targets or dive into each target, prioritized by risk level.

MSP & MSSP

MSP and agency solutions

Protect all of your clients with a scalable DAST scanning solution. Use tags and workspaces to easily manage multiple tenants and projects. Affordable pricing that scales as you grow.

Learn about our MSP Program

Learn more about DAST

What is a DAST scan?

DAST (dynamic application security testing) is security testing of running applications to look for weaknesses and vulnerabilities. DAST scanning is 'black box' testing. In other words, it sends requests to a live application and examines the responses. This is different from static application security testing (SAST), which examines the static resources such as source code and container images for vulnerabilities.

How does a DAST web application scan work?

First, the scanner crawls the web application to discover the different pages, forms, and APIs. Next the scanner will perform passive and active security tests against the discovered elements.

Passive Tests

Passive tests examine the GET responses from crawling the website. Examples of passive vulnerabilities are cross-domain misconfigurations, insecure cookies, and vulnerable js dependencies.

Active Tests

Active tests will POST data, send requests, and submit forms to the web application. Examples of active vulnerabilities are SQL injection, remote command execution, and cross-site scripting.

Learn More

To learn more about the different passive and active vulnerabilities read the info page for our online web application vulnerability scan.

DAST tool spotlight: ZAP

One of the best DAST tools is OWASP ZAP (Zed Attack Proxy). This open source project is among the world's most widely used DAST scanners and powers the DAST scans of many great companies, including HostedScan.

Learn about ZAP

Benefits of using HostedScan

Strengthen your
cybersecurity
resilience

Mitigate security vulnerabilities

Discover CVEs, OWASP Top 10 vulnerabilities, and exploitable weaknesses across your entire infrastructure. Get prioritized remediation guidance with CVSS scoring and actionable risk classifications—fix what matters first.

Learn more

Manage your risk exposure

With regulations such as GDPR and CCPA, failure to maintain reasonable security procedures is grounds for lawsuits and fines.

Get started

Meet compliance requirements

Vulnerability scanning is essential for your compliance with SOC 2, ISO 27001, cyber insurance, and more.

Learn more

Detect misconfigurations

90% of cyber attacks exploit simple misconfigurations, not zero-days. Detect exposed ports, weak credentials, outdated software, and common security gaps before attackers do—automatically, every day.

Get started

Map your attack surface

Your infrastructure changes constantly. Automatically discover and monitor all websites, servers, networks, and APIs—maintaining complete visibility of your attack surface without manual tracking.

Get started

Our Customers

5,000+ MSPs and IT teams who move faster

BbAmericas
Porsche
ExpediaGroup
WeMakeApps
SibylSoft
Luminary
CoinMe
Appetize
WonderProxy
Median
TaxiCaller
Yamaha
UniversityOfOxford

Speed and power,
without the complexity

The world's leading vulnerability scanners, all in one platform.

Loading call to action