Skip to content
José da Cruz

Enterprise Architect, and Life Thinker

José da Cruz

Enterprise Architect, and Life Thinker

IAST

josedacruz, September 23, 2023

IAST – Interactive Application Security Testing

identifies security vulnerabilities in application code while it’s running.

  • Integrates agents, sensors, and libraries into the application.
  • It has access to the entire code, dataflow, configurations, web components, and connections.
  • Can be automated or manually conducted by a human tester.
  • It highlight the blocks of code where a vulnerability is found.
  • This test combats the trend of attacks targeting the application layer.
  • Types of vulnerabilities identified: hardcoded APII keys, lack of sanitization, and connections without SSL
  • IAST tests an application during execution; SAST tests in a non-execution application.
  • Complements other testing methods such as SAST and DAST.

Related

architecture architectureiastsecurity

Post navigation

Previous post
Next post

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • architecture (153)
  • artificial-intelligence (6)
  • books (2)
  • courses (4)
  • decision-frameworks (4)
  • finances (1)
  • java (8)
  • life-improvement (20)
  • metrics (3)
  • observability (2)
  • puzzles and challenges (3)
  • reviews (1)
  • security (8)
  • spring-boot (36)
  • Systems Thinking (3)
  • The Bulkhead Pattern: Why One Slow Dependency Shouldn’t Sink the Whole Ship
  • Essential Reading: A Philosophy of Software Design — Fighting Complexity One Module at a Time
  • GitHub Weekly: Top 10 Trending Repos (September 21 – September 27, 2026)
  • The Volunteer Tax: Why Raising Your Hand in a Meeting Makes You the Permanent Owner
  • Postel’s Law: Why Being Liberal in What You Accept Usually Backfires
©2026 José da Cruz | WordPress Theme by SuperbThemes