Skip to content

Software delivery

Dynamic application security testing

Review runtime host-scan and incident-response data where DAST is enabled.

The DAST area exposes Incident Response Data and Host Scans Data for eligible test roles. Use it to investigate runtime observations alongside the project’s source and dependency results.

DAST visibility is role- and environment-dependent. Confirm authorization and target scope before a test, and do not infer source-code coverage from a host scan result.

Runtime context complements pre-execution checks

Section titled “Runtime context complements pre-execution checks”

Source and dependency scans examine material before or apart from execution. Runtime observations describe an environment while software is operating. The DAST area brings eligible host-scan and incident-response information into the console for investigation alongside the project’s other results.

Use the available target, time and observation details to establish what was assessed. A source finding and a runtime observation can support the same investigation without being equivalent evidence.

Console observations versus managed Cloud assessment

Section titled “Console observations versus managed Cloud assessment”

The DAST page’s role-gated data views are different from Cortex Cloud runtime security. Cloud’s eligible workflow builds and validates a project candidate, checks application readiness and performs bounded behavior assessments in an isolated environment.

Neither page implies permission to test an arbitrary external target. Confirm authorization and supported scope before assessment. Broader runtime-security research, including automated containment or production monitoring, does not establish that those controls are exposed in the DAST console.

See the public runtime-security discussion for context and the Cloud assessment release for the separate managed workflow.