Best SAST and DAST for web applications

Hey, guys!

I know SAST and DAST tools aren't the most reliable softwares in the world and can give you tons of false positives or false negatives... But if you have to choose one, which one would be? And why?

I search about a few and I'm using OWASP Zap, mainly 'cause it's free and my team lack experience with his kind of software, so I don't want to spent a lot of money rn.

submitted by /u/Rekkien
[link] [comments]

from hacking: security in practice
