security-testing
Safeguard articles tagged "security-testing" — guides, analysis, and best practices for software supply chain and application security.
40 articles
Your DAST Scanner Was Built to Crawl Links. Your Application Doesn't Have Any.
Classic DAST discovers attack surface by following hyperlinks. In an estate of APIs and serverless functions there is nothing to crawl, so the scan completes, reports clean, and covers little.
Hacking Software: What It Is and How Defenders Use It Legally
Hacking software is the category of programs used to test and break into systems. Used with authorization, it is how security teams find their own weaknesses first.
VAPT Tools: The Vulnerability Assessment and Penetration Testing Toolkit
VAPT tools are the software used to run vulnerability assessment and penetration testing. Here is what belongs in the toolkit, how the categories differ, and how to pick the right tool for the job.
Red team vs. blue team fundamentals: how to structure the exercise
MITRE ATT&CK went public in May 2015 to give red and blue teams a shared language — most organizations still run the two in total isolation.
Dynamic Scanning, Explained for Engineers Who Aren't Security Specialists
Dynamic scanning tests a running application the way an attacker would, by sending it requests and watching what comes back. Here's what that actually involves and when it's the right tool.
Security Regression Testing: Make Sure Fixed Vulnerabilities Stay Fixed
A vulnerability you patched last quarter that quietly comes back this quarter is worse than one you never fixed — because you thought it was handled. Here is how to build security regression testing that keeps fixes fixed.
DAST Tools List: The Dynamic Application Security Scanners That Matter
A practical DAST tools list for 2025: the open source and commercial scanners worth knowing, what each is good at, and how to fit DAST into your pipeline.
How Do You Run a Vulnerability Test? A Practical Guide
A vulnerability test is a systematic check of a system for known security weaknesses. Here is what it involves, the types available, and how to run one that produces action instead of a wall of findings.
Web App Pen Testing: A Practical Guide for Developers
Web app pen testing simulates a real attacker to find exploitable flaws before they do. Here is how the process works, what it covers, and where it fits alongside automated scanning.
ZAP Security Testing: Using OWASP ZAP in Your Pipeline
ZAP security testing works best as a pipeline stage, not a desktop tool. Docker scan modes, authentication, alert filters, and the CI wiring that makes findings stick.
What Is Black Box Testing? A Security Guide with Examples
Black box testing probes a system from the outside with no view of its internals. Here is what it catches, where it falls short, and how it fits a security program.
DAST vs Penetration Testing: Which One Does Your App Actually Need?
DAST vs penetration testing comes down to automation versus human creativity. Here is how they differ, where SAST fits, and why mature teams run all three.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.