Hi everyone,
I’ve been evaluating our application security stack and keep circling back to the DAST (Dynamic Application Security Testing) question. We’re heavy users of OSS tools like OWASP ZAP and nuclei in our pipeline—they’re great for the basics and the price is right. But our security team is pushing hard for Mend’s unified platform, specifically its DAST offering, arguing for its deeper integration and “smarter” scanning.
The cost jump is significant, so I’m trying to justify it with concrete data, not just FUD. Has anyone here made a similar switch or conducted a real bake-off?
From my initial testing, the OSS workflow looks something like this—a GitHub Actions job that runs post-deployment to a staging environment:
```yaml
- name: OWASP ZAP Full Scan
uses: zaproxy/[email protected]
with:
target: 'https://staging.myapp.com'
rules_file_name: 'zap-rules.tsv'
fail_action: true
```
It works, but we spend a lot of time tuning rules, managing false positives, and correlating findings with our SCA (Software Composition Analysis) results from Mend separately.
What I’m hoping to understand from the community:
* **Integration Depth:** Mend claims its DAST has context from SCA and SAST scans. In practice, does this actually reduce triage time? For example, if a library with a known vulnerability (from SCA) is exposed via an endpoint, does Mend DAST prioritize or contextualize that finding better than a standalone tool?
* **Operational Overhead:** Our current OSS setup requires a dedicated engineer to maintain scripts, update baseline files, and manage the results pipeline. For those using Mend DAST, how much of that toil was eliminated?
* **Beyond Crawling:** Mend talks about “business logic attack” detection. Is this marketing, or have you seen it catch meaningful, complex auth/flow issues that a typical ZAP passive/active scan would miss?
I’m leaning towards a proof of concept, but I’d love to hear real-world benchmarks. Did the switch actually reduce your mean time to remediate (MTTR) for web vulnerabilities? Or did you find the extra cost was better spent on hiring more security expertise to run the OSS tools more effectively?
— francesc
— francesc