We recently switched our security scanning from annual manual pen tests to a Veracode subscription (static + dynamic scanning on a monthly cadence). The automation is great for catching regressions, but I'm worried we've created a coverage gap in business logic and authorization flaws.
Our old process: external consultants would spend two weeks with full context, trying to chain vulnerabilities and exploit workflow edges. Now Veracode's dynamic scanner seems to crawl and test like an authenticated user, but I'm not convinced it understands our app's actual *intent*.
Has anyone else made this shift? I'm trying to map what we might be missing:
* **AuthZ bypasses:** Does the dynamic scanner effectively test for horizontal/vertical privilege escalation, or just common IDOR patterns it knows?
* **Multi-step exploits:** Can it simulate a complex attack that requires state changes across several requests (e.g., create object, update metadata, trigger action)?
* **Context-aware payloads:** Our manual testers would craft inputs based on conversation with our team. Does the DAST engine go beyond standard payload libraries?
I've started a rough spreadsheet comparing findings from our last manual test against Veracode's first three monthly reports. The initial data shows Veracode is strong on OWASP Top 10 technical flaws (SQLi, XSS, etc.) but silent on several business logic issues that were previously flagged.
Are we just configuring the dynamic scans wrong, or is this an inherent limitation of automated DAST? Do we need to supplement with periodic manual tests even with the subscription, or are there advanced Veracode workflows (custom rules, specific scan settings) that can close part of this gap?
I'm a community manager at a mid-sized SaaS company, and we've run both annual pen tests and a Veracode subscription for the past three years to cover different parts of our web app stack.
Your concern is spot-on, and our experience lines up with your mapping exercise. Here's a breakdown of the concrete gaps we've had to fill:
1. **Coverage of Business Logic Flaws**: Veracode's dynamic scan, in our setup, does not find authZ bypasses that require understanding user roles and workflow intent. It reliably catches common IDOR patterns, but we've never had it flag a horizontal privilege escalation that wasn't in a standard OWASP test library. Manual tests found 3-5 of these per cycle for us; Veracode DAST found zero.
2. **Multi-Step Exploit Simulation**: The dynamic scanner cannot chain state changes across requests to simulate a complex attack. It treats requests largely in isolation. For example, it won't create an object, then manipulate its metadata, then trigger a downstream action. Our manual testers consistently found 1-2 critical issues per year using these multi-step chains.
3. **Context-Aware Payloads**: The engine does not go beyond its standard payload libraries. It doesn't craft inputs based on app-specific context or business rules communicated to a human. This is a major blind spot for parameters that expect specific data formats or sequences unique to your app.
4. **Cost & Effort Comparison**: Our Veracode subscription runs about $65-85k annually for static and dynamic. An annual two-week manual pen test from a reputable firm was $25-35k. The automation is not cheaper; it's a different line item. The integration effort for Veracode was about 3 weeks of engineering time to get clean scans, and it requires ongoing tuning of about 4-8 hours per month to manage false positives.
My recommendation is to keep Veracode for regression catching and common vuln scanning, but budget for a targeted, focused manual pen test annually to cover business logic and complex authZ flaws. To make a clean call, tell us your app's compliance requirements and how many unique user roles/workflows you have.
Keep it real, keep it kind.