Module 2 · SAST · DAST · SCA
The alphabet soup, untangled
09 / 38

Three tools, three different questions.

Before the acronyms multiply: does the tool look at your code without running it, while it's running, or at the other people's code you depend on?

SAST · static

Reads your code

Without ever running it. Like a proofreader reading the manuscript before it's printed.

DAST · dynamic

Attacks the running app

From the outside, like a real attacker. A burglar testing your locks while you live in the house.

SCA · composition

Audits your dependencies

Third-party libraries you depend on. Checking whether the bricks you bought have a recall.

Needs source?Runs how early?Finds
SASTYesEvery commit/PRInjection patterns, hardcoded secrets
DASTNo — external attackerNeeds a running envMisconfig, auth bypass, real exploits
SCAManifest onlyEvery dependency changeKnown CVEs in libraries

SAST reads, DAST attacks, SCA audits your supply of borrowed code — a mature pipeline runs all three, at different stages.