Dynamic Application Security Testing

Live security testing that actually confirms what it finds

Point Pragma Core at an application, and an AI agent takes over a dedicated Kali worker to test it end to end. It maps the attack surface, probes for real vulnerabilities, and confirms each one with a full request and response before it ever reaches your findings list. You watch it happen in real time.

Start a DAST engagement View all features

From URL to confirmed findings without spinning up new tools

Create an engagement, set the scope, optionally link a repository for greybox context, and press start. An AI agent handles the rest on dedicated infrastructure your admins control.

1
Define the engagement
Give it a target URL. Optionally attach a repository for source-code context and provide credentials if the test needs to be authenticated. Pick the scope options that match your authorization.
2
A worker gets allocated
The platform picks a free Kali worker from your pool, uploads any credentials it needs as a protected file, and hands control to the agent. You see which worker was assigned on the engagement page.
3
The agent tests the application
Recon, content discovery, authentication, injection, and exploitation happen in sequence. Every command the agent runs shows up on the live timeline so you always know what is going on.
4
You get findings you can trust
Each finding stores the exact request, response, and evidence that proved exploitation. Duplicates across engagements are collapsed automatically so your backlog stays clean.

A timeline you can actually follow, with proof you can reproduce

A slice from a real Medium-depth DAST engagement against a Laravel app. The timeline tracks every command the agent ran, grouped by phase. Each finding ships with the request that triggered it and the response that confirmed exploitation.

Live engagement timeline

3 confirmed findings

Filter by track to focus on a single phase, or scroll to follow the agent step by step. Every action is timestamped against the engagement start.

00:01:08 recon whatweb / wappalyzer fingerprint, app stack identified done
00:04:33 discovery feroxbuster -w common.txt, 38 endpoints discovered done
00:09:21 auth authenticated as [email protected], session cookie captured done
00:14:02 injection SQL injection probe on /api/search, error-based hit confirmed finding
00:21:46 exploitation IDOR on /api/invoices/{id}, retrieved another tenant's invoice finding
00:34:11 exploitation Reflected XSS on /search?q= captured with benign canary finding
00:48:02 general No further injectable parameters found, moving to closure done

Sample finding: IDOR on /api/invoices/{id}

Critical
CWE-639 CVSS 9.1 Confirmed

Request   sent as [email protected] (tenant A)

GET /api/invoices/91144 HTTP/1.1 Host: target.example.com Cookie: laravel_session=eyJpdiI6...truncated Accept: application/json User-Agent: AppSec-Automator/dast

Response   invoice belongs to tenant B

HTTP/1.1 200 OK Content-Type: application/json { "id": 91144, "tenant_id": 42, // bob is on tenant 17 "customer": "Acme Co.", "total": 12480.00 }

Fix: scope the query by tenant. Replace Invoice::findOrFail($id) with $tenant->invoices()->findOrFail($id).

Built for real testing, not checkbox compliance

Non-destructive by design
The agent is instructed to avoid destructive payloads, high-volume fuzzing, brute force, and anything that could affect application stability. Confirmation is always read-only or uses benign canaries. Your production traffic stays healthy.
Live timeline
Every action the agent takes is recorded on a real time timeline organized by phase: recon, discovery, auth, injection, and exploitation. You can watch nmap finish, feroxbuster run, or a targeted exploit attempt complete as it happens.
Confirmed findings only
Every finding carries the exact request that triggered it, the response that confirmed exploitation, and a human explanation of why the issue is real. No theoretical speculation, no noise to triage. You can hand the PoC to a developer and they can reproduce it instantly.
Greybox when you want it
Link any repository already in your workspace and the agent can read the source code while testing. This turns a black-box run into a much smarter greybox engagement where the agent already knows where sensitive routes, auth logic, and trust boundaries live.
Dedicated worker pool
Global admins register their own Kali machines with SSH credentials. The platform handles allocation, capacity limits, and health checks. Test traffic leaves from infrastructure you trust and that nobody else shares.
Authenticated testing, cleanly
Provide login credentials, a session cookie, or a custom header such as an API token. The platform encrypts the value, drops it on the worker as a protected file, and the agent uses it to reach the parts of your application that matter most.

Source-code review is only half the story

Find what static analysis cannot reach
Misconfigured reverse proxies, broken session handling in production, credentials that slipped past the build, exposed debug endpoints. These are the issues that only show up when you talk to the live application. DAST is where they surface.
Sanity check your staged releases
Run a DAST engagement against a staging deployment before a production release. Catch regressions in authentication, access control, and input validation before they reach paying customers.
Continuous pressure, not yearly audits
Traditional dynamic testing happens once a year if you are lucky. With an AI-driven approach, you can run a full engagement whenever a feature ships, a new deployment goes live, or a major refactor lands. Security keeps pace with delivery.
Give developers something they can act on
When every finding comes with a request, a response, and a reproduction story, the fix conversation gets shorter. Developers stop arguing about whether the bug is real. They open the ticket and ship the patch.

What the agent actually looks for

The agent walks through a structured methodology covering the most common web application weaknesses. It does not try to be a marketing scanner with a thousand noisy checks. It tries to find the issues that would get you breached.

SQL Injection Cross-Site Scripting IDOR / Broken Access Control SSRF CSRF Remote Code Execution Path Traversal XXE Open Redirect Information Disclosure Security Misconfiguration Weak Authentication Broken Session Management Cryptographic Flaws Business Logic Abuse

Put your running applications under real pressure

Start a DAST engagement, watch the timeline unfold live, and review findings that come with a full proof of exploitation.

Have questions? Get in touch →