I recently started using StackHawk, and I am impressed with the tooling. Its DAST and API security testing are outstanding, and it integrates beautifully with VS Code.
Application security requires more than simple source code scanning. While SAST, SCA, and secrets scanning are great in CI pipelines, key vulnerabilities remain hidden until an application is running. This is where Dynamic Application Security Testing (DAST) becomes essential.
In my development environment, Claude and GitHub Copilot are building my code and do so much of the Static Application Security Testing (SAST) 7I don't feel compelled to use them in the IDE. Claude does a great job; it can do SAST and implement security best practices extremely well.
Software Composition Analysis (SCA) focuses on the third-party and open-source components our code relies on. Claude once again does a great job of identifying vulnerabilities and upgrading to the latest versions.
Security secrets: Claude once again does a great job, especially with remote repo integrations such as GitHub, ADO, and GitLab.
Conclusion:For enterprises building Azure-hosted web applications and APIs, StackHawk provides a developer-focused approach to DAST that integrates directly into modern DevSecOps workflows. Unlike traditional DAST tools that are often operated chiefly by security teams, StackHawk is designed to work with the developer, providing rapid feedback during testing and deployment processes. This "shift left" saves time and money. There are various DAST options, but StackHawk has become my favourite. With the rise of AI coding, Vibe coding DAST at the developer level is more important than ever.
