Burp Suite User Forum

Create new post

Static Analysis (SAST) and Dynamic Analysis

Jorge | Last updated: Jun 25, 2021 07:59PM UTC

Dear, I would like to know if it is possible to perform static and dynamic analysis of code for an API developed in C #. Greetings

Uthman, PortSwigger Agent | Last updated: Jun 28, 2021 07:43AM UTC

Hi Jorge, The Burp Scanner can perform SAST and DAST but the SAST is limited to client-side JavaScript. You can find all the issues the scanner can detect here: - https://portswigger.net/kb/issues To scan an API, you need to make sure that it meets the criteria in the documentation below: - https://portswigger.net/burp/documentation/desktop/scanning/api-scanning I would suggest applying for a free trial to understand how well our products fit your use case: - https://portswigger.net/burp/pro/trial - https://portswigger.net/burp/enterprise/trial

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.