SAST
Static Application Security Testing
Static Application Security Testing analyzes source code, bytecode, or binaries for security vulnerabilities without executing the application. SAST tools scan for patterns matching known vulnerability types like SQL injection, buffer overflows, and hardcoded credentials.
Cómo se usa en ciberseguridad
Security engineers integrate SAST into CI pipelines to catch vulnerabilities before code reaches production. Penetration testers review SAST findings to identify areas worth deeper manual testing. Security architects evaluate and standardize SAST tools across engineering teams to maintain consistent code quality.
Término relacionado en el glosario: sast
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.