FARION.AI
  • Home
  • Product
      • Platform
      • Platform overview
      • Exploitability Analysis
      • Supply Chain Security
      • Vulnerability Management
      • Active Verification
      • Software License Compliance
      • Solutions
      • Cyber Resilience Act
      • NIS2 Compliance
      • SaaS Application Security
      • AI-Generated Code Security
      • Container Security
      • Pricing
      • Plans & pricing
      • About
      • Technology overview
      • Contact us
      • Imprint
      • Privacy
      • Farion dashboard
        Start free now
  • About
Sign in
Start free now
Active Verification

SAST-directed DAST. Test the finding at runtime.

Farion connects static analysis directly to dynamic testing. A SAST finding supplies the route, parameter, vulnerable operation, and data flow for a targeted test against the running application. The result returns to the same finding with runtime evidence.

Active Verification is enabled only after target ownership or explicit authorization has been verified.

Start free nowNo credit card required
Book a technical demo
Static findings direct dynamic tests

Test the path identified in your code.

Endpoint discovery tells a scanner where it can send requests. Farion also knows what the static analysis found: the input involved, the operation it reaches, and the path between them. That context directs DAST toward a specific vulnerability hypothesis and makes the result relevant to an existing finding.

1. Start with the SAST finding

Use the finding’s route, affected parameter, vulnerable operation, and data flow to define what the dynamic test needs to check.

2. Configure the authorized target

Select the running application and environment to test. Confirm ownership or testing authorization and configure authentication for protected paths.

3. Generate and run a targeted test

Farion uses the static-analysis context to generate a test for that finding and execute it against the configured application. The code context guides the request and payload.

4. Review the runtime evidence

Inspect the payload, requests, responses, and observations alongside the original SAST finding. Review what the execution demonstrated and use the result in the same assessment and remediation workflow.

Sample data · as of October 2026
Route PathExploitabilitySCASASTDAST
APIPOST/api/auth/login
5/5722


A07:2021 – No rate limiting on authentication endpoint
CWE-307: Improper Restriction of Excessive Authentication Attempts
•DAST
•medium

The /api/auth/login endpoint does not implement rate limiting or account lockout. An attacker can perform unlimited login attempts for credential brute-forcing.

Target Endpoint
POST

https://shop.example.com/api/auth/login

Attack Details

Payload

100 sequential POST requests with different password values

Evidence

All 100 requests returned HTTP 401 in ~0.8s avg response time with no rate limiting headers (X-RateLimit-*). No CAPTCHA or account lockout triggered.

APIGET/api/users
4/5721
APIPUT/api/users/:id
4/5510
APIDELETE/api/users/:id
4/5410
APIGET/api/restaurants/…/menu
3/5510
APIGET/api/restaurants/feed
3/5501
APIPOST/api/payments/checkout
3/5310
APIPOST/api/auth/reset-password
3/5310
APIGET/api/users/…/profile
2/5210
APIGET/api/admin/dashboard
2/5200
APIPOST/api/orders
1/5110
APIPUT/api/orders/…/status
1/5100
APIGET/api/restaurants/:id
100
APIGET/api/orders/…/track
100
APIGET/api/search/export
100
APIGET/api/orders
100
APIGET/api/health
000
APIGET/api/config/features
100
Authenticated testing

Include protected application paths.

Configure authentication and application secrets for the authorized target. Farion can then test findings on protected routes in the context of the configured access.

One integrated workflow

Keep the result with the finding.

Static analysis identifies the suspected weakness. Dynamic testing adds observations from the running application. Both remain attached to the finding, so your team can review the code evidence and test result together.

Frequently asked questions

A black-box scanner starts from the exposed application and its responses. Farion also uses an existing SAST finding and its code-level route, parameter, operation, and data flow to choose what to test. This focuses the execution on a specific suspected weakness and connects the result to the evidence that motivated it.

No. The test checks the hypothesis against the configured target. Its outcome must be read with the execution evidence, authentication, and environment. A test that does not reproduce a vulnerability is not by itself proof that the application is safe.

Yes. Configure authentication and secrets for an authorized target so the test can exercise protected application paths.

Active Verification runs against configured targets after ownership or explicit testing authorization has been verified.

Take a SAST finding into a dynamic test.

Walk through the code context, targeted execution, and resulting evidence with our team.

Start free nowNo credit card required
Book a technical demo

FARION.AI

The Farion platform combines native SAST, exploitability-aware SCA with SBOM, VEX and license compliance, and SAST-informed active AI verification.

Platform
Platform overviewExploitability AnalysisSupply Chain SecurityVulnerability ManagementActive VerificationLicense Compliance
Solutions
Cyber Resilience ActNIS2 ComplianceSaaS Application SecurityAI-Generated Code SecurityContainer SecurityCompliance
Scanners
SASTSCADAST
Technology
Technology overviewVulnerability IntelligenceRoute & Data Flow AnalysisLanguages & FrameworksArchitecture & DeploymentIntegrations
Farion
About usPricingFAQsSecurityContact us
Legal
ImprintPrivacyTerms and Conditions (AGB)
Contact
sales@farion.ai

© All rights reserved.