← Back to Labs

Automated Vulnerability Scanner Blindspots

Step through SAST AST taint engines, DAST dynamic crawlers, business logic flaws, race conditions, and manual threat modeling

SAST: ACTIVE (AST TAINT TRACE)DAST: INACTIVEMANUAL: NOT APPLIEDSAST Taint Engine: Abstract Syntax Tree & Control Flow Graph AnalysisSource Inputreq.query.keywordTaint TrackAST BinaryExprStringConcat (Unsanitized)Vulnerable Sinkdb.query(sqlQuery)FLAGGED (CWE-89)AST Pattern Rule #104 MatchedStatic Taint propagation confirmed untrusted HTTP query string reached raw SQL query sink without sanitizer node.
STEP 1 OF 6

SAST Abstract Syntax Tree Taint Analysis

SAST parsers construct Abstract Syntax Trees (AST), Control Flow Graphs (CFG), and Data Flow Graphs (DFG) to trace untrusted inputs (sources) to sensitive execution points (sinks). While highly effective for known pattern matching like raw SQL string concatenation, SAST operates statically without runtime execution context.

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →