Likelihood to Recommend I think CAST is a great tool to give insight into your applications. The tool can be met with resistance from team members as the tool is going to expose defects that should be addressed. Out of the box, it may need some tailoring to focus on certain areas so that you are not overwhelmed with defects the first time you scan your code. But ultimately, you will want to eliminate all defects in the code and have all violations turned on.
Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review Burp Suite is a good general tool to test websites as long as your website is not too large or you have the time for it to complete. We have some websites that only about five to ten minutes for Burp Suite to complete an attack and a spider only takes about two minutes. Other websites have taken a few hours to complete. I have seen a tester actually run Burp Suite against one of our websites and it took all day to complete.
Read full review Pros Identifies common coding vulnerabilities. Compares code to industry best practices. Assesses the code for data privacy compliance. Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review The passive scan feature is really awesome, it kind of covers areas that you might miss. The CSRF POC is really helpful to my team. It helps development team see the issue and understand it. Burp intruder and repeater are the features I myself and my team uses the most as it helps us use our payloads in a variety of different ways. Active scan helps the team to ensure coverage for the whole application. Read full review Cons Code scans could be faster. A large application may need to be broken down into smaller sub-applications in order to facilitate faster code scans. We spent a lot of time trying to figure out how to best structure our code base in the application for ultimate performance. Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review More features to be available for the free/community version to allow more learning Manual updating of plugin without network connectivity More controls with the manual testing with scenario inputs Read full review Usability Given this tool's wide area of testing functionality for mobile and web applications, it's a great tool to invest in for security testing. Though it lacks documentation to carry out particular vulnerability findings which are very challenging for a new user of this tool
Read full review Support Rating Tech support and pro services are top-notch.
Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review BurpSuite does not have an amazing customer support. All the major help that you will find is from public forums and Google. Although you will find all the required information on Google, still at time professional support helps you solve the problem in much less time and make your operations go smoothly.
Read full review Alternatives Considered These other tools only do a part of what CAST does. CAST gives a comprehensive view into the code looking at all aspects, code quality, security, maintainability, vulnerability, privacy, reuse, etc. These other tools only focus on one or two dimensions.
Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review The only other tool I use that works like Burp Suite is the OWASP ZAP. It works a lot like Burp but just has a different layout. I prefer how Burp has the tabs for Repeater, Intruder, Decoder, ect.
Read full review Return on Investment I believe once we had the tool working for our code base, we immediately saw positive ROI. We spent some time getting to where our code code be scanned efficiently but some of that was trying to do things ourselves instead of fully utilizing Cast Professional Services. I highly recommend to do an engagement with CAST to have them help setup the tool in your environment or to run it in the cloud for you. Gene Baker Vice President, Chief Architect, Development Manager and Software Engineer
Read full review Positive impact, time to complete security development stage is decreased. Very positive impact on budgeting for external penetration testing. We can do the bulk of the common testing ourselves now. Read full review ScreenShots CAST Highlight Screenshots