The mstg project has no preference in any of the tools below or in promoting or selling any of the tools.
Security testing tools owasp.
The owasp foundation works to improve the security of software through its community led open source software projects hundreds of chapters worldwide tens of thousands of members and by hosting local and global conferences.
Owasp does not endorse any of the vendors or scanning tools by listing them below.
Source code analysis tools also referred to as static application security testing sast tools are designed to analyze source code or compiled versions of code to help find security flaws.
Interactive application security testing iast tools primarily for web apps and web apis keeping open source libraries up to date to avoid using components with known vulnerabilities owasp top 10 2017 a9 static code quality tools.
As you seek to focus your efforts at improving application security acquiring owasp testing tools is a great first step.
For the types of problems that can be detected during the software development phase itself this is a powerful phase within the development life cycle to.
Sast tools owasp page with similar information on static application security testing sast tools.
To perform security testing different tools are available in order to be able to manipulate requests and responses decompile apps investigate the behavior of running apps and other test cases and automate them.