DongTai IAST is an open-source tool for finding application vulnerabilities by analyzing runtime traffic. It uses passive instrumentation, examining application test traffic rather than running dedicated attack tests. Its engine analyzes HTTP, HTTPS, and RPC requests using method-call data and taint tracking. The project lists Java, Python, PHP, and Go for detection, and says it can prioritize verified vulnerabilities by risk and help developers trace findings to code. It also identifies open-source component vulnerabilities, sensitive information, and hardcoded information. The server provides project and user management, vulnerability analysis and reports, notifications, a Web API, and custom vulnerability rules. Deployment options include SaaS, localized deployment, Docker Compose, and Kubernetes. An IntelliJ IDEA plugin can run the Java probe. The project describes uses including DevSecOps detection, open-source vulnerability research, and pre-release security testing. The self-hosted open-source deployment is free under the Apache-2.0 license. Python, PHP, and Go agents are marked beta; the project cautions that community-maintained beta agents are not guaranteed to deploy successfully.
Who it is for
DongTai suits development and security teams seeking passive vulnerability analysis in application test traffic. Its deployment options and API may also suit teams incorporating findings into DevSecOps workflows.
What is good
- Passive analysis uses application test traffic.
- Analyzes HTTP, HTTPS, and RPC requests.
- Offers Docker Compose and Kubernetes deployment.
- Server includes reports, notifications, and custom rules.
- Open-source self-hosted deployment is free.
What to know first
- Python, PHP, and Go agents are beta.
- Community-maintained beta agents may not deploy successfully.
- Commercial deployment guide requires sudo privileges for iastctl.
Verdict
DongTai combines traffic-based detection with vulnerability reporting and several deployment options. Check the beta status of non-Java agents before relying on them.
DongTai IAST plans and pricing
All plansCompared on interactive application security testing software
- Runtime targets
- web
- Deployment
- hybrid
- API testing
- Yes
- Instrumentation
- agent
- Language coverage
- Java, Python, PHP, Go




