Seeker is an Interactive Application Security Testing (IAST) tool that analyzes web application code and data flows at runtime to detect and confirm exploitable security vulnerabilities. The tool discovers APIs in application portfolios and dynamically scans them for vulnerabilities. It detects API and web interfaces, including microservices like gRPC, by finding specifications for REST, SOAP, and GraphQL APIs. Seeker monitors web application interactions in the background during normal testing and can process HTTP(S) requests with minimal false positives. The tool automatically retests identified vulnerabilities to validate whether they are exploitable and provides real-time views of security vulnerabilities. It tracks sensitive data flow and API calls, showing where critical information is stored without sufficient encryption. Seeker integrates Black Duck Binary Analysis to analyze target binaries for open source security vulnerabilities, versioning, and license information. The tool provides actionable guidance that enables developers to address root causes of security vulnerabilities and is designed to deploy and scale in CI/CD development workflows with native integrations, web APIs, and plugins for integration with development tools.