Tenable Web App Scanning is a dynamic application security testing (DAST) solution that provides comprehensive and automated vulnerability scanning for modern web applications. It offers unified web app and API scanning that is simple, scalable, and automated. Tenable Web App Scanning identifies OWASP Top 10 vulnerabilities, including cross-site scripting (XSS) and SQL injection, in custom application code and vulnerable third-party components. It crawls a running web application to create a site map of pages, links, and forms for testing, then interrogates the site to identify vulnerabilities in the application code or known vulnerabilities in third-party components.