DAST identifies security vulnerabilities in running web applications by simulating real-world attacks without access to source code.