Application scanning tools are commonly used as part of the software development process. These tools analyse *custom developed software to identify common security vulnerabilities*. Application testing occurs using three techniques:
- **Static testing** analyses code *without executing* it. This approach points developers directly at vulnerabilities and often provides specific remediation suggestions.
- **Dynamic testing** executes code as part of the test, running all the *interfaces that the code exposes* to the user with a variety of inputs, searching for vulnerabilities.
- **Interactive testing** combines static and dynamic testing, *analysing the source code while testers interact with the application* through exposed interfaces.
Application testing should be an integral part of the software development process. Many organisations introduce testing requirements into the software release process, requiring clean tests before releasing code into production.