What is Static Code Analysis? | AppSec 101

  Рет қаралды 15,037

Fortify Unplugged

Fortify Unplugged

Күн бұрын

Пікірлер: 12
@domaincontroller
@domaincontroller 3 жыл бұрын
00:59 my background 03:17 Static analysis 04:50 weaknesses, vulnerabilities 08:34 SAST, DAST
@FortifyUnplugged
@FortifyUnplugged 2 жыл бұрын
Sorry for the late reply, but thanks for your helpful comment.
@brentjenkins6235
@brentjenkins6235 4 жыл бұрын
Awesome video with great explanations. Look forward to the upcoming series!
@FortifyUnplugged
@FortifyUnplugged 4 жыл бұрын
Thanks! We're trying to add some AppSec intro material to go along with our more technical content.
@SamiEltamawy
@SamiEltamawy 3 жыл бұрын
Great video guys! Very informative and comprehensive explanation and comparison.
@FortifyUnplugged
@FortifyUnplugged 3 жыл бұрын
We appreciate the feedback and glad you found it informative!
@roboedar
@roboedar 2 жыл бұрын
Very great explanation. Thank you.
@FortifyUnplugged
@FortifyUnplugged 2 жыл бұрын
Glad it was helpful!
@rabella183
@rabella183 4 жыл бұрын
Excellent video. Will you be having Hans Enders to provide an overview of WebInspect?
@FortifyUnplugged
@FortifyUnplugged 4 жыл бұрын
He doesn't know it yet, but that's a great idea.
@amjad.6244
@amjad.6244 3 жыл бұрын
Thank You Sir for this video. Can you show me difference between Compiler and Static Code Analysis?
@FortifyUnplugged
@FortifyUnplugged 3 жыл бұрын
Compilers and Static Code Analyzers have a lot in common. In fact, Fortify SCA internally leverages open source compilers in the first stage of the analysis for several languages (e.g. Java, Kotlin). The key difference is what happens after the initial parsing and resolution stages. Compilers would then proceed to output binary or byte-code, where Static Code Analyzers will run multiple analysis algorithms on the data to find security vulnerabilities. Compilers may be doing some quality checking as part of their process (e.g. warning for unused variables or similar bad-practices), but they don't do the type of security analysis that static analysis tools do.
AppSec & QA: Why They Are Better Together | AppSec 101
12:39
Fortify Unplugged
Рет қаралды 777
What Is Dynamic Application Security Testing (DAST)? | AppSec 101
19:41
Fortify Unplugged
Рет қаралды 22 М.
Nastya and balloon challenge
00:23
Nastya
Рет қаралды 55 МЛН
SHAPALAQ 6 серия / 3 часть #aminkavitaminka #aminak #aminokka #расулшоу
00:59
Аминка Витаминка
Рет қаралды 332 М.
Static Code Analysis: Scan All Your Code For Bugs | Synopsys
19:05
What is SAST? | AppSec 101
22:51
Fortify Unplugged
Рет қаралды 4,7 М.
Cybersecurity Architecture: Application Security
16:36
IBM Technology
Рет қаралды 64 М.
Bug Hunting with Static Code Analysis - Nick Jones
34:45
Security BSides London
Рет қаралды 11 М.
What is the OWASP Top 10? | AppSec 101
14:34
Fortify Unplugged
Рет қаралды 13 М.
What is Static Code Analysis? || Various Examples
15:58
Naveen AutomationLabs
Рет қаралды 23 М.
What is DevSecOps? DevSecOps explained in 8 Mins
8:20
TechWorld with Nana
Рет қаралды 224 М.
Nastya and balloon challenge
00:23
Nastya
Рет қаралды 55 МЛН