Dynamic Application Security Testing
3h 24mIntermediate2023-02-22
Authors

Jerod Brennen
Security Architect, Advisor, Speaker, Teacher
Course details
Building security testing into the software development lifecycle is the best way to protect your app and your end users. This course identifies tools and techniques that developers can use to minimize the cost and impact of security testing—while maximizing its impact and effectiveness. Instructor Jerod Brennen focuses on dynamic application security testing, using security scanning, penetration testing, and vulnerability testing to validate code and uncover vulnerabilities. He explains the difference between positive and negative, manual and automated, and production and nonproduction testing, so you can choose the right kind for your workflow. The hands-on sections—with demos of popular tools such as OWASP ZAP and Burp Suite—prepare you to apply the lessons in the real world.
Skills covered
Burp SuitePortSwiggerApplication SecuritySecurity TestingCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - The importance of dynamic testing
- 02 - What you should know
1. Security Testing in QA
- 03 - Software quality assurance process
- 04 - Positive testing
- 05 - Negative testing
- 06 - SQA metrics
- 07 - OWASP Testing Guide
- 08 - Demo - OWASP ZAP
2. Assessing Deployed Apps
- 09 - Manual vs. automated testing
- 10 - Scanning vs. pen testing
- 11 - Testing in non-production
- 12 - Testing in production
- 13 - OSINT gathering
- 14 - Web app proxies
- 15 - DevSecOps
- 16 - Demo - Burp Suite
3. Web App Pen Testing
- 17 - Scoping a web app pen test
- 18 - Avoiding production impacts
- 19 - Penetration testing execution standard
- 20 - Types of pen tests
- 21 - Web application firewalls
- 22 - SIEMs
- 23 - Purple teaming
- 24 - Demo - Kali Linux
4. Testing for the OWASP Top Ten (2021)
- 25 - The OWASP Top Ten
- 26 - A1 - Broken access control
- 27 - A2 - Cryptographic failures
- 28 - A3 - Injection
- 29 - A4 - Insecure design
- 30 - A5 - Security misconfiguration
- 31 - A6 - Vulnerable and outdated components
- 32 - A7 - Identification and authentication failures
- 33 - A8 - Software and data integrity failures
- 34 - A9 - Security Logging and monitoring failures
- 35 - A10 - Server-side request forgery (SSRF)
Conclusion
- 36 - Next steps