
Explore secure code analysis through static application testing using Fortify, focusing on source code review to identify vulnerabilities and ensure security controls work across languages.
Master secure code analysis by applying manual and automated methods, evaluate popular tools and languages, and leverage Fortify, Sonar Cube, Bandit, and Veracode for effective vulnerability detection.
Identify Fortify 45 system requirements, including minimum 8 GB RAM (16 GB recommended, 32 GB server), supported Windows, Linux, and macOS, and compatible build tools and plugins.
Install Fortify SCA by selecting the installation directory, license, and needed plugins. Launch Fortify Workbench to manage rules, view the Fortify project report, and complete post-install updates and migration options.
Execute a basic Fortify audit workbench scan to generate an fpr report, selecting Java version 1.8 and customizing issue and code-quality filters in the GUI.
Explore advanced scan in audit workbench by configuring folders, classpath directories, and build format, manage warnings and fpr output, and tune memory and quick scan mode for efficient scanning.
Review the Fortify project report (FPR) in the auditor view, examining critical, high, medium, and low issues with analysis evidence, and group by category to prioritize remediation.
Explore the scan wizard in Fortify, configure a project root, select languages, enable build integration, and generate a batch file to run a secure code analysis with verbose output.
Learn how to run a command line scan with sourceanalyzer in Fortify, generate an fpr report, and interpret findings like cross-site scripting, open redirect, and privacy issues.
Install the fortify plugin for Visual Studio after installing and closing the IDE, then run the wizard to update and enable analyze, collaborate, and audit projects with the complete package.
Install the Fortify plugin in Visual Studio, scan a dotnet solution to generate an FPR, and set ASP pre-compilation to false in Fortify properties to avoid errors.
Learn to interpret Fortify's FPR results, switch to security audit view, and triage findings from insecure transport, path manipulation, and XSS with encryption and input validation recommendations.
Explore the software security center overview, a deployable web server with Apache, LDAP, and FPR uploads that enables vulnerability tracking and risk management through a comprehensive dashboard.
Explore fpr analysis of a Java application, identifying critical vulnerabilities such as cross-site scripting, sql injection, and path manipulation, and how to mark issues as exploitable or suspicious.
Analyze high findings in secure code analysis, including access control, file disclosure, header manipulation, server side request forgery, and reliability issues to strengthen application security.
Analyze medium issues like xml entity expansion injection due to missing doctype restrictions, and examine low severity concerns from sql injection risks, csrf, javascript hijacking, and missing null checks.
Review and categorize remaining low issues in secure code analysis, covering null checks, XML validation, password management, error handling, logging, and cryptographic hashing, with actionable recommendations.
Walks through critical and high severity issues in Fortify secure code analysis, detailing cross-site scripting, dangerous file inclusion, open redirects, and external entity injection with practical examples.
Explore the details and recommendations tabs for medium and low Fortify vulnerabilities, reading code-level mitigations and examples to perform effective code reviews and secure fixes.
So are you struggling to get a job in Information Security industry but Resume got rejected for not having Secure Code Review?
Recruiter prefer secure code as an added advantage over other skills, because candidates with this skill are very rarely available.
In Information security domain, only 1 out of 10 security analysts have secure code review experience.
If you want to be that 1 out of those 10 candidates, then this is right place for you.
This course provides details right from the scratch - installation of tool , scanning to complete analysis.
Curriculum For This Course below provides topic wise description of each video that may help you to make your mind with your requirements.
There are no course in the market to give good training on secure code review nor about Fortify tool, because the licensing are quite high. And are only available with IT giants. Moreover, trainers charge thousands of dollars to teach about this tool. So why not invest a hundred dollar instead of thousands?
After completing this course, you will have the necessary skills to be able to undertake assessments without supervision.
The sooner you sign up for this course, the sooner you will have the skills and knowledge you need to increase your job or consulting opportunities in the Information Security.
Bonus Advantage for subscribing this course-
Offline guidance provided with prompt response, if you are stuck up or unable to grasp things.
For newbies - Documentation are provided, with examples, in a very lucid language, just one glance is enough to grasp.
Report extracted from fortify is provided at the end of the course for better understanding (Which you will never get anywhere)
Security consultants with Secure Code Review skills are in high demand.
Your new job or consulting opportunity awaits!
Why not get started today?
Hit the Signup button and Happy Learning :)