
discover how a security champion acts as the liaison between development and security teams, educates developers, fixes security flaws, and keeps Veracode guidelines and the seven challenges in view.
Learn how to combine static and dynamic analysis through automated scanning to comprehensively identify vulnerabilities, configure unauthenticated and authenticated dynamic analyses, and schedule scans with the Veracode platform.
Learn to understand dashboards and convey security program results by analyzing Varicode scan data, using the security program overview, policy compliance overview, and scanning activity dashboards.
Apply custom dashboard filters on Varicode to narrow results and follow analytics documentation to set a date filter, using exact or relative dates such as before two years ago.
Create custom visualizations to tailor data for management, using filters and publish date adjustments to show relevant scan results with Varicode platform access and documentation.
Save and share dashboards to create an evidential history of security work for upper management, using the Veracode platform to export dashboards, choose Excel format, and share results.
Learn how to start using Varicode software composition analysis to inventory third-party components, identify vulnerabilities, and scan compiled applications via upload-and-scan or agent-based methods.
Learn how to perform static analysis with SAST on Java, C#, and microservices using the Varicode platform. Upload binaries, configure scans, manage auto scan, and review results.
Learn to assemble a consolidated Veracode report that includes the application score, SAST, DAST, and SCA findings, plus executive dashboards to showcase security program status.
Review Varicode knowledge recap, activate your account, manage multi-factor authentication, and generate Varicode API credentials. Explore Varicode software composition analysis for inventorying third-party components, scanning workflows, roles, and platform features.
Learn how to install Burp Suite, compare the professional and community editions, and use the core tools—proxy, repeater, intruder, collaborator, and scanner—for effective web application security testing.
Learn how burp proxy intercepts http requests and responses between your browser and the target server, enabling you to inspect and modify traffic in a man-in-the-middle setup.
Master burp repeater to manually manipulate and re-send individual HTTP and WebSocket messages, analyze responses, and reuse TCP connections to streamline security testing.
Explore burp intruder, a powerful tool for automated web attacks by injecting varied payloads into predefined positions for repeated requests, including Pitchfork and cluster bomb methods.
Learn how the burp collaborator client enables manual testing by generating payloads and pulling the collaborator server for network interactions, using public domains and ports 80 and 443.
Learn to scan websites with burp scanner, automatically crawl web applications to map content and identify vulnerabilities, then generate html or pdf reports for security assessment.
Explore elastic security for siem and security information event monitoring, automating threat detection to investigate and respond quickly, especially when combined with endpoint security in a cloud deployment.
Get started by adding the network packet capture integration and installing the elastic agent to collect data, with built-in dashboards, visualizations, and pipelines that simplify new data sources.
Filebeat collects logs from harvesters and forwards them to Elasticsearch for Elastic Security, enabling professionals to monitor logs for anomalous behavior using the quick start guide and hints-based auto discovery.
Leverage the Filebeat AWS module to read logs from AWS S3 buckets, including S3 server access logs, ELB logs, VPC flow logs, and CloudTrail logs, using SQS notifications for efficiency.
Master the CIS benchmark for AWS resources and identity and access management with IAM, enabling granular, least-privilege permissions, MFA, and guided setup with the Getting Started guide.
Discover AWS S3 as scalable object storage for data lakes, websites, backups, and analytics, with lifecycle, replication, object lock, and batch operations, plus region-aware bucket setup and encryption.
learn to ingest and process AWS logs using CloudTrail for evidential history of API calls, install Philby, configure log locations, parse fields, and visualize in Kibana with Elasticsearch.
Explore monitoring with a siem that ingests, consolidates, searches, and analyzes logs from cloud infrastructure and applications using elastic stack tools, with real-time alerts and case workflows.
Explore VPC peering connections, including inter-region links, to route private traffic between VPCs as a single network, and learn about internet gateways, NAT gateways, security groups, and NACLs.
Explore compliance and infrastructure as code using AWS IAM to control authentication and permissions with least privilege, create an IAM admin user and user group, and review CloudTrail logging.
Learn how Amazon Simple Notification Service (SNS) delivers messages from publishers to subscribers and routes to endpoints like Lambda, SQS, and Kinesis. Also explore CloudTrail for API call logging.
Explore Amazon S3 storage for data lakes, websites, backups, IoT devices, and big data; learn to create a bucket, specify a name and region, and navigate the getting started steps.
Explore how AWS Config maps resource configurations and their direct and indirect relationships over time, enabling administration, auditing, compliance, and security analysis via the AWS management console.
Track AWS API activity with CloudTrail, providing a history of calls across your infrastructure for security and visibility. Learn to create trails and apply filters by time and attributes.
Explore how Amazon CloudWatch monitors AWS resources and applications in real time, collects and tracks metrics and logs, and provides visibility into utilization, performance, and health to help save money.
Learn how Amazon CloudWatch metrics and CloudWatch Metrics Insights identify real-time performance trends, build queries across resources, and monitor logs from EC2, ELB, DynamoDB, and more using the CloudWatch console.
Learn AWS KMS, a managed service for creating and controlling cryptographic keys protected by hardware security modules validated under FIPS 142, with a default key store and key creation steps.
Discover how Amazon SQS provides a secure, durable, and scalable hosted queue for integrating and decoupling software components, with getting started steps to set up a queue.
Explore Amazon vpc basics, launching resources into scalable virtual networks, and managing them through the aws management console, cli, sdk, and api, including public ip addresses and route tables.
Explore how AWS Organizations centralizes multiple accounts into a hierarchical organization using organizational units, including management and member accounts, and follow steps one through four to configure it.
Enable automated security scanning with JFrog Xray, integrating security into DevOps workflows to reveal vulnerabilities, generate vulnerability reports via API, and optionally fail builds to prevent insecure releases.
Welcome to our approach to culture, automation, and platform design, where we forge your team's security skills like a sword. We integrate security as a shared responsibility throughout the entire IT life cycle and equip your team with the necessary skills for implementing "shift-left" development processes, like honing and sharpening a dagger.
Our curriculum includes automated Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Container Scanning, Penetration Testing, and systematic logging to evaluate scanning results, like the fire that fuels your passion for security. And with industry-recognized certifications and executive dashboards to monitor program progress, we'll help keep your assets safe.
Our training program is supported by industry-recognized certificates from Veracode, like the foundation and structure of your sword. We've developed a system that not only leverages state-of-the-art security tools but also provides an automated system that ensures accountability and open communication amongst teams, like the etiquette and grace that a warrior carries on and off the battlefield.
We follow the Net Forward Energy Ratio (NeFER) strategy principle, which provides a systematic process of questions that encourages individuals to take accountability for their work and encourages them to take steps in a forward direction, like a warrior who plans their battles wisely.
Our ideal client for this training program is a Security Engineer who works for a midsize corporation with roughly 40-50 employees. We'll offer the best training coupled with state-of-the-art technology and research-based management practicesto help you wield your security skills like a sword.
The target audience for this training program falls into three categories - CISO, Security Team Lead, or Security Engineer - each with their own unique challenges and opportunities, like the different battles that a warrior faces.
Join us on this journey to become security experts, where we'll hone your skills like a dagger, fuel your passion like fire, and equip you with the knowledge and tools to protect your organization's assets.