Overview
Syllabus
Intro
Go Purple! Adopt purple team strategy to augment Application Security Programs
Challenges
Application Security Program Elements
Blue Team vs Red team
Economics of fixing Security Bugs
Purple team (Realist)
Blue Team (Optimist) vs Red team (Paranoid)
Security within SDLC
Checkpoint Approach
Secure DevOps Approach
Purple Team Approach
Key Aspects
Foundations for a Positive Security Process
Application Security Program Ithe Purple wall
Application Security Program the Purple way!
Application Inventory
Engagement
Unrestricted File Upload
Blind XSS
Security Plan
Full Stack Assessment
Reporting
How do you communicate a vulnerability?
Remediation Consulting
Metrics
Conclusion
Taught by
LASCON