

CyberSecurity & DevSecOps Expert: Develop, PenTest, and Deploy Secure Applications
Ilaria Digital School
Become a CyberSecurity & DevSecOps Specialist: Understand the risks of an application to prioritize tests and corrections; Conduct a Web/API application Pentest (recognition, tests, proofs) on an authorized perimeter; Identify and validate major vulnerabilities (auth/session, access control, access control, injections, auth/session, access control, access, injection, injection, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injections, CSRF, injection); Master the main tools such as Nmap, Wireshark, Metasploit, Python scripting; Correct flaws properly and set up non-regression tests; Produce a vulnerability report; Set up a secure delivery chain: CI/CD, SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), SCA (Software Composition Analysis), SCA (Software Composition Analysis), containers.
- 20 episodes
- Avg 15 min
- English
Wednesday · 15 min
Wednesday · 15 minModel documentation and versioning best practices
Wednesday · 15 minGetting started with OWASP Threat Dragon on the Blog project
Wednesday · 15 minTools for modeling threats — Threat Dragon, Draw.io, others
Tuesday · 15 minAdapting the checklist to a third party public API

Tuesday · 15 minDevelop a test checklist based on the threat model
Tuesday · 15 minFrom modeling to test plans — a practical and practical bridge
Monday · 15 minVisual summary — Mental map of the concepts seen
Monday · 15 minVarying the scoring on an e-commerce API
September 18 · 15 minHeuristics to prioritize corrections and tests
September 18 · 15 minScore previous threats with OWASP Risk Rating
September 17 · 15 minOWASP Risk Rating Methodology — probability vs impact
September 16 · 15 minMap the Blog's attack surface
September 15 · 15 minAttack surface — definition and identification
September 15 · 15 minAdapting the principles to a file upload microservice
September 14 · 15 minCase study — Incident due to the absence of Least Privilege
September 11 · 15 minEvaluate the Blog against the principles of secure design
September 11 · 15 minSecure Design Principles — Least Privilege & Defense in Depth
September 10 · 15 minRed thread — Building a complete threat matrix for the Blog