DevSecOps Guide
DevSecOps Guide
This is a guide of tools and resources to DevSecOps and Application Security professionals. In this guide the different tools and resources are provided with tags. In addition, a subjective evaluation is made (from 1 to 5 stars).
[!IMPORTANT]
The raiting is based on my work experience evaluating the tool, the use in the AppSec comunity and different parameters that I consider relevant (pricing, % of false positives, innovation…)
Tools
Static Application Security Testing (SAST)
Fortify 



Checkmarx 



Veracode 



Kiuwan 



Snyk Code 



Sonarqube 


Semgrep 


Bearer 


Bandit 

Brakeman 

FindSecBugs 
DevSkim 

Insider 
MobSF 


LuaSec 

GoSec 

Progpilot 
Software Composition Analysis (SCA)
Snyk Open Source 



Dynamic Application Security Testing (DAST)
Secret detection
Container Static Security Analysis
Container Runtime Security
Infraestructure-as-Code Security Analysis (IaC Security Analysis)
Application Security Posture Management (ASPM)
Runtime Application Security Testing (RASP)
Cloud Security Posture Management (CSPM)
API Security
Threat Modelling
Security vulnerability fixers
Learning Secure Application Development platforms
Resources
Formation & Certifications
Security vulnerability fix
Tags