Главная
Study mode:
on
1
Intro
2
Audience Poll
3
Agenda
4
Netflix Application Security
5
Netflix Security Challenges
6
Proactive Security
7
Matured Program
8
Terminology
9
Demo
10
Metadata
11
Configurable columns
12
New task types
13
Task groups
14
Events
15
Open Source
16
Demos
17
Bulk Add Results
18
Identify Secret in HTML Response
19
Scumblr Event Log
20
Github Easter Egg
21
GitHub Search
22
Chaining
23
Results
24
Using Events
25
Creating vulnerabilities manually
26
Metadata search
27
Why does this approach work
28
We are hiring
Description:
Explore how Netflix tackles application security challenges in this AppSecUSA 2016 conference talk. Learn about Scumblr, an open-source tool developed by Netflix to address asset management, risk assessment, and vulnerability detection in their dynamic cloud environment. Discover how Scumblr has evolved from its initial focus on external intelligence gathering to become a versatile platform for tracking endpoints, application risk profiles, and vulnerabilities across thousands of applications. Gain insights into the tool's architectural changes, new plugins, and integrations with Arachni, AppSpider, and Github. Understand how to replicate Netflix's approach to automation, data collection, and analysis in your own security practices. Presented by Scott Behrens and Andrew Hoernecke, senior application security engineers at Netflix, this talk covers Scumblr's latest uses, including vulnerability management and application risk tracking, and demonstrates how to create custom integrations for enhanced security automation. Read more

Cleaning Your Applications' Dirty Laundry with Scumblr

OWASP Foundation
Add to list
0:00 / 0:00