Code auditing — topics
Source-review notes for PHP, Java, and ASP.NET stacks. See code-auditing for ordering.
Methodology
- source-sink-flow-analysis
- ssrf-source-sink-flow
- whitebox-to-exploit-methodology
- auth-bypass-from-source-review
- second-order-injection-chains
- blind-vuln-confirmation-from-source
- debugger-driven-source-review
PHP
Java
ASP.NET / .NET Core
Node.js / JavaScript
Python
Ruby
Go
Rust
Framework patterns
- spring-boot-audit-patterns
- django-audit-patterns
- laravel-audit-patterns
- rails-audit-patterns
- express-nestjs-audit-patterns
Framework deep dives
Supply chain and secrets
- npm-postinstall-and-typosquat-audit
- python-pypi-supply-chain-audit
- go-module-substitution-audit
- secrets-in-code-detection-patterns
AppSec discipline
- appsec-threat-modeling
- sast-dast-ci-integration
- authorization-patterns-rebac-abac
- appsec-maturity-checklist
Threat modelling deep
- threat-modelling-stride-deep
- threat-modelling-pasta
- threat-modelling-linddun-privacy
- attack-tree-methodology
DevSecOps platform / culture
- devsecops-platform-engineering
- paved-road-pattern-platform
- appsec-champions-program
- sast-dast-iast-vendor-selection
- sbom-and-software-supply-chain-attestation