DAST/SAST integration with ModSecurity
Kyle Richard Orlando <[email protected]> Wed, 24 Feb 2021 13:23:42 +0000
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <OL1P279MB0225EACC8DCDD1D2B911A950989F9@OL1P279MB0225.NORP279.PROD.OUTLOOK.COM> |
Hi, Is anyone aware of any attempts to integrate ModSecurity with either a SAST or DAST? I figured it would be more common, but I've only seen DAST integration mentioned in a couple of Ryan Barnett's articles from 2012: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-advanced-topic-of-the-week-automated-virtual-patching-using-owasp-zed-attack-proxy/ https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/dynamic-dastwaf-integration-realtime-virtual-patching/ They mention a couple of Perl scripts, which I was able to find here: https://github.com/coreruleset/coreruleset/tree/v3.4/dev/util/virtual-patching I'm also a quite curious about how these scripts came about and how effective they are (I'm currently testing out the ZAP one). Thanks, Kyle _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/