DAST/SAST integration with ModSecurity

Kyle Richard Orlando <[email protected]> Wed, 24 Feb 2021 13:23:42 +0000
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <OL1P279MB0225EACC8DCDD1D2B911A950989F9@OL1P279MB0225.NORP279.PROD.OUTLOOK.COM>
Hi,

Is anyone aware of any attempts to integrate ModSecurity with either a SAST or DAST? I figured it would be more common, but I've only seen DAST integration mentioned in a couple of Ryan Barnett's articles from 2012:
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-advanced-topic-of-the-week-automated-virtual-patching-using-owasp-zed-attack-proxy/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/dynamic-dastwaf-integration-realtime-virtual-patching/

They mention a couple of Perl scripts, which I was able to find here:
https://github.com/coreruleset/coreruleset/tree/v3.4/dev/util/virtual-patching

I'm also a quite curious about how these scripts came about and how effective they are (I'm currently testing out the ZAP one).

Thanks,
Kyle

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/