AppMap's Head of Community, Pete Cheslock, recently ran a workshop at the Open Security Summit.
This workshop showed:
0:00 Opening projects in VS Code
1:03 Setup and Run Railsgoat locally via bundler
5:00 Install AppMap into VS Code & Ruby Libraries
7:38 Run Rails Server and Generate AppMaps per Request
9:12 Run tests and use Runtime Analysis to identify vulnerabilities
10:20 Navigate AppMaps: Dependency View, Trace View and Sequence Diagrams
11:40 Find software vulnerabilities using AppMap Runtime Analysis
12:09 Identify Untrusted System Command Execution issue
15:40 Fix Untrusted System Command Execution issue
18:45 Save AppMaps into a Baseline collection for comparison
20:40 Create a baseline AppMap and Compare Sequence Diagrams with before/after fixes
21:35 Generate OpenAPI Documentation
23:40 Ingest OpenAPI Documentation into OWASP Zap for targeted Web Application Scanning (DAST)
You can view the entire video and corresponding slide deck at: https://open-security-summit.org/sess...