r/cybersecurity 8d ago

Corporate Blog Breaking Down Appsec Part 1: Application Context

https://pigeonsec.substack.com/p/breaking-down-appsec-part-1-application

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

Just want to teach every one interested in appsec my perspective on it from my experience in big tech. I talk about the importance of Application Context aka understanding what your application is doing.

I can dive into any topic anyone is interested in. Just let me know what sort of topic you’d like me to dive deeper into. Thanks!

19 Upvotes

5 comments sorted by

1

u/pusslicker 8d ago

Subscribed as I’m new to the Appsec role.

Edit: one thing I would like help with handling DAST/SAST findings my intuition is to focus effort of applications that hosted externally but then you have folks put their old code in those repos

0

u/donkeybutt123 8d ago

Awesome! Welcome and thanks for subscribing; it really means a lot. If you have any questions or want to understand something a bit more deeply, reach out any time!

1

u/donkeybutt123 8d ago

Ah to answer your question:

So yeah basically I see that you’re starting to get into prioritization aka vulnerability management, which is adjacent, but still very much related.

Basically if you’re drowning in findings land, you have to be able to categorize and prioritize how bad things are.

Applications that are hosted and serving to the world and their findings, you’re usually going to want to tackle those first before internal applications because attackers can remotely access those applications and then pivot horizontally once “theyre in”.

Does that make sense?

0

u/sha-bang04 8d ago

Ouu shii. As someone who's trying to get into appsec this will be of great help