Learn. Research. Get Secure.

Browse through the materials below to improve your knowledge of Application Security.

Top 5 Most Popular Resources

  • The State of Software Security Report Volume 5
    Our latest release in this semi-annual report series, This report pulls data from tens of thousands of live application scans performed on the Veracode Platform. The report outlines the top vulnerabilities found in web, mobile and internal applications written various programming languages.  
  • The State of Software Security Report - Feature Supplement on Enterprise Testing of Software Supply Chain
    This featured supplement focuses on the state of enterprise programs that assess the security of software purchased from vendors. Veracode can uniquely report on how program practices evolve because our analysis is based on data aggregated from companies as they test real applications. 
  • Gartner Magic Quadrant Report for DAST
    Veracode has been positioned as a Visionary in Magic Quadrant for Dynamic Application Security Testing. In this Magic Quadrant, Gartner analyzes the evolution of the static application security testing market, and evaluates its vendors according to their business and technology vision, as well as their ability to execute against that vision in their products and services.
  • Gartner Magic Quadrant Report for SAST
    Veracode has been positioned as a leader in Magic Quadrant for Static Application Security Testing.
  • Veracode: Preparing and Submitting Your Application
    View the demo of Veracode's Platform. Learn how to create an Application Profile and Submit your application for analysis.

Veracode Research Report

  • The State of Software Security Report
    View and download the the latest Veracode Report on the State of Software Security. This semi-annual report is the most comprehensive of its kind because it draws on the continuously updated information resident in Veracode’s unique cloud-based application risk management services platform.  The data represents intelligence gleaned from the analysis of more than 55 billion lines of code and thousands of applications.  It is growing every minute as more organizations come to Veracode for independent verification of the security quality of their software. 

Webinars

  • Understanding the Latest Security Threats
    Join Brian LaFlamme, Veracode's Director of Solutions Enablement, as he discusses best practices for integrating security testing into the development lifecycle.
  • Weekly Veracode Platform Demo
    Please join us for a live demonstration of Veracode's on-demand application testing solution. This demostration will utilize the Veracode web-portal and we will walk through actual testing scenarios and results followed by a Q&A session.
  • Security Tools

    • SmartShare
      Our smart social sharing widget allows users to share your content across four popular social networks; Facebook, Twitter, Linkedin and Google +, it also includes an email share function for your socially disinclined peers. The widget will also display a share count for each network on your website page.

    Demonstrations

    • Product Demonstration
      View the demo of Veracode SecurityReview - the standard for on-demand application security testing. The 5 minute demo, in flash format, provides a narrated guide to various aspects of Veracode's On-Demand Assurance Platform.
    • e-Learning Demo
      View this demo of Veracode eLearning integrates a security knowledge base and web-based secure programming training courses for developers and security personnel to meet formal training and testing requirements.

    Whitepapers

    • Anti-Debugging – A Developers View
      Anti-debugging is the implementation of one or more techniques within computer code that hinders attempts at reverse engineering or debugging a target binary. Within this paper we will present a number of the known methods of antidebugging in a fashion that is easy to implement for a developer of moderate expertise.
    • Protecting Your Organization from Application Backdoors
      This whitepaper discusses how binary (compiled code) analysis is the ideal platform for detecting backdoors and conducting the most complete independent security test, validation and verification of applications.

    Datasheets

    • SDLC SecurityReview
      Veracode's SDLC SecurityReview enables security teams to conduct security assessments on mission-critical internally developed applications before they ship.
    • COTS SecurityReview
      Veracode’s COTS SecurityReview provides enterprises with an independent security assessment of purchased commercial off-the-shelf software – stopping security risk before it enters the organization.

    Podcasts

    Security Threat Guides