Burp Suite User Forum

Create new post

Static Application Security Testing

Ed | Last updated: Oct 01, 2018 07:43PM UTC

Our team has been discussion implementing SAST for our PHP code to help identify issues earlier in the development cycle. Would please provide a "How To", diagram, helpful hints etc on how we would accomplish this task? It would be great if we could integrate with our ticket, and continuous integration engines as well.

PortSwigger Agent | Last updated: Oct 02, 2018 09:24AM UTC

Burp is primarily a DAST tool - it works by injecting attacks into a running application. A SAST tool works by analysing source code. The Burp Enterprise has support for integration with CI systems. There's more information here: - https://portswigger.net/blog/enterprise-edition-ci-integration Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.