What 200 SAST Triage Sessions Taught Me About Application Security
There’s a pattern in security tooling that I’ve seen across multiple roles, multiple products, and multiple organizations. The team buys the SAST tool. The first scan runs. The report comes back with somewhere between 200 and 2,000 findings. Somebody, usually me or somebody like me, sits down to triage them.
The first triage takes a long time. The second triage is shorter. By the tenth triage, you start to recognize the patterns, the same five rules that produce the same five categories of finding, the same false-positive shapes, the same handful of real issues mixed in.
I haven’t counted exactly, but I’ve sat through somewhere around 200 SAST scan triages over the past decade. I want to share what I actually found in those scans. Not what the marketing decks say SAST tools find. What the scans, in production codebases, with real engineering teams, were actually telling us.
This is...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE