The document explores the benchmarking of web application scanners, emphasizing the importance of coverage, low false positives, and low false negatives in achieving effective scans. It highlights the need for organizations to train scanners properly to access all URLs and collect accurate vulnerability data. The presentation also introduces Threadfix as a management system for vulnerability aggregation and offers insights into common weaknesses and reporting standards.
Related topics: