SWAMPs in the cloud and ground
Andrew Freeborn
1
• The SWAMP
• What’s it like in the cloud?
• Can I have a SWAMP in a box?
• Demo!
Agenda
2
• Software Assurance Marketplace
• https://www.mir-swamp.org/
• Scans C, C++, Java, Ruby, Python, Android
apps, and more!
• Checks source code for problems and gives you
a report with a variety of tools
• FREE
The SWAMP
3
• The SWAMP in the cloud has lots of capability to
scan all kinds of packages you want
• Performs decently with short wait times
• You can have your application scanned on
various platforms like Red Hat, Ubuntu, etc
• Lots of tools available such as gcc, Clang, and
linters
The SWAMP cloud
4
• Now you can have the SWAMP on-premise
• https://continuousassurance.org/swamp-in-a-box/
• Minimum: 12GB RAM, 256GB HD, 4 cores
• Not all tools are available, but you still get Code Dx
• You can tune the SWAMP to your specific use
cases, but then you have to manage things
• Still free
SWAMP in a box
5
• SWAMP
• https://www.mir-swamp.org
DEMO
6
• vivirytech@gmail.com
• https://vivirytech.blogspot.com
• Twitter: @vivirytech
Thanks!
7

More Related Content

PPTX
Augmented Reality For Processing
PPTX
Intro to Codefresh YAML
KEY
Migrating big data
PDF
Hacklu2011 tricaud
PPTX
Laverna vs etherpad
PDF
Nats.io meetup october 2015 - Community Update
PPTX
The Road to Kubernetes
PPTX
Docker Security
Augmented Reality For Processing
Intro to Codefresh YAML
Migrating big data
Hacklu2011 tricaud
Laverna vs etherpad
Nats.io meetup october 2015 - Community Update
The Road to Kubernetes
Docker Security

What's hot (19)

PPTX
Reinventing anon email
PDF
PyConIT 2018 Writing and deploying serverless python applications
PPTX
Blue Teaming on a Budget of Zero
PDF
FOSDEM 2021 - Infrastructure as Code Drift & Driftctl
PPTX
BSides Algiers - Layer7 DoS Attacks - Oussama Elhamer
PDF
PDX Serverless Meetup - Self-Healing Serverless Applications
PPTX
Daily AWS Issues
PDF
Web Crypto
PDF
10 Things you should know about Ruby
ODP
AllDayDevOps ZAP automation in CI
ODP
Testing at-cloud-speed sans-app-sec-austin-2013
ODP
RSYSLOG v8 improvements and how to write plugins in any language.
ODP
Open Source Monitoring Tools Shootout
PPT
nanog
PPTX
OTP, Concurrency and Testing Strategies
ODP
Introduction to ethereum_public
PPTX
Nsa and vpn
PDF
Sullivan white boxcrypto-baythreat-2013
ODP
OWASP 2013 APPSEC USA ZAP Hackathon
Reinventing anon email
PyConIT 2018 Writing and deploying serverless python applications
Blue Teaming on a Budget of Zero
FOSDEM 2021 - Infrastructure as Code Drift & Driftctl
BSides Algiers - Layer7 DoS Attacks - Oussama Elhamer
PDX Serverless Meetup - Self-Healing Serverless Applications
Daily AWS Issues
Web Crypto
10 Things you should know about Ruby
AllDayDevOps ZAP automation in CI
Testing at-cloud-speed sans-app-sec-austin-2013
RSYSLOG v8 improvements and how to write plugins in any language.
Open Source Monitoring Tools Shootout
nanog
OTP, Concurrency and Testing Strategies
Introduction to ethereum_public
Nsa and vpn
Sullivan white boxcrypto-baythreat-2013
OWASP 2013 APPSEC USA ZAP Hackathon
Ad

Similar to Omaha OWASP Dec 2016 (19)

PDF
Software Bill of Materials - Accelerating Your Secure Embedded Development.pdf
 
KEY
Cloud Security: Ten Things
PPTX
vBACD- July 2012 - Crash Course in Open Source Cloud Computing
PDF
Crash Course in Open Source Cloud Computing
PDF
Crash Course on Open Source Cloud Computing
PDF
Delivering Infrastructure-as-a-Service with Open Source Software
PPTX
vBACD - Crash Course in Open Source Cloud Computing - 2/28
PPTX
Build a Cloud Day SF - Crash Course on Open Source Cloud Computing
PDF
PHP Architect Virtual Cloud summit
PPTX
InfoSec 2011: Crash Course Open Source Cloud Computing
ODP
Why Cloud Computing has to go the FOSS way
PDF
FishEye - Source Code Explore and more - Brief
PPT
Good Security Starts with Software Assurance - Software Assurance Market Plac...
KEY
What is this cloud thing?
PPTX
Overview: Building Open Source Cloud Computing Environments
PDF
CLOUD COMPUTING: A REVIEW
PPTX
Linuxcon Europe 2011: Overview - Building Cloud Computing Environments
PDF
Open Source Tools and the Software Engineering Process
PDF
Open source and cloud computing
Software Bill of Materials - Accelerating Your Secure Embedded Development.pdf
 
Cloud Security: Ten Things
vBACD- July 2012 - Crash Course in Open Source Cloud Computing
Crash Course in Open Source Cloud Computing
Crash Course on Open Source Cloud Computing
Delivering Infrastructure-as-a-Service with Open Source Software
vBACD - Crash Course in Open Source Cloud Computing - 2/28
Build a Cloud Day SF - Crash Course on Open Source Cloud Computing
PHP Architect Virtual Cloud summit
InfoSec 2011: Crash Course Open Source Cloud Computing
Why Cloud Computing has to go the FOSS way
FishEye - Source Code Explore and more - Brief
Good Security Starts with Software Assurance - Software Assurance Market Plac...
What is this cloud thing?
Overview: Building Open Source Cloud Computing Environments
CLOUD COMPUTING: A REVIEW
Linuxcon Europe 2011: Overview - Building Cloud Computing Environments
Open Source Tools and the Software Engineering Process
Open source and cloud computing
Ad

Recently uploaded (20)

PDF
Architecture types and enterprise applications.pdf
PPTX
Modernising the Digital Integration Hub
PDF
Abstractive summarization using multilingual text-to-text transfer transforme...
PDF
UiPath Agentic Automation session 1: RPA to Agents
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
Five Habits of High-Impact Board Members
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PPTX
2018-HIPAA-Renewal-Training for executives
Architecture types and enterprise applications.pdf
Modernising the Digital Integration Hub
Abstractive summarization using multilingual text-to-text transfer transforme...
UiPath Agentic Automation session 1: RPA to Agents
Convolutional neural network based encoder-decoder for efficient real-time ob...
Getting started with AI Agents and Multi-Agent Systems
sustainability-14-14877-v2.pddhzftheheeeee
NewMind AI Weekly Chronicles – August ’25 Week III
Hindi spoken digit analysis for native and non-native speakers
Five Habits of High-Impact Board Members
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
The influence of sentiment analysis in enhancing early warning system model f...
CloudStack 4.21: First Look Webinar slides
OpenACC and Open Hackathons Monthly Highlights July 2025
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
A proposed approach for plagiarism detection in Myanmar Unicode text
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
1 - Historical Antecedents, Social Consideration.pdf
Taming the Chaos: How to Turn Unstructured Data into Decisions
2018-HIPAA-Renewal-Training for executives

Omaha OWASP Dec 2016

  • 1. SWAMPs in the cloud and ground Andrew Freeborn 1
  • 2. • The SWAMP • What’s it like in the cloud? • Can I have a SWAMP in a box? • Demo! Agenda 2
  • 3. • Software Assurance Marketplace • https://www.mir-swamp.org/ • Scans C, C++, Java, Ruby, Python, Android apps, and more! • Checks source code for problems and gives you a report with a variety of tools • FREE The SWAMP 3
  • 4. • The SWAMP in the cloud has lots of capability to scan all kinds of packages you want • Performs decently with short wait times • You can have your application scanned on various platforms like Red Hat, Ubuntu, etc • Lots of tools available such as gcc, Clang, and linters The SWAMP cloud 4
  • 5. • Now you can have the SWAMP on-premise • https://continuousassurance.org/swamp-in-a-box/ • Minimum: 12GB RAM, 256GB HD, 4 cores • Not all tools are available, but you still get Code Dx • You can tune the SWAMP to your specific use cases, but then you have to manage things • Still free SWAMP in a box 5