
technologyFeb 5, 202545:56pending
Automating Dynamic Application Security Testing at Scale
About this episode
In this episode of The BlueHat Podcast, hosts Nic Fillingham and Wendy Zenone are joined by Jason Geffner, Principal Security Architect at Microsoft, to discuss his groundbreaking work on scaling and automating Dynamic Application Security Testing (DAST). Following on from his BlueHat 2024 session, and outlined in this MSRC blog post, Jason explains the key differences between DAST, SAST, and IAST, and dives into the challenges of scaling DAST at Microsoft’s enterprise level, detailing how automation eliminates manual configuration and improves efficiency for web service testing.
In This Episode You Will Learn:
Overcoming the challenges of authenticated requests for DAST tools
The importance of API specs for DAST and how automation streamlines the process
Insights into how Microsoft uses DAST to protect its vast array of web services
Some Questions We Ask:
What's a lesson from this work that you can share with those without Microsoft's resources?
Can you explain what the transparent auth protocol is that you mentioned in the blog post?
How is your work reducing the manual effort needed to configure DAST system services?
Resources:
View Jason Geffner on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Blog Post: Scaling Dynamic Application Security Testing (DAST) | MSRC Blog
Related BlueHat Session Recording: BlueHat 2024: S10: How Microsoft is Scaling DAST
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get every episode summarized
Each time The BlueHat Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The BlueHat Podcast

Hunting Variants: Finding the Bugs Behind the Bug
The BlueHat Podcast
Jul 9, 202539:00pending

Securing Redirections with Mike Macelletti
The BlueHat Podcast
Jun 25, 202542:02pending

Ignore Ram Shankar Siva Kumar’s Previous Directions
The BlueHat Podcast
Jun 11, 202539:54pending

Protecting AI at the Edge with David Weston
The BlueHat Podcast
May 28, 202539:15pending