PS Product SecurityKnowledge Base

Application Security

Application Security

Section focus: Application Security.
Best use: start with the section map below, then move into the deeper pages that match your role or stack.
Design note: this index was refreshed to act as a cleaner GitBook landing page instead of a plain directory listing.

Start with these pages

Page Why open it first
SAST Noise Reduction High-value page inside Application Security.
๐Ÿฅ‹ DefectDojo and ASPM Platforms High-value page inside Application Security.
๐Ÿงญ ASOC and ASPM Orchestration Platforms High-value page inside Application Security.
๐Ÿ” Repository Secret Scanning High-value page inside Application Security.
๐Ÿ”Ž TruffleHog and Gitleaks Deep Dive High-value page inside Application Security.
GitHub and GitLab Native Secret Scanning Comparison High-value page inside Application Security.
๐Ÿ“ฑ Mobile Application Security Testing High-value page inside Application Security.
๐Ÿงฑ Secure by Design for AppSec and SDLC High-value page inside Application Security.
๐Ÿ—๏ธ Web Application Security Architecture โ€” Practical Intro Architecture-first onboarding page for reviewers who need the component map before the bug list.
๐Ÿง  Business Logic Vulnerabilities and Verification Explains application-level workflow flaws, how to verify them, and how to connect them to real product abuse.
๐Ÿ”Š SonarQube Modern Practical Guide โ€” Quality Gates, Security Hotspots, PR Analysis, and Review Workflows Modernizes the 2014 SonarQube mental model into a 2026 AppSec operating guide.
๐Ÿงญ Burp Suite vs OWASP ZAP โ€” Practical Positioning Helps teams choose between analyst-first Burp workflows and automation-first ZAP workflows.
๐Ÿงช Mobile Report Analysis and Finding Walkthrough High-value page inside Application Security.

  • modern SonarQube positioning for SAST, hotspots, and review workflows
  • practical Burp versus ZAP decision guidance
  • architecture-first onboarding for modern web applications
  • scanner signal quality and secret detection
  • mobile application security testing
  • cross-links into CI/CD quality gates and newer architecture, abuse, and secure-engineering sections

Intro: This section stays close to product-facing security work: scanner signal quality, findings management, secret scanning, mobile security testing, and the orchestration layer that helps teams make release decisions without drowning in tool output.

What this page includes

  • vulnerability orchestration and posture tooling

๐Ÿงช Core pages in this section


Author attribution: Ivan Piskunov, 2026 - Educational and defensive-engineering use.