OWASP Demo Lab - Hands-On Workshop / Small Group SessionZone 1Internal development teams and external suppliers love producing binaries for ease of deployment and distribution. Binary formats, however, make security analysis and compliance more complex for the security and OSPO teams. The good news is that the team behind
OWASP dep-scan maintains a couple of binary analysis tools (
OWASP blint and
OWASP dosai). We show how these two tools can help defenders find strange things in binaries and help with your software transparency journey.
The session will be technical showcasing blint and dosai to analyse complex binaries to identify capabilities, risks, and threats. Users can walk away with new knowledge about modern techniques related to binary SBOM generation, Source line to Assembly instruction mapping, security capabilities analysis, and more.
https://github.com/owasp-dep-scan/blinthttps://github.com/owasp-dep-scan/dosai