This is a walkthrough on configuring application in ThreadFix to take advantage of ThreadFix's Hybrid Analysis Mapping (HAM) capabilities

Introduction

This walkthrough on configuring application in ThreadFix to take advantage of ThreadFix's Hybrid Analysis Mapping (HAM) capabilities allows for interactions such as:

Supported Languages and Frameworks for ThreadFix Hybrid Analysis Mapping (HAM)

Hybrid Analysis Mapping current works for:

Support for additional languages and frameworks is planned. Source code can be imported from git repositories, subversion repositories or from local or network folder locations with additional source code access methods planned.



Setting up an application to take advantage of HAM involves pointing ThreadFix toward the source code and (optionally) telling ThreadFix what language and framework the application uses:

The fields are as follows:

Providing ThreadFix with access to the application source code will allow the server to perform a lightweight static analysis of the source code and build an internal database of the application's attack surface and the source code elements responsible for each piece of attack surface. This attack surface database allows for the advanced interactions both inside of ThreadFix and with external tools that was mentioned above.