Secure Code Review helps identify vulnerabilities in source code of the application during the development phase and allows organizations to fix and address those identified issues before deploying to the real world. ECQ’s DRAMA code review approach offers both static and dynamic code analysis together with exploitation or Proof-of-Concept where possible to provide better severity rating for the vulnerable code block.

DRAMA code review approach contains five different phases: Define, Recon, Analyze, Manual Review, and Advise.

D
Define
R
Recon
A
Analyze
M
Manual Review
A
Advise
1
Define
2
Recon
3
Analyze
4
Manual Review
5
Advise

ECQ works with customer to define the scope of work and gain an overall understanding of the target application such as the type of application, business purpose, the programming languages, and lines of code (LoC). ECQ Consultants also advise the methodology and framework to be used depends on the requirements and scope of work.

Example frameworks used by ECQ for code review service include OWASP Testing Guide V4.2 for Dynamic Application Security Testing (DAST), OWASP Top 10, and OWASP Code Review 2 for Static Application Security Testing (SAST)

Page 01
Define