denimgroup / threadfix

ThreadFix is a software vulnerability management platform. This GitHub site is far out of date. Please go to www.threadfix.it for up-to-date information.
340 stars 127 forks source link

Pre-defined Global Filters #442

Open stevespringett opened 10 years ago

stevespringett commented 10 years ago

I would be a nice addition to have pre-defined filters for certain things. For example, the OWASP Top Ten specifies 'Broken Authentication and Session Management'. This category of vulnerability has many CWE's. Having a pre-defined set of global filters would be extremely helpful.

stevespringett commented 10 years ago

CWE 929 - 938 (and all children) provide mappings to OWASP Top 10. The SANS list is here: http://www.sans.org/top25-software-errors/