Consider reading the following links for more information:
- US CERT WhiteBox Testing: https://www.us-cert.gov/bsi/articles/best-practices/white-box-testing/white-box-testing.
- Security Code Scan – static code analyzer for .NET: https://security-code-scan.github.io/
- SEI CERT Coding Standards: https://wiki.sei.cmu.edu/confluence/display/seccode/SEI+CERT+Coding+Standards.
- Find Security Bugs: http://find-sec-bugs.github.io/.
- DevBug is an on-line PHP secure code analysis (SCA): http://www.devbug.co.uk/.
- MITRE Secure Code Review: https://www.mitre.org/publications/systems-engineering-guide/enterprise-engineering/systems-engineering-for-mission-assurance/secure-code-review.
- MITRE Cyber Threat Susceptibility Assessment: https://www.mitre.org/publications/systems-engineering-guide/enterprise-engineering/systems-engineering-for-mission-assurance/cyber-threat-susceptibility...