Feel free to discuss any topics relating to cybersecurity with the rest of the security community in this forum.
Fortify vs checkmarx
- o_icemanssl22
- Offline
- Premium Member
- Posts: 142
- Thank you received: 0
There is commercial and open source tools available. Depend on your needs and budget I guess.
Open source:
Google CodeSearchDiggity
FxCop
FindBugs
RATS
OWASP SWAAT Project
Please Log in or Create an account to join the conversation.
- o_34jonston
- Topic Author
- Offline
- Junior Member
- Posts: 37
- Thank you received: 0
thanks icemanssl22. have u used these tools b4? which one is good?
Please Log in or Create an account to join the conversation.
try fortify, it's one of the best in the market.
Please Log in or Create an account to join the conversation.
- o_icemanssl22
- Offline
- Premium Member
- Posts: 142
- Thank you received: 0
Hi 34jonston, I?ÿuses Google CodeSearchDiggity and FxCop for .net. Pretty good and meet my objective.
Guess it also depend on your target size, complexity and goal.
Please Log in or Create an account to join the conversation.
- o_Akash Desai
- Offline
- New Member
- Posts: 1
- Thank you received: 0
I evaluated both products a few months ago. While performance is similar in many areas, I can say for sure that Checkmarx is more user friendly and our developers prefer it over Fortify. The fact it can scan un-compiled source code is useful and the ability to fine tune the scan rules allowed us to minimize false positives to a few % which I consider negligible. Another important factor - ?ÿI found the Checkmarx support team to be more responsive.
Please Log in or Create an account to join the conversation.
- o_34jonston
- Topic Author
- Offline
- Junior Member
- Posts: 37
- Thank you received: 0
Scan un-compiled source code meaning I do not pass through all the codes and library files thru the scanner? That's interesting cos I heard fortify need everything to be compiled before u can run the scan.
Please Log in or Create an account to join the conversation.