Avi Douglen

18.6K posts

Avi Douglen banner
Avi Douglen

Avi Douglen

@sec_tigger

'Cuz AppSec is what Tiggers do best! Value driven consulting @BounceSecurity. @owasp BoD, @OWASP_IL, #TM, @StackSecurity moderator. He/Him. +5 kids👩‍👩‍👧‍👦

Israel เข้าร่วม Kasım 2010
727 กำลังติดตาม1.7K ผู้ติดตาม
ทวีตที่ปักหมุด
Avi Douglen
Avi Douglen@sec_tigger·
I was so honored to deliver the closing keynote at @BSidesTLV - and now the recording is available! Thanks so much to the organizers and CFP crew that agreed for me to share this with the community. youtube.com/watch?v=CnGt-o…
YouTube video
YouTube
English
5
6
19
0
Avi Douglen รีทวีตแล้ว
OWASP® Foundation
🚨 Keynote Speaker Alert! 🚨 Gadi Evron, Founder & CEO of Knostic, joins Global AppSec Vienna 2026 with his keynote: “We Live in the Future: The Death and Rebirth of Application Security.” owasp.glueup.com/event/owasp-gl… A must-see session on the future of AppSec, AI, and cybersecurity. #OWASP #AppSec
OWASP® Foundation tweet media
English
0
4
6
1.1K
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 5th example where we take the units produced by a @KnosticAI OpenAnt scan and scan those units individually for vulnerabilities. youtu.be/pALxeunbH7s
YouTube video
YouTube
English
1
2
3
1K
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced. youtu.be/k-CqAsOicA4
YouTube video
YouTube
English
0
1
1
119
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 4th example takes a SARIF file simulating some generic SAST results and evaluates each finding to decide if it is a false positive. youtu.be/I3b2Cn87ugg
YouTube video
YouTube
English
0
2
1
116
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 3rd example which doesn't use AI at all but rather just a custom written static rule to find exposed API endpoints without authentication decorators. youtu.be/2P8yAWRJSLk
YouTube video
YouTube
English
0
2
2
105
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 2nd video is a hybrid check using a static @Semgrep rule to find uses of a sensitive function and an AI prompt on each use to check for correct validation. youtu.be/rjYegEg6dx0
YouTube video
YouTube
English
0
2
1
130
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. There is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced. youtu.be/k-CqAsOicA4
YouTube video
YouTube
English
0
1
1
78
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
After that, at @BlackHatEvents #BHUSA in Las Vegas in August: 3/n x.com/i/status/20371…
Josh Grossman 👻 (tghosth)@JoshCGrossman

Sign-up today for my new training course with content exclusive to @BlackHatEvents! "Achieving Scalable Code Security Scanning through AI Acceleration" dives into the newest ways to validate code security, emphasizing AI acceleration Register: #achieving-scalable-code-security-scanning-through-ai-acceleration-50694" target="_blank" rel="nofollow noopener">blackhat.com/us-26/training… #BHUSA

English
1
3
2
1.9K
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
First up in Vienna, Austria in June at @OWASP Global AppSec Vienna: 2/n x.com/i/status/20359…
Josh Grossman 👻 (tghosth)@JoshCGrossman

Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuvienna20.sched.com/event/2EB8l

English
1
2
2
73
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
You currently have TWO opportunities to sign up for my brand new training course about building repeatable, scalable, and, automateable code security scanning. The courses feature @BounceSecurity's new open source framework, AGHAST. Don't delay, sign up today! 1/n
Josh Grossman 👻 (tghosth) tweet mediaJosh Grossman 👻 (tghosth) tweet mediaJosh Grossman 👻 (tghosth) tweet media
English
1
2
3
127
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
What it will do is give you a framework to take your suspicions about what vulnerabilities might exist and turn them into repeatable, scalable, and automatable validations you can run across your codebases, returning results in a structured format. 3/4
English
1
1
1
58
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
AGHAST (AI-Guided Hybrid Application Static Testing) won't automatically scan your repositories and find all your vulnerabilities. 2/4
English
1
1
1
50
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
Today, we are releasing AGHAST, an open source framework that combines static discovery with AI prompts to find repository-specific and company-specific security issues for accurate and economical analysis. 1/4
Josh Grossman 👻 (tghosth) tweet media
English
1
4
8
657
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
Introducing AGHAST: AI-Guided Hybrid Application Static Testing
English
1
3
8
1K
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
Everyone in this industry is losing their minds, like we never knew vulnerabilities existed before. Look out for an upcoming tool release, that uses what you already know and turns your suspicions into validations.
English
1
1
4
163
Avi Douglen รีทวีตแล้ว
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
Sign-up today for my new training course with content exclusive to @BlackHatEvents! "Achieving Scalable Code Security Scanning through AI Acceleration" dives into the newest ways to validate code security, emphasizing AI acceleration Register: #achieving-scalable-code-security-scanning-through-ai-acceleration-50694" target="_blank" rel="nofollow noopener">blackhat.com/us-26/training… #BHUSA
Josh Grossman 👻 (tghosth) tweet media
English
0
1
1
2K
Avi Douglen รีทวีตแล้ว
OWASP Israel
OWASP Israel@OWASP_IL·
💎💎💎💎💎💎💎💎💎💎💎💎💎💎💎 This year’s diamond sponsor is: @MinimusIO! 💎💎💎💎💎💎💎💎💎💎💎💎💎💎💎 2/5
OWASP Israel tweet media
English
1
1
1
32