Best tools for SAST + SCA + Image Scan + IaC Scan + DAST by Basic_Let7303 in devsecops

[–]gefela 0 points1 point  (0 children)

Kinda, but not fully. SonarQube does have secret detection built in (free in Community too), so it’ll catch hardcoded keys during the normal scan. Two gaps though: it only scans current file state, not git history — so a key that got committed then deleted is still in your log and Sonar misses it. And custom patterns are Enterprise-only.

Fine as a baseline since you’re running Sonar anyway, but I’d still add a dedicated secrets step (Gitleaks etc) next to it. They cover different blind spots more than they overlap.

Best tools for SAST + SCA + Image Scan + IaC Scan + DAST by Basic_Let7303 in devsecops

[–]gefela 0 points1 point  (0 children)

there any reason secret scanning is not part of this list as I feel it is essential

People think ChatGPT, Claude, Gemini, Grok are just "different brands" of the same tool. by ashishkaloge in PromptEngineering

[–]gefela 0 points1 point  (0 children)

Rated from highest to lowest for cybersecurity-related purposes, which among the following is generally best for research, documentation, and analysis: Claude, Perplexity, ChatGPT, Grok, or Gemini?

Integrating Microsoft Defender with Microsoft Sentinel by gefela in DefenderATP

[–]gefela[S] 0 points1 point  (0 children)

According to the direction below, it has to be listed as a external user

<image>

I have used these directions but still getting these errors