How can I see all the rules of Fortify Secure Coding Rules?
Asked Answered
C

3

7

I want to see the specific rules of Fortify Secure Coding Rules (the rules that Fortify uses by default), because I want to write a report about all rules that are used by Fortify:

  • I have tried to see them in C:\Program Files\Fortify Software\HP Fortify v3.60\Core\config\rules but I have found .bin files and I can't see them.
  • I also have opened AuditWorkbench and in Security Content Management I can't see them either.

Is there any way to see them?? Thanks for your help.

Ctesiphon answered 14/1, 2013 at 13:28 Comment(0)
D
4

Short of becoming a Software Engineer at HP Fortify, No. The default rules are considered Intellectual Property of HP Fortify and no one outside Engineering has access to them.

What problem are you trying to solve by this report?

Dawnedawson answered 14/1, 2013 at 14:4 Comment(1)
Amm ok!! The idea was to scan a project and generate a report with the auditworkbench for example. However, in another report put the information that I have generated a report of this project thanks of Fortify with this rules... etc. So, I will write that I used the default rules. Thanks!!Ctesiphon
L
1

As HP/Fortify distributes rule-packs as binary files to protect their intellectual property, you will not be able to see how the individual rules are written.

However, if you're looking to include some information about which rules/rule-packs were used, you can navigate to the project summary screen and see which rule packs were used at the time of the scan. You will also have access to information such as each rule pack's version and additional meta data about each pack.

Being able to provide this level of detail in a meta-report might be sufficient to preempt follow-up questions. Just a thought...

Letterpress answered 14/1, 2013 at 18:8 Comment(0)
M
0

The built in Fortify rules are not available to read and edit since it's the core intellectual property of the tool.

However, Fortify has published a taxonomy of what vulnerabilities are scanned, and their mapping to CWE:s. The link is here: https://vulncat.fortify.com/en/weakness

Minotaur answered 3/2, 2022 at 12:3 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.