.NET Code Security Checker

I am looking for a utility that can be used against .NET compilers to test code using best practices and, most importantly, can analyze code for security vulnerabilities, injection and cross-site scripting. I know that this is not an exact science, but I am looking for any experience / recommendations on the best solution that will at least set a basic standard. I know that nothing can compare with an individual review, but I look at a high level.

I did some Fortify research, and still it looks like a good tool, from what I can say it gives a very detailed answer. I know that FXCop is there too, but I don’t know if it goes deep enough.

EDIT One of the attractive things I've found about Fortify, and that would be nice in the tool, is a combination of a security review and a review of the best .NET applications. IE strengthens checks for potential unblocked connections, recommends using usage statements, etc.

+7
source share
2 answers

FxCop is a tool for analyzing static code, although it is not specifically aimed at security, it will find many common errors (be sure to turn off the naming rules that you are not interested in).

Also, I came across the "Performance Code Verification Tool - Practice Verification Tool" here .

+2
source share

We have licenses for Ounce for development, and I heard a lot about SpiDynamics for testing post-Soviet applications.

0
source share

All Articles