Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Tool
BSides talks featuring OWASP ZAP
72
talks mention this tool across
42
BSides chapters.
Talks featuring OWASP ZAP
15:37
Tale of Chaining Bugs for Account Takeover
Harsh Bothra
BSides Ahmedabad
· 2022
Technical
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2023-02
1:05:00
You can't make web app security easy, but you can make it simple
Joseph McCray
BSides DC
· 2015
Technical
Web AppSec
Talk
Open →
2015-12
29:16
Damn GraphQL - Defending and Attacking APIs - Dolev Farhi
BSides Vancouver
Open →
2021-06
42:33
Web Application Vulnerability Scanners: An Introduction & Discussion on Their Limitations
Robert Feeney
BSides Cape Town
· 2019
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2019-12
32:37
The Automation Of Firmware-Analysis For IoT-Devices - Alexander Poth
BSides Munich
Open →
2019-03
10:48:30
BSides LV 2022 - Wednesday - Breaking Ground Track
BSides Las Vegas
Open →
2022-08
40:50
Building Burp Extensions
Jason Gillam
BSides Charleston
· 2015
Technical
Talk
Open →
2015-12
51:14
Continuous Security Testing in a DevOps World
Stephen de Vries
BSides London
· 2014
Technical
DevSecOps
Web AppSec
Demo
Talk
Open →
2014-05
6:18:25
Security BSides Athens 2022 — Live Stream Part 2
BSides Athens
· 2022
Technical
Talk
Open →
2022-06
57:55
Seriously? You Want Me To Believe Cyber-Spies Want My Data
BSides Detroit
Open →
2012-06
49:18
Aarti Gadhia: There is no security skills shortage!
Aarti Gadhia
BSides Calgary
Career
Talk
Open →
2020-12
27:11
Hacking with a Heads Up Display
David Scrobonia
BSidesSF
· 2019
Technical
Tooling
OWASP
Web AppSec
Talk
Open →
2019-03
16:43
Automation In Application Security
Javier Dominguez
BSides London
· 2019
Technical
Talk
Open →
2019-06
26:54
Introduction to OWASP Juice Shop
Tim Corless-Carter
BSides Manchester
· 2019
Technical
OWASP
Vulnerability Research
Web AppSec
Intro
Red
Demo
Open →
2019-09
40:17
Jakub Kaluzny - Proprietary network protocols - risky business on the wire.
Jakub Kaluzny
BSides London
· 2015
Technical
Advanced
Red
Talk
Open →
2015-07
33:40
BSidesIOWA 2015 Track1: Intro to WebApp Testing with Mutillidae by Andrew Freeborn
BSides Iowa
Open →
2015-04
29:35
The Bucket List: Experiences Operating S3 Honeypots
Cameron Ero
BSidesSF
· 2018
Research
Cloud IAM
Threat Intel
Blue
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2018-04
24:15
OWASP Top 10 in GraphQL: An API Adventure
Danielle Rosenfeld-Lovell
BSides Canberra
· 2024
Technical
OWASP
Web AppSec
Talk
Open →
2024-12
34:32
Introduction To Ethical Hacking
Brandon S. Keath
BSides Delaware
· 2018
Talk
Open →
2018-11
24:47
BSides Berlin 2023: Jorge Gimenez - Phishing techniques for challenging environments
BSides Berlin
Open →
2024-01
47:04
Intro to API Hacking
Jamy Casteel
BSides Dallas/Fort Worth
· 2022
Technical
OWASP
Web AppSec
Intro
Red
Talk
Open →
2022-11
29:07
SOC Analyst's Arsenal: Essential Tools, Tips & Tricks For Effective Investigations
Samuel Kavaler
BSides Munich
· 2023
Technical
DFIR
Detection Engineering
Tooling
Intermediary
Blue
Talk
Open →
2023-10
58:51
How to use XXE to your Advantage
Leo Pate
BSides Augusta
· 2018
Technical
Web AppSec
Blue
Purple
Red
Talk
Open →
2018-11
27:09
2017 - Security Testing As Part Of The Release Pipeline by David Brownhill and Craig Scott Angell
BSides Manchester
Open →
2017-08
25:14
Securing Fast and Furious DevOps Pipelines
Abdessamad Temmar
BSides Las Vegas
· 2019
Technical
DevSecOps
Supply Chain Security
Blue
Talk
Open →
2019-10
25:44
APIcalypse Now: Hunting APIs to Profit
Nithin Ravi
BSides Galway
Technical
Talk
Open →
2025-03
24:12
Bootstrapping Security
Jared Casner
Rob Shaw
BSidesSF
· 2020
Talk
Open →
2020-03
24:58
What's Inside The Open Directory From 96 Different Threat Actors?
Alana Witten
BSides London
· 2025
Research
Case Studies and Incidents Analysis
Empirical Research
Talk
Open →
2025-02
46:48
InfoSec, Just Doing It
Rob Jorgensen
BSides SLC
· 2015
Career
Career & Soft Skills
Intro
Talk
Open →
2015-04
35:33
BSidesIOWA 2015 Track1: Integrating Vuln Scanning into the SDLC by Eric Johnson
BSides Iowa
Open →
2015-04
1:57:57
DevSecOps for Security Teams
Hassan Mussana
BSides Pakistan
· 2021
Technical
DevSecOps
Supply Chain Security
Talk
Open →
2021-10
33:27
Front end Security
Martin Stoynov
Spas Genov
BSides Sofia
· 2022
Technical
Web AppSec
Red
Talk
Open →
2022-04
25:35
Low Hanging Blue Fruit: Defending With Open-Source Tools
Yaron King
BSides TLV
· 2019
Technical
Blue
Talk
Open →
2019-11
28:13
A Hitchhackers Guide to the IoT: Security from a FMCG Perspective
Jerome de las Alas
BSides Charleston
· 2022
Technical
Hardware Hacking
IoT
Vulnerability Research
Talk
Open →
2022-11
33:41
Start Hacking APIs
Corey Ball
BSides Edmonton
· 2023
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2023-11
24:28
Injections... again?
Márk Módly
BSides Budabest
· 2022
Technical
OWASP
Talk
Open →
2023-06
43:55
Where and how to implement Security in Software Development
Radostina Kondakova
Jordan Popov
BSides Sofia
· 2022
Technical
DevSecOps
Threat Modeling
Web AppSec
Methodology
Talk
Open →
2022-04
56:51
Hacking the OWASP Top 10: An Intro to Web Application Security
Greg Sternberg
BSides Denver
· 2020
Technical
OWASP
Web AppSec
Intro
Talk
Open →
2020-10
50:35
Building A Secure Development Lifecycle On A Shoestring Budget
John Overbaugh
BSides SLC
· 2016
Technical
DevSecOps
Talk
Open →
2016-05
17:58
DevSecOps On A Budget: Building A Secure Dev Pipeline Without Breaking The Bank
Robbie Thandi
BSides London
Technical
DevSecOps
Talk
Open →
2024-02
49:50
Intro to HTTP and De-Sync Attacks
Cary Hooper
BSides SATX
· 2021
Technical
Web AppSec
Intro
Talk
Open →
2021-06
31:15
Web Application Penetration Testing on a Budget: Building an In-House Program
Harshal Chandorkar
Natalia Wadden
BSides Toronto
· 2017
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2018-01
33:43
The Secure Software Supply Chain Function S3C
Alexandar Andonov
BSides Sofia
· 2023
Technical
DevSecOps
Supply Chain Security
Talk
Open →
2023-03
48:05
Mallet — an Intercepting Proxy for Arbitrary Protocols
Rogan Dawes
BSides Cape Town
· 2018
Technical
Tooling
Network Security
Reverse Engineering
Web AppSec
Red
Talk
Open →
2019-02
51:12
REST is the Sweet Sauce of Labor
Kevin Cody
BSides Peru
· 2018
Technical
OWASP
Web AppSec
Demo
Talk
Open →
2018-06
25:44
Threat Modeling for Security Professionals
Matt Trevors
BSides Peru
· 2019
Technical
Threat Modeling
Talk
Open →
2019-07
29:27
LightBulb Framework: Shedding Light on the Dark Side of WAFs and Filters
Ioannis Stais
BSides Athens
· 2017
Technical
Web AppSec
Talk
Open →
2017-10
21:54
Breaking Down Walls With Windows
Alexander Klepal
BSides SATX
· 2020
Technical
Red
Talk
Open →
2020-08
29:56
BSidesWLG 2017 - Kim Carter - Secrets of a Security Focused Agile Team
BSides Wellington
Open →
2018-02
26:58
5 Open Source Security Tools
Chris Koehnecke
BSides SLC
· 2023
Technical
Container Security
DevSecOps
Supply Chain Security
Web AppSec
Talk
Open →
2023-06
10:49
Shift Left without Losing Your Mind - Practical DevSecOps for Busy Teams - Callian Berends
Callian Berends
BSides Joburg
· 2025
Technical
DevSecOps
Intro
Talk
Open →
2025-09
38:24
Penetration Testing Experience and How to Get It
Phillip Wylie
BSides Las Vegas
Career
Career & Soft Skills
Intro
Talk
Open →
2024-09
45:29
Web Hacking 101: Hands-on with Burp Suite
David Rhoades
BSides Philly
· 2018
Technical
Web AppSec
Intro
Workshop
Open →
2018-11
45:28
Rahul Raghavan: The Clutter That's Choking AppSec
Rahul Raghavan
BSides Calgary
Talk
Open →
2020-12
28:57
Framework for Embedded Device Analysis
Madison Oliver
Kyle O'Meara
BSides Peru
· 2017
Research
Technical
Methodology
Technical Deep-dives
Talk
Open →
2017-10
16:09
AppSec On A Shoe String by Sean Wright
Sean Wright
BSides Lancashire
· 2023
Technical
Supply Chain Security
Tooling
Web AppSec
Talk
Open →
2023-04
39:01
Ochaun Marshall: Samurai Web Training Framework 5.0
Ochaun Marshall
BSides Calgary
· 2021
Open →
2021-12
36:52
BSidesROC 2023 Hacking and Defending APIs - Robert Wagner
BSidesROC
Open →
2024-09
39:49
Chris Koehnecke - Minimum Viable Security for Cloud Native Stacks
BSides Knoxville
Open →
2023-05
25:13
The Security Hitchhiker's Guide to API Security
Timothy De Block
BSides Augusta
· 2023
Technical
Web AppSec
Talk
Open →
2023-10
32:24
Using Large Language Models To Augment AppSec Testing
Thomas Ballin
BSides Newcastle
· 2025
Technical
AI Security
Detection Engineering
Web AppSec
Intermediary
Talk
Open →
2025-01
19:28
The Halcyon Project: Applying DevSecOps to a Vulnerable App
James Clapperton
BSides Belfast
· 2025
Technical
DevSecOps
OWASP
Supply Chain Security
Threat Modeling
Web AppSec
Talk
Open →
2025-12
42:00
Open Source Software is Amazing and Risky
Nicole Schwartz
BSides Saskatoon
· 2024
Technical
DevSecOps
Supply Chain Security
Vulnerability Research
Talk
Open →
2024-09
48:39
eXes & Oauths They Haunt Me: In-Depth Analysis of OAuth/OIDC Misconfigurations & Token Replay Attacks
Darryl G. Baker
BSides Las Vegas
· 2025
Technical
Cryptography
Web AppSec
Demo
Talk
Open →
2025-12
37:07
Navigating DevOps security journey at scale with OWASP SAMM 2 0 by Hardik Parekh at BSides Toronto
BSides Toronto
Open →
2021-11
30:31
What Will Go Wrong When ZAP Is Driven By GenAI
Gerald Benischke
BSides Newcastle
· 2025
Technical
AI Security
Tooling
Web AppSec
Technical Deep-dives
Demo
Talk
Open →
2025-11
28:29
Do Scanners Suck? I Have The Receipts - Thomas Ballin
Thomas Ballin
BSides Leeds
· 2026
Talk
Open →
2025-08
49:15
Imperial Stout: Building Bolder BurpSuite Functionality
Jason Gillam
BSides Greenville 2020
Technical
Tooling
Web AppSec
Red
Demo
Talk
Open →
2020-06
34:22
Salman, Khwaja: Story of Implementation of SecDevOps in Fin Tech Organization and beyond
BSides Calgary
· 2021
DevSecOps
Talk
Open →
2021-12
24:39
Shift Left with DevSecOps: Scanning Every Code Change
Avinash Jain
BSides Newcastle
· 2020
Technical
DevSecOps
OWASP
Talk
Open →
2020-11
33:31
Security in Continuous Delivery Pipelines
Sam Hogy
BSides Newcastle
· 2020
Technical
DevSecOps
Threat Modeling
Talk
Open →
2020-11
29:27
Building the Flight Deck: Tools and Technologies for a Robust AppSec Program
Chris Koehnecke
BSides Albuquerque
Technical
Talk
Open →
2024-08