Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Tool
BSides talks featuring Semgrep
48
talks mention this tool across
23
BSides chapters.
Talks featuring Semgrep
34:45
Bug Hunting with Static Code Analysis
Nick Jones
BSides London
· 2016
Technical
Talk
Open →
2016-07
45:31
Source Code Security Audit Speed Run
Eldar Marcussen
BSides Canberra
· 2019
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2019-05
43:57
TL;DR: Applying AI to Security
Clint Gibler
BSidesSF
· 2024
Technical
AI Security
Detection Engineering
Threat Intel
Intro
Talk
Open →
2024-07
27:37
Overwatch: A serverless approach to orchestrating your security automation
Sanchay Jaipuriyar
BSidesSF
· 2023
Technical
DevSecOps
Talk
Open →
2023-05
25:14
From Firmware to Exploit
Michael Messner
BSides Las Vegas
· 2023
Technical
Tooling
Firmware Security
IoT
Reverse Engineering
Vulnerability Research
Intermediary
Technical Deep-dives
+1
Open →
2023-10
22:20
When is a vulnerability not a vulnerability? Overcoming the inundation of noisy supply chain security alerts
Adam Berman
BSidesSF
· 2023
Technical
Supply Chain Security
Technical Deep-dives
Talk
Open →
2023-05
41:37
Getting Things Fixed: Security Wins and Fails
Scott Piper
BSides SLC
· 2025
War Stories
Cloud IAM
Vulnerability Research
Keynote
Open →
2025-06
49:30
Infrastructure as RCE: How to abuse Terraform to elevate access
Mike McCabe
BSides NYC
· 2023
Technical
Cloud IAM
DevSecOps
Vulnerability Research
Red
Talk
Open →
2023-06
38:01
Entomology 101: Finding, Studying, and Exploiting Bugs
Louis Nyffenegger
BSides Canberra
· 2020
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2020-07
50:47
BSidesSF 2023 - FAIR STRIDE - Building Business Relevant Threat Models (Arthur Loris)
Arthur Loris
BSidesSF
· 2023
Technical
Talk
Open →
2023-05
24:41
Got popcorn? What's on the Vuln Channel tonight?
Rob Jerdonek
Lily Chau
BSidesSF
· 2022
Technical
Talk
Open →
2022-07
31:50
Who Makes the Rules?
Meghna Vikram
BSides Knoxville
Research
Technical
AI Security
Supply Chain Security
Vulnerability Research
Empirical Research
Technical Deep-dives
Talk
Open →
2024-07
25:14
The Power of Guardrails: How to slash your risk of XSS in half
Colleen Dai
Grayson Hardaway
BSidesSF
· 2022
Technical
Vulnerability Research
Web AppSec
Case Studies and Incidents Analysis
Empirical Research
Talk
Open →
2022-07
50:37
The Power of Guardrails: How to Slash Your Risk of XSS in Half
Colleen Dai
Grayson Hardaway
BSides Las Vegas
· 2021
Technical
Vulnerability Research
Web AppSec
Empirical Research
Technical Deep-dives
Talk
Open →
2021-08
47:22
Manage Your Attack Surface on a Budget
Brittany D Little
Dileep Gurazada
Joshua Danielson
Anchal Raheja
BSides Las Vegas
· 2021
Technical
Tooling
Cloud IAM
Vulnerability Research
Panel
Open →
2021-08
24:39
Start - Recon - Exploit: A Framework for Desktop App Pentesting
Santiago Gimenez Ocano
Ryan Syed
BSides SLC
· 2025
Technical
Red
Talk
Open →
2025-06
45:10
Reversing Bytecode into Bounties: Uncovering Vulnerabilities in Jira and Confluence Plugins
Giuliana De Bellis
Jamal Hopwood
BSides Canberra
· 2025
Technical
Reverse Engineering
Vulnerability Research
Web AppSec
Intermediary
Red
Talk
Open →
2025-12
20:55
CG - Towards Effective & Scalable Vulnerability Management
Yotam Perkal
BSides Las Vegas
· 2023
Technical
Supply Chain Security
Vulnerability Research
Talk
Open →
2023-10
41:12
Threat Modelling as Code: Building Security into Your Git Workflow
Christian Frichot
BSides Perth
· 2025
Technical
Talk
Open →
2025-10
51:07
PW - The attackers guide to exploiting secrets in the universe
BSides Las Vegas
Open →
2023-10
34:17
BSides Perth 2023: Sajeeb Lohani & Ben Christian: Achieving Supply Chain Security on a Budget
Sajeeb Lohani
Ben Christian
BSides Perth
· 2023
Technical
Supply Chain Security
Purple
Talk
Open →
2023-08
17:58
DevSecOps On A Budget: Building A Secure Dev Pipeline Without Breaking The Bank
Robbie Thandi
BSides London
Technical
DevSecOps
Talk
Open →
2024-02
17:20
GenAI et sécurité du code : le bon et le mauvais
Edouard Viot
BSides Paris
· 2024
Research
Technical
AI Security
Supply Chain Security
Vulnerability Research
Talk
Open →
2024-05
40:16
How to Start and Mature an AppSec Program
Nivedita Murthy
BSides Knoxville
· 2022
Technical
DevSecOps
Web AppSec
Talk
Open →
2022-05
37:04
Terraform Security: Attacking and Defending Infrastructure as Code
Michael McCabe
BSides Philly
· 2023
Technical
Cloud IAM
DevSecOps
Vulnerability Research
Technical Deep-dives
Talk
Open →
2024-01
40:32
SELECT * FROM code WHERE input != 'sanitized'
Jardel Matias
BSides São Paulo
Technical
Vulnerability Research
Red
Talk
Open →
2025-06
14:48
Why You Must Make Your DEV Team Formally Verify Their New Feature Before Deployment
Rahul Balaji
BSides Leeds
Technical
Talk
Open →
2025-08
22:14
Prepare for the Appocalypse: Exposing Shadow and Zombie APIs
Amit Srour
BSides Las Vegas
· 2024
Technical
Vulnerability Research
Web AppSec
Blue
Talk
Open →
2024-09
37:08
Tracking and Hacking Your Career
Leif Dreizler
BSides Las Vegas
· 2024
Career
Career & Soft Skills
Intro
Talk
Open →
2024-09
24:25
A Blueprint for Branding: Authentic Ways to Establish your Public Persona
Leif Dreizler
Misha Kuenstner
BSides Seattle
Career
Talk
Open →
2025-06
26:58
5 Open Source Security Tools
Chris Koehnecke
BSides SLC
· 2023
Technical
Container Security
DevSecOps
Supply Chain Security
Web AppSec
Talk
Open →
2023-06
44:08
BSidesCharm 2024 - Who’s going to secure the code our army of robots are going to be writing?
BSides Charm
Open →
2024-06
16:09
AppSec On A Shoe String by Sean Wright
Sean Wright
BSides Lancashire
· 2023
Technical
Supply Chain Security
Tooling
Web AppSec
Talk
Open →
2023-04
24:24
Offensive by Design: GenAI and Docker for the Lazy Hacker
Wes Wright
BSides SATX
· 2025
Technical
Talk
Open →
2025-09
39:49
Chris Koehnecke - Minimum Viable Security for Cloud Native Stacks
BSides Knoxville
Open →
2023-05
52:06
Improve the identification of vulnerabilities in your project with just few commands
Filipi Pires
BSides SATX
· 2021
Technical
Demo
Open →
2021-06
16:42
Who Makes the Rules?
Meghna Vikram
BSides SLC
· 2024
Research
Technical
AI Security
Vulnerability Research
Web AppSec
Methodology
Technical Deep-dives
Talk
Open →
2024-09
51:24
An Introduction to Application Security Testing
Daniel Ulrich
BSides Buffalo
· 2025
Technical
DevSecOps
Web AppSec
Intro
Talk
Open →
2025-06
19:28
The Halcyon Project: Applying DevSecOps to a Vulnerable App
James Clapperton
BSides Belfast
· 2025
Technical
DevSecOps
OWASP
Supply Chain Security
Threat Modeling
Web AppSec
Talk
Open →
2025-12
42:00
Open Source Software is Amazing and Risky
Nicole Schwartz
BSides Saskatoon
· 2024
Technical
DevSecOps
Supply Chain Security
Vulnerability Research
Talk
Open →
2024-09
46:27
Your Ad Here: Helping Your Organization Build Their Security Brand
Leif Dreizler
Coleen Coolidge
BSides Las Vegas
Career
Community
Career & Soft Skills
Talk
Open →
2023-10
27:33
Buffer Overflows in the Era of Gen AI
Maxime Reynaud
BSides Exeter
· 2026
Research
AI Security
Vulnerability Research
Empirical Research
Technical Deep-dives
Talk
Open →
2026-05
28:29
Do Scanners Suck? I Have The Receipts - Thomas Ballin
Thomas Ballin
BSides Leeds
· 2026
Talk
Open →
2025-08
25:58
Running an AppSec Program in an Agile Environment
Mert Coskuner
BSides Newcastle
· 2021
Technical
DevSecOps
Web AppSec
Talk
Open →
2021-10
20:57
Half-Life: Lambda Security
Artem Tsvetkov
BSides Barcelona
· 2019
Technical
Talk
Open →
2022-01
50:29
MCP LFI in 60 minutes (or your money back)
Kurt Boberg
BSides Seattle
· 2026
Technical
Talk
Open →
2026-04
24:39
Shift Left with DevSecOps: Scanning Every Code Change
Avinash Jain
BSides Newcastle
· 2020
Technical
DevSecOps
OWASP
Talk
Open →
2020-11
35:40
Henrique Pereira
Henrique Pereira
BSides Calgary
Open →
2024-03