Tool Name
Smart Application Security Score Card
Release date
14/May/2010
Last Updated Date
14/May/2010
Description
Smart Application Security Score Card is a decision-making tool for application/product owners to help determine the essential security assessments for their products/applications. Whilst ideally every application must undergo required security assessments, but not all types of applications are required to undergo all the commonly recommended (Design Review, Code Review, Penetration Testing, Post-Release Review) security assessments. There are situations where application owners do not have enough budget to get all the applications they own undergo all the recommended security assessments.

This tool is meant to aid application stakeholders in determining essential security assessments required for a particular product or application. Additionally, it also helps assign a score/weight for each recommended security assessment for the application which would help in prioritising the required security assessments.

Platform / OS

It is a PDF based tool. Therefore, Adobe reader is required to use this tool.

Download

Tool Name
TA-Mapper (Application Penetration Testing Effort Estimator)
Release date
01/Jan/2009
Last Updated Date
01/Jan/2009
Description
Time and Attack Mapper (aka TA-Mapper) is an effort estimator tool for application penetration testing. This tool takes a scientific approach towards estimating efforts required for penetration testing for a particular application.

Efforts estimation done by most independent penetration testers or consulting companies are still done in a subjective way and there is no standardisation around it. TA-Mapper fills the gap by providing a scientific approach towards estimating efforts. This tool is able to calculate efforts with greater accuracy for application penetration testing.

This tool was originally written in 2004 to support some of my independent consulting assignments. I kept this tool private for a long time and made it public in 2009. It won't be wrong to say that during the time of the release of this tool, it was first of it's kind and is industry's first effort estimation tool for penetration testing.

Platform / OS

Windows (Developed in VB.NET)

Download

Tool Name
SwordFish - Microsoft Access Password Recovery Tool
Release date
17/Sep/2008
Last Updated Date
17/Sep/2008
Description

SwordFish is a Microsoft Access password recovery tool. It can only recover passwords for MS Access 97/2003. Originally tested to work successfully on Windows XP/2000. Note: I have discontinued support for this tool.

Platform / OS

Windows (Developed in VB 6.0)

Download

Tool Name
Static Code Analysis Tools - Pilot Guide
Release date
01/Sep/2005
Last Updated Date
01/Sep/2005
Description

Static Code Analysis Tools - Pilot Guide

Platform / OS

Any

Download