Runtime application self-protection (RASP)
            
    
    
                DevSecOps
            
        Runtime application self-protection & Containers (RASP) - Falco / Notary / The Update Framework (TUF) / Nikto
            The Update Framework TUF
            
    
    
                DevSecOps
            
        Runtime application self-protection & Containers (RASP) - The Update Framework (TUF)
            DAST
            
    
    
                DevSecOps
            
        - Dynamic Application Security Testing (DAST) -  OWASP ZAP (Zed Attack Proxy) / Skipfish / Nmap / OpenVAS by Greenbone / Fortify WebInspect
            Threat Models
            
    
    
                DevSecOps
            
        Threat Models & Tools -  STRIDE / PASTA / VAST & Microsoft Threat Modeling Tool / OWASP Threat Dragon