DerSecur Guides
Step-by-step operational guides for DerScanner and DerOS — written and executed on real installations, with screenshots of the actual interface and the exact API calls used.
Each guide documents one task end to end, states the environment it was executed in, and shows the commands and screens an engineer will actually see.
Popular knowledge with guides
Start from a knowledge article, then follow the linked step-by-step guide in DerScanner.
Claude Code Security
Security review for Claude Code-generated code — five linked guides.
KnowledgeWhat Is SAST?
Definitions and controls, with guides to run SAST on AI-generated code.
KnowledgeAutomated Vulnerability Remediation
Remediation workflow with rescan guides on JavaScript and TypeScript.
All guides
Claude Code Security Review and Code Quality — Claude Opus Wrote It, We Scanned It
A step-by-step Claude Code security review of a synthetic ShipDesk Express service generated by Claude Opus in Cursor — baseline DerScanner scan with SAST and Code Quality on JavaScript, a remediation prompt, a rescan under identical settings, and hybrid before/after reports built from the REST API on a local installation.
DerScannerClaude Code Security Wasn't Enough — DAST Found SQL Injection, SAST Correlation Confirmed It
A step-by-step walkthrough of the same synthetic InventoryDesk FastAPI service used in the SAST and SCA guide — generated in Cursor with Claude as the model, first scanned with DAST against a running instance, then scanned with Python SAST linked to that DAST project. Findings that share a CWE with a DAST issue receive a D tag in Detailed Results. Screenshots were taken under a dedicated non-administrator account named Cursor.
DerScannerClaude Opus Wrote the App and the Dependencies — SAST and SCA Caught Both
A step-by-step walkthrough of a synthetic InventoryDesk FastAPI service generated by Claude Opus in Cursor — Python SAST on the source archive, then hybrid SCA with vulnerability reachability analysis on the same zip, with screenshots from a local DerScanner installation under a dedicated non-administrator account named Cursor.
DerScannerCursor Security and Code Quality — One Prompt, 19 Findings, One Rescan
A step-by-step walkthrough of generating a DeskQueue Express service from one Cursor prompt, running a baseline DerScanner scan with SAST and Code Quality on TypeScript, fixing vulnerabilities and hygiene issues with a second prompt, rescanning, and building hybrid before/after reports from the REST API on a local installation.
DerScannerCursor Wrote the App, DerTriage Confirmed Three Real Bugs — On a CPU-Only Host
A step-by-step walkthrough of scanning a one-prompt FastAPI application with DerScanner, leaving bulk AI triage disabled, and running selective DerTriage on three critical findings — SQL injection, command injection, and insecure deserialization — all verified on a CPU-only installation.
DerScannerWe Planted SQL Injection in a Delphi App — Cursor Ran the Scan, DerTriage Confirmed It
A step-by-step walkthrough of selective AI verification in DerScanner — issuing an API token, starting a scan with scan-wide AI triage switched off, and running DerTriage on one finding at a time. Executed on a self-hosted installation against a synthetic Delphi application written for this guide.
DerSecur Recognition · build 2dac3d6 · 2026-09-07 06:49:25Z · system