Guides

DerSecur Guides

Step-by-step operational guides for DerScanner and DerOS — written and executed on real installations, with screenshots of the actual interface and the exact API calls used.

Each guide documents one task end to end, states the environment it was executed in, and shows the commands and screens an engineer will actually see.

Popular knowledge with guides

Start from a knowledge article, then follow the linked step-by-step guide in DerScanner.

All guides

DerScanner

Claude Code Security Review and Code Quality — Claude Opus Wrote It, We Scanned It

A step-by-step Claude Code security review of a synthetic ShipDesk Express service generated by Claude Opus in Cursor — baseline DerScanner scan with SAST and Code Quality on JavaScript, a remediation prompt, a rescan under identical settings, and hybrid before/after reports built from the REST API on a local installation.

Application security engineers reviewing JavaScript written by Claude Opus or another AI coding model · 40 minutes

DerScanner

Claude Code Security Wasn't Enough — DAST Found SQL Injection, SAST Correlation Confirmed It

A step-by-step walkthrough of the same synthetic InventoryDesk FastAPI service used in the SAST and SCA guide — generated in Cursor with Claude as the model, first scanned with DAST against a running instance, then scanned with Python SAST linked to that DAST project. Findings that share a CWE with a DAST issue receive a D tag in Detailed Results. Screenshots were taken under a dedicated non-administrator account named Cursor.

Application security engineers who need static findings validated against a running deployment of AI-generated Python services · 50 minutes

DerScanner

Claude Opus Wrote the App and the Dependencies — SAST and SCA Caught Both

A step-by-step walkthrough of a synthetic InventoryDesk FastAPI service generated by Claude Opus in Cursor — Python SAST on the source archive, then hybrid SCA with vulnerability reachability analysis on the same zip, with screenshots from a local DerScanner installation under a dedicated non-administrator account named Cursor.

Application security engineers reviewing Python services and dependency lists produced by Claude Opus or another AI coding model · 40 minutes

DerScanner

Cursor Security and Code Quality — One Prompt, 19 Findings, One Rescan

A step-by-step walkthrough of generating a DeskQueue Express service from one Cursor prompt, running a baseline DerScanner scan with SAST and Code Quality on TypeScript, fixing vulnerabilities and hygiene issues with a second prompt, rescanning, and building hybrid before/after reports from the REST API on a local installation.

Application security engineers reviewing AI-generated TypeScript backends · 40 minutes

DerScanner

Cursor Wrote the App, DerTriage Confirmed Three Real Bugs — On a CPU-Only Host

A step-by-step walkthrough of scanning a one-prompt FastAPI application with DerScanner, leaving bulk AI triage disabled, and running selective DerTriage on three critical findings — SQL injection, command injection, and insecure deserialization — all verified on a CPU-only installation.

Application security engineers reviewing AI-generated Python services · 45 minutes

DerScanner

We Planted SQL Injection in a Delphi App — Cursor Ran the Scan, DerTriage Confirmed It

A step-by-step walkthrough of selective AI verification in DerScanner — issuing an API token, starting a scan with scan-wide AI triage switched off, and running DerTriage on one finding at a time. Executed on a self-hosted installation against a synthetic Delphi application written for this guide.

Application security engineers and developers who triage SAST findings · 30 minutes

DerSecur Recognition · build 2dac3d6 · 2026-09-07 06:49:25Z · system