OWASP .NET Recommended Resources

OWASP .NET Recommended Resources
This is a canonical list of outside resources for .NET developers seeking security information.

Blogs & People
Mark Curphrey's Blog

Michael Howard's Blog

J.D. Meier's Blog

Dominick Baier's Blog

Shawn Farkas' Blog

Microsoft's ACE Team

Troy Hunt's Blog

App Protection Blog

Advisories, Articles & Projects
Security and Operational Guidance for .NET Applications

ASP.NET Security Architecture

patterns & practices Security Engineering Index

patterns & practices Security Guidance for Applications Index

patterns & practices Security Guidance for .NET Framework 2.0

Authentication in ASP.NET: .NET Security Guidance

Security Engineering

Solutions to SOA Security

Web Service Specifications

Security Guidance for Windows Communication Foundation

Microsoft Security Advisory (954462) (SQL Injection Advisory)

Security Development Lifecycle

Online References, Training
Patterns and Practices

MSDN Security Developer Center

Microsoft Security Resources

Pluralsight Security Course Catalog

OWASP Top 10 for .NET developers - Troy Hunt

TeamMentor

Security in the .NET Framework

Books and Publications
Writing Secure Code, Michael Howard and David LeBlanc

Microsoft Security Development Lifecycle 3.2

Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication, J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy

Improving Web Application Security: Threats and Countermeasures, J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan

Developer Highway Code, Microsoft Corp, United Kingdom

Security Driven .NET, Stan Drapkin

Tools
Microsoft Threat Modeling Tool 2014

Anti-Cross Site Scripting

URLScan

Microsoft Source Code Analyzer

MS Source Code Analyser for SQL Injection

Visual Studio .NET Obfuscator