Application-Security is no longer the “optional” department as many companies throughout the world recognize it as a requirement, as well a being prudent for their own risk management. This talk discusses my experiences as someone new to the field of AppSec and through the many hurdles I faced. I will also discuss the challenges that a new Application Security team will see whilst trying to develop methods and processes for an ever growing code-base. This talk will benefit the individual that is new to the field and those who are managing these groups. Attendees of this talk will take away how I learned to think on my feet whilst under pressure and how I survived my first year in Application Security. emulacra and emulation: an intro to emulating binary code with VivisectAtlas of D00m N/AN/Astatic analysis is my favorite hard thing. blurring the lines between static and dynamic analysis can be incredibly powerful and immensely gratifying. come listen to atlas talk about how “partial emulation” works, how emulation works in Vivisect in general, and the powerful toys one can create using these tools