Microsoft Download Center Archive

Microsoft SDL - Developer Starter Kit

  • Published:
  • Version: 1.0
  • Category: Document
  • Language: English

The Microsoft SDL - Developer Starter Kit provides a compliation of baseline developer security training materials on core Microsoft Security Development Lifecycle (SDL) topics.

  • The Microsoft SDL - Developer Starter Kit provides a compliation of baseline developer security training materials on the following core Microsoft Security Development Lifecycle (SDL) topics: a) secure design principles; b) secure implementation principles; c) secure verification principles; d) SQL injection; e) cross-site scripting; f) code analysis; g)banned application programming interfaces (APIs); h) buffer overflows; i) source code annotation language; j) security code review; k) compiler defenses; l) fuzz testing; m) Microsoft SDL threat modeling principles; and n) the Microsoft SDL threat modeling tool.Each set of guidance contains Microsoft Office PowerPoint slides, speaker notes, train-the-trainer audio files, and sample comprehension questions. All materials have limited formatting so that you can leverage the content to achieve broader, enhanced adoption of Microsoft SDL principles in your development organization.

Files

Status: Live

This download is still available on microsoft.com. The downloads below will come directly from the Microsoft Download Center.

FileSize
- Microsoft SDL - Developer Starter Kit - COMPLETE.zip
SHA1: 188359da099c84db2d511f5d2490c20b7fdb0741
324.86 MB
Banned APIs - Microsoft SDL - Developer Starter Kit.zip
SHA1: 4864dcb78bd521e988502abd11d70a9bc3aa5d52
14.83 MB
Buffer Overflows - Microsoft SDL - Developer Starter Kit.zip
SHA1: c5e1bbd9e12d3a9485171bca2021ad319fd6f0d0
27.18 MB
Code Analysis - Microsoft SDL - Developer Starter Kit.zip
SHA1: 06e20373eb331851d530de349362cafe4a863742
23.42 MB
Compiler Defenses - Microsoft SDL - Developer Starter Kit.zip
SHA1: dced1bd3c9c3b76bd97f1f0adbc468d80eb6cead
20.86 MB
Cross-Site Scripting - Microsoft SDL - Developer Starter Kit.zip
SHA1: a526a8b455956741f68f5ab1ed564b038ccd3244
36.78 MB
Fuzz Testing - Microsoft SDL - Developer Starter Kit.zip
SHA1: be5b659561e417a76d7378818b6b59a4d5e78f82
24.77 MB
READ ME - Microsoft SDL - Developer Starter Kit Overview.docx
SHA1: 01a4858a32adffe1596d8df8b341a9770a546441
100 KB
Secure Design Principles - Microsoft SDL - Developer Starter Kit.zip
SHA1: 32558a83c8c8756b1191284a7d4d1370d475d0d2
18.87 MB
Secure Implementation Principles - Microsoft SDL - Developer Starter Kit.zip
SHA1: 70fd87b88e92fc1a30213eafc2b9b598f9a65c1c
19.75 MB
Secure Verification Principles - Microsoft SDL - Developer Starter Kit.zip
SHA1: 879c75865cd567befb0129f9830d3d337eb0c621
15.24 MB
Security Code Review - Microsoft SDL - Developer Starter Kit.zip
SHA1: 57eeb10ee592dc0bea30598defbbe9ecb4f7a2ca
20.22 MB
Source Code Annotation Language - Microsoft SDL - Developer Starter Kit.zip
SHA1: 9ae561d6e47f1fdd18ba7f6edc6a8b9bcb004cd9
30.29 MB
SQL Injection - Microsoft SDL - Developer Starter Kit.zip
SHA1: c1873e53e4c344250980896c182b33c3b693fc3b
30.71 MB
Threat Modeling Principles - Microsoft SDL - Developer Starter Kit.zip
SHA1: d32cee495b5f1876292238c2f9e2ab83f07fbb39
21.57 MB
Threat Modeling Tool 2014 Principles.zip
SHA1: 0c4a84e7bf91cd17ed3d9b729c44cbf6005bf432
114.60 MB

File sizes and hashes are retrieved from the Wayback Machine’s indexes. They may not match the latest versions of files hosted on Microsoft servers.

System Requirements

Operating Systems: Windows 7, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP

  • To view kit materials, you will need Microsoft Office Word (2003 or later), Microsoft Office PowerPoint (2003 or later), Windows Media Player (or other media player that plays .wmv files), and a zip file extractor.

Installation Instructions

  • Download the kit overview, individual components, or the complete kit by clicking the Download button and saving the file to the desired location. Note: the complete kit and the individual components are in .zip format and may need to be extracted before they can be viewed.

Related Resources