Static Application Security Testing. White box testing. Analyzes source code without running the program. Definition-based. Cannot find zero-days.
Want to actually apply concepts like this instead of just reading definitions?