Learning Materials
Resources
Curated learning materials for application security
Featured Resources
OWASP Top 10
The definitive guide to the most critical web application security risks.
OWASP
OWASP Cheat Sheet Series
Concise collection of high value information on specific application security topics.
OWASP
PortSwigger Web Security Academy
Free online web security training with interactive labs.
PortSwigger
OWASP SAMM
Software Assurance Maturity Model for measuring and improving your security program.
OWASP
Semgrep
Fast, open-source static analysis tool supporting 30+ languages.
Semgrep
OWASP ZAP
Free, open-source web application security scanner with active community.
OWASP
OWASP Top 10
The definitive guide to the most critical web application security risks.
OWASP Cheat Sheet Series
Concise collection of high value information on specific application security topics.
PortSwigger Web Security Academy
Free online web security training with interactive labs.
OWASP SAMM
Software Assurance Maturity Model for measuring and improving your security program.
Microsoft SDL
Microsoft Security Development Lifecycle practices and resources.
NIST Secure Software Development Framework
NIST guidelines for secure software development practices.
BSIMM
Building Security In Maturity Model - measure your software security initiative.
Semgrep
Fast, open-source static analysis tool supporting 30+ languages.
SonarQube
Continuous inspection of code quality and security vulnerabilities.
CodeQL
GitHub's semantic code analysis engine for finding vulnerabilities.
Bandit
Python security linter for finding common security issues.
ESLint Security Plugin
Security rules for ESLint to catch JavaScript vulnerabilities.
Gosec
Security scanner for Go source code.
OWASP ZAP
Free, open-source web application security scanner with active community.
Burp Suite
Industry-leading web security testing toolkit for penetration testers.
Nuclei
Fast vulnerability scanner based on customizable YAML templates.
Nikto
Open source web server scanner for dangerous files and vulnerabilities.
Arachni
Feature-rich modular web application security scanner framework.
Snyk
Developer-first security for finding and fixing vulnerabilities in dependencies.
OWASP Dependency-Check
Open source SCA tool detecting publicly disclosed vulnerabilities.
Dependabot
Automated dependency updates and security alerts in GitHub.
LiveOverflow
IT security YouTube channel covering hacking, CTFs, and security research.
John Hammond
Cybersecurity content including CTF walkthroughs and security tutorials.
IppSec
HackTheBox and CTF walkthroughs with detailed explanations.
DevSecOps Talks
Conference talks and tutorials on integrating security into DevOps.
Burp Suite Community
Leading web security testing toolkit for penetration testers.
SQLMap
Automatic SQL injection and database takeover tool.
HackTricks
Comprehensive hacking wiki with techniques and methodology.
PayloadsAllTheThings
A list of useful payloads and bypasses for web security.
SAST vs DAST Guide
Understanding the differences between static and dynamic testing.
Shift Left Security
Guide to implementing security early in the development lifecycle.
TryHackMe
Learn cyber security through hands-on exercises and labs.
HackTheBox Academy
Structured cybersecurity training with certification paths.
OWASP Application Security
Free OWASP courses on web application security fundamentals.
Secure Coding Practices
Learn secure coding with practical examples and exercises.
GitHub
Open source tools & resources
YouTube
VideoCamera tutorials & walkthroughs
OWASP
Security standards & guides
Know a great resource?
Help the community by suggesting resources to add to this list.
Contribute on GitHub