Learning Materials

Resources

Curated learning materials for application security

OWASP Top 10

The definitive guide to the most critical web application security risks.

documentationOWASP

OWASP Cheat Sheet Series

Concise collection of high value information on specific application security topics.

documentationOWASP

PortSwigger Web Security Academy

Free online web security training with interactive labs.

coursePortSwigger

OWASP SAMM

Software Assurance Maturity Model for measuring and improving your security program.

documentationOWASP

Microsoft SDL

Microsoft Security Development Lifecycle practices and resources.

documentationMicrosoft

NIST Secure Software Development Framework

NIST guidelines for secure software development practices.

documentationNIST

BSIMM

Building Security In Maturity Model - measure your software security initiative.

documentationSynopsys

Semgrep

Fast, open-source static analysis tool supporting 30+ languages.

toolSemgrep

SonarQube

Continuous inspection of code quality and security vulnerabilities.

toolSonarSource

CodeQL

GitHub's semantic code analysis engine for finding vulnerabilities.

toolGitHub

Bandit

Python security linter for finding common security issues.

toolOpen Source

ESLint Security Plugin

Security rules for ESLint to catch JavaScript vulnerabilities.

toolGitHub

Gosec

Security scanner for Go source code.

toolGitHub

OWASP ZAP

Free, open-source web application security scanner with active community.

toolOWASP

Burp Suite

Industry-leading web security testing toolkit for penetration testers.

toolPortSwigger

Nuclei

Fast vulnerability scanner based on customizable YAML templates.

toolProject Discovery

Nikto

Open source web server scanner for dangerous files and vulnerabilities.

toolOpen Source

Arachni

Feature-rich modular web application security scanner framework.

toolOpen Source

Snyk

Developer-first security for finding and fixing vulnerabilities in dependencies.

toolSnyk

OWASP Dependency-Check

Open source SCA tool detecting publicly disclosed vulnerabilities.

toolOWASP

Dependabot

Automated dependency updates and security alerts in GitHub.

toolGitHub

LiveOverflow

IT security YouTube channel covering hacking, CTFs, and security research.

videoYouTube

John Hammond

Cybersecurity content including CTF walkthroughs and security tutorials.

videoYouTube

IppSec

HackTheBox and CTF walkthroughs with detailed explanations.

videoYouTube

DevSecOps Talks

Conference talks and tutorials on integrating security into DevOps.

videoYouTube

Burp Suite Community

Leading web security testing toolkit for penetration testers.

toolPortSwigger

SQLMap

Automatic SQL injection and database takeover tool.

toolOpen Source

HackTricks

Comprehensive hacking wiki with techniques and methodology.

articleCommunity

PayloadsAllTheThings

A list of useful payloads and bypasses for web security.

articleGitHub

SAST vs DAST Guide

Understanding the differences between static and dynamic testing.

articleOWASP

Shift Left Security

Guide to implementing security early in the development lifecycle.

articleDevSecOps

TryHackMe

Learn cyber security through hands-on exercises and labs.

courseTryHackMe

HackTheBox Academy

Structured cybersecurity training with certification paths.

courseHackTheBox

OWASP Application Security

Free OWASP courses on web application security fundamentals.

courseOWASP

Secure Coding Practices

Learn secure coding with practical examples and exercises.

courseCommunity

Know a great resource?

Help the community by suggesting resources to add to this list.

Contribute on GitHub