Skip to main content

Roadmaps

Role-based routes through the labs. Each roadmap mixes secure coding, code review and investigation labs in the order they build on each other. A stage is complete when its labs are solved.

Developers who build APIs and server-side code

Secure backend development

The vulnerabilities that most often reach production in web backends, in the order you are likely to meet them: injection first, then access control, authentication and the server’s own outbound requests.

4 stages · 12 labs · ~4.8 h

0/12 solved0%
View roadmap

Full-stack and frontend developers

Secure web application development

Browser-facing risks: output encoding, cross-site requests, redirects, uploads and the sign-in flow. Finishes with reviewing whole features the way a security reviewer would.

4 stages · 10 labs · ~3.4 h

0/10 solved0%
View roadmap

Security engineers and reviewers who support development teams

Application security engineer

Review-first: learn to spot defects in pull requests, confirm them by fixing the code, and trace real incidents back to the bug that caused them.

4 stages · 12 labs · ~5.1 h

0/12 solved0%
View roadmap

SOC analysts and on-call engineers

Detection and incident response

Work incidents end to end from web, auth, audit, CI and git evidence using a shell. Each lab starts from a ticket and ends with scope and impact.

3 stages · 6 labs · ~3.0 h

0/6 solved0%
View roadmap
AppSec Arena

Hands-on application security labs for engineers.

Labs

  • All labs
  • Learning paths

Library

  • Vulnerability guide
  • OWASP Top 10
  • Resources
  • Roadmaps

Community

  • Discussions
  • Teams

Company

  • About
  • Contact
  • Privacy
  • Terms
  • Cookies

© 2026 AppSec Arena