Roadmaps
Role-based routes through the labs. Each roadmap mixes secure coding, code review and investigation labs in the order they build on each other. A stage is complete when its labs are solved.
Developers who build APIs and server-side code
Secure backend development
The vulnerabilities that most often reach production in web backends, in the order you are likely to meet them: injection first, then access control, authentication and the server’s own outbound requests.
4 stages · 12 labs · ~4.8 h
Full-stack and frontend developers
Secure web application development
Browser-facing risks: output encoding, cross-site requests, redirects, uploads and the sign-in flow. Finishes with reviewing whole features the way a security reviewer would.
4 stages · 10 labs · ~3.4 h
Security engineers and reviewers who support development teams
Application security engineer
Review-first: learn to spot defects in pull requests, confirm them by fixing the code, and trace real incidents back to the bug that caused them.
4 stages · 12 labs · ~5.1 h
SOC analysts and on-call engineers
Detection and incident response
Work incidents end to end from web, auth, audit, CI and git evidence using a shell. Each lab starts from a ticket and ends with scope and impact.
3 stages · 6 labs · ~3.0 h