
training-application-security
Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

Rules Shared by the Community from 100 Days of YARA 2023 -

Rules shared by the community from 100 Days of YARA 2024

Free educational courses in cybersecurity, reverse engineering, malware analysis, and programming designed to expand access, build practical skills,…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Issues to consider when planning a red team exercise.

A structured course built from personal study notes of the book Linux Basics for Hackers by OccupyTheWeb.

Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage…

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Materials for Windows Malware Analysis training (volume 1)

Building 70 Projects ranging from beginner to advanced so anyone can — learn from, build upon, use as a reference, or even copy directly. Gamified…

Rules shared by the community from 100 Days of YARA 2026

Rules shared by the community from 100 Days of YARA 2026

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the…

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.