Security

Once by the book.
Safer code, by design.

A practical map of software security, from threat modeling and secure coding to identity, AI application security, testing, delivery, and incident response.

Work in progress. The first lessons are available to explore. The rest of the catalog is still taking shape.

190 topics

Taking shape Ready lessons are open to explore alongside planned and in-progress topics.

Security mindset and core vocabulary

foundation

Build a practical vocabulary for reasoning about software risk and controls.

  • foundation authoring

    Security goals: confidentiality, integrity, availability

    Which property a control protects, and what it cannot protect.

  • foundation authoring

    Assets, actors, trust boundaries, and attack surface

    Start from what matters, who can influence it, and where data crosses ownership.

  • foundation authoring

    Threat, vulnerability, exploit, impact, and risk

    Distinguish a weakness from its possible use and consequence.

  • foundation authoring

    Authentication, authorization, and accounting

    Identity proof, permission decisions, and evidence are different jobs.

  • foundation authoring

    Least privilege and secure defaults

    Grant only the access needed; make the safe path the default.

  • foundation authoring

    Defense in depth and security boundaries

    Layer controls without treating any single layer as a substitute for the others.

  • foundation authoring

    Fail open or fail closed

    Choose behavior when a control or dependency is unavailable, based on the protected action.

  • foundation authoring

    Security by design versus security by obscurity

    Keep useful design secrecy distinct from controls that must hold even when implementation is known.

Threat modeling and secure design

foundation

Start with assets and boundaries; use threats to decide which controls matter.

  • foundation authoring

    Threat modeling a small feature

    Identify assets, actors, boundaries, abuse cases, and the controls that change the risk.

  • foundation authoring

    Data-flow diagrams and trust boundaries

    Draw only the flows needed to make security assumptions visible and reviewable.

  • foundation authoring

    STRIDE and alternative threat prompts

    Use a structured prompt as a completeness aid, not as a scoring oracle.

  • foundation authoring

    Abuse cases and business logic

    Ask how a valid feature can be misused, combined, repeated, or accessed out of sequence.

  • foundation authoring

    Security requirements and acceptance criteria

    Turn risks into explicit, testable requirements before implementation.

  • foundation authoring

    Secure architecture decisions

    Record assumptions, rejected options, residual risk, and revisit triggers.

  • foundation authoring

    Attack surface reduction

    Remove unused routes, permissions, dependencies, endpoints, and data.

  • foundation authoring

    Third-party and integration trust

    Define what each provider may send, read, change, and trigger.

  • foundation authoring

    Privacy and security design review

    Include data minimization, user expectations, and misuse impact alongside technical controls.

  • foundation authoring

    Lightweight threat-model review in pull requests

    Revisit the model when a change adds a new boundary, privilege, data type, or external dependency.

Web and API trust boundaries

foundation

Identify the trust boundaries where web requests and data enter the system.

Output handling and injection

foundation

Keep untrusted data from becoming executable code or query structure.

  • foundation authoring

    Reflected, stored, and DOM-based XSS

    Where attacker-controlled content enters and how it reaches an executable browser context.

    TypeScriptGo
  • foundation authoring

    Contextual output encoding

    HTML text, attributes, URLs, JavaScript, CSS, and rich text require different safe handling.

    TypeScriptGo
  • foundation authoring

    Safe DOM APIs and dangerous HTML escape hatches

    Prefer text and structured APIs; isolate and sanitize rich HTML when it is genuinely required.

    TypeScript
  • foundation authoring

    Framework escaping and its limits

    Know what a framework escapes automatically and identify raw HTML, unsafe URL, and template escape hatches.

    TypeScript
  • foundation authoring

    NoSQL and search-query injection

    Treat query operators and search syntax as untrusted structure, not harmless strings.

    TypeScriptGo
  • foundation authoring

    OS command injection

    Avoid shell construction; call a process with argument arrays and constrained inputs when process execution is necessary.

    TypeScriptGo
  • foundation authoring

    Template, expression, and code injection

    Separate data from executable templates and avoid evaluating untrusted expressions.

    TypeScriptGo
  • foundation authoring

    LDAP, XPath, and other interpreter injection

    Recognize that every interpreter needs its own parameterization or safe construction strategy.

    TypeScriptGo
  • foundation authoring

    Header, CRLF, and log injection

    Keep untrusted values from creating response headers, splitting messages, or forging log records.

    TypeScriptGo
  • foundation authoring

    Deserialization and object construction

    Avoid unsafe polymorphic deserialization; constrain types and validate parsed data.

    TypeScriptGo
  • foundation authoring

    Prototype pollution

    Prevent attacker-controlled object keys from changing inherited properties, configuration, or later authorization checks in JavaScript.

    TypeScript
  • foundation authoring

    ReDoS and parser complexity

    Bound input and algorithmic work so valid-looking inputs cannot monopolize CPU or memory.

    TypeScriptGo

Authorization and access control

foundation

Make every sensitive action depend on an explicit, verified permission.

  • foundation authoring

    Deny by default and check every request

    Enforce authorization on the server for every protected operation and resource.

    TypeScriptGo
  • foundation authoring

    Function-level and administrative authorization

    Protect privileged actions independently of whether a user can access the general application.

    TypeScriptGo
  • foundation authoring

    Horizontal and vertical privilege escalation

    Test access across peers and across privilege levels.

    TypeScriptGo
  • foundation authoring

    RBAC, ABAC, and relationship-based policies

    Choose a model that represents real ownership, attributes, roles, and relationships.

    TypeScriptGo
  • foundation authoring

    Authorization policy placement

    Centralize policy enough to audit it while keeping resource ownership explicit.

    TypeScriptGo
  • foundation authoring

    Tenant isolation

    Derive tenant context from a verified membership, scope every query, and add database protections where appropriate.

    TypeScriptGo
  • foundation authoring

    Mass assignment and over-posting

    Bind only fields the caller is allowed to set; do not deserialize request fields directly into privileged domain state.

    TypeScriptGo
  • foundation authoring

    Time-of-check/time-of-use authorization

    Keep the permission decision valid through the protected change, particularly under concurrency.

    TypeScriptGo
  • foundation authoring

    Authorization regression tests

    Build a matrix of subject, resource, operation, and expected outcome; test negative cases as first-class behavior.

    TypeScriptGo

Authentication, credentials, and sessions

practitioner

Protect account access, credentials, and the sessions that represent a user.

Data protection and cryptography

practitioner

Choose sound ways to protect sensitive data, secrets, and cryptographic keys.

  • practitioner authoring

    Data classification and minimization

    Collect, retain, expose, and log only what the feature needs.

  • practitioner authoring

    TLS, certificate validation, and trust stores

    Verify peers and configure the transport; encryption without correct certificate validation is incomplete.

    TypeScriptGo
  • practitioner authoring

    Encryption at rest and field-level protection

    Choose what is protected from which threat and account for application access to decryption keys.

    TypeScriptGo
  • practitioner authoring

    Hashing, encryption, encoding, and signing

    Explain the distinct security properties each operation provides.

  • practitioner authoring

    Cryptographically secure randomness

    Use platform cryptographic APIs for tokens, reset links, and unpredictable secrets—not general-purpose PRNGs.

    TypeScriptGo
  • practitioner authoring

    Key lifecycle and key management

    Generate, store, grant access to, rotate, back up, and retire keys deliberately.

    TypeScriptGo
  • practitioner authoring

    Timing attacks and constant-time comparison

    Avoid leaking secrets through data-dependent comparison or other observable timing where constant-time primitives are appropriate.

    TypeScriptGo
  • practitioner authoring

    Message authentication and digital signatures

    Verify integrity and sender authenticity without confusing signatures with encryption.

    TypeScriptGo
  • practitioner authoring

    Nonces, IVs, and authenticated encryption

    Use library-managed, unique parameters and authenticated modes; never invent a crypto protocol.

    TypeScriptGo
  • practitioner authoring

    Token and URL leakage

    Keep credentials out of URLs, referrers, analytics, error reports, and logs.

    TypeScriptGo
  • practitioner authoring

    Backups, deletion, and cryptographic erasure

    Align copies, retention, access, and key destruction with the data lifecycle.

API, workflow, and abuse resistance

practitioner

Protect APIs and business workflows from unauthorized use and resource abuse.

  • practitioner authoring

    API authentication is not API authorization

    Validate identity and separately check action and resource access.

    TypeScriptGo
  • practitioner authoring

    Request size, pagination, and resource limits

    Bound payloads, nested structures, result sizes, and expensive operations.

    TypeScriptGo
  • practitioner authoring

    Rate limiting and abuse controls

    Apply limits to the right identity and operation while considering distributed clients and shared infrastructure.

    TypeScriptGo
  • practitioner authoring

    Idempotency and replay resistance

    Make retries safe and protect sensitive one-time actions from replay.

    TypeScriptGo
  • practitioner authoring

    Workflow and business-logic abuse

    Validate allowed state transitions on the server, not just individual fields.

    TypeScriptGo
  • practitioner authoring

    Price, quota, and entitlement tampering

    Derive sensitive values and eligibility from trusted state.

    TypeScriptGo
  • practitioner authoring

    Webhook signature verification

    Verify the exact raw body and timestamp using the provider's documented scheme, then handle duplicates safely.

    TypeScriptGo
  • practitioner authoring

    SSRF and server-side fetches

    Restrict destinations and redirects, validate resolved addresses including cloud metadata ranges, and isolate outbound network access.

    TypeScriptGo
  • practitioner authoring

    Clickjacking and framing controls

    Decide which trusted origins may embed the application and set frame protections accordingly.

    TypeScriptGo
  • practitioner authoring

    GraphQL and query-shape abuse

    Bound depth, complexity, batching, and object-level authorization.

    TypeScriptGo
  • practitioner authoring

    WebSocket and long-lived connection security

    Authenticate connection setup, authorize each relevant message/action, and handle expiry and origin checks.

    TypeScriptGo
  • practitioner authoring

    HTTP request smuggling and parser disagreement

    Investigate when a proxy and origin parse message boundaries differently, and verify consistent handling across the request path.

    TypeScriptGo
  • practitioner authoring

    Web cache poisoning and cache deception

    Check whether cache keys and origin behavior can store attacker-influenced content or expose a private response to other users.

    TypeScriptGo

LLM and AI application security

practitioner

Secure AI features by treating model inputs, outputs, retrieved content, and tool proposals as untrusted.

  • practitioner authoring

    Threat-model an LLM feature

    Map user prompts, system instructions, retrieved content, model providers, tools, and sinks as separate trust boundaries.

  • practitioner authoring

    Direct and indirect prompt injection

    Understand that instructions in user input or retrieved content can manipulate model behavior; prompt wording alone is not a security boundary.

    TypeScript
  • practitioner authoring

    Untrusted model output and dangerous sinks

    Validate and authorize structured outputs before they reach HTML, SQL, shell, URLs, code execution, or state-changing tools.

    TypeScriptGo
  • practitioner authoring

    Data exfiltration through rendered output

    Prevent rendered model-authored links or media from making unintended external requests that disclose sensitive context.

    TypeScript
  • practitioner authoring

    Tool calls as untrusted requests

    Treat every proposed tool call as data; validate its schema, caller, target, scope, and current user permissions in ordinary application code.

    TypeScriptGo
  • practitioner authoring

    Agent permissions and excessive agency

    Limit available tools, operation scope, autonomy, and downstream identities to what the task actually needs.

    TypeScriptGo
  • practitioner authoring

    MCP and tool server security

    Assess server identity, untrusted tool descriptions and results, authorization scope, and credential exposure across the client-server boundary.

    TypeScriptGo
  • practitioner authoring

    Human approval for high-impact actions

    Require explicit, contextual confirmation before irreversible, externally visible, or privileged actions.

    TypeScriptGo
  • practitioner authoring

    Retrieval authorization and tenant isolation

    Apply the requesting user's permissions before retrieval and recheck authorization before disclosing retrieved content.

    TypeScriptGo
  • practitioner authoring

    Poisoned and hostile retrieved content

    Treat documents, web pages, email, and tool results as untrusted context that can contain indirect instructions.

    TypeScriptGo
  • practitioner authoring

    Vector stores, embeddings, and sensitive data

    Protect access to source documents, derived embeddings, metadata, and retrieval results; consider leakage and cross-tenant exposure.

    TypeScriptGo
  • practitioner authoring

    System prompts are not secrets

    Keep credentials and access decisions out of prompts; assume instructions can be exposed and enforce controls elsewhere.

  • practitioner authoring

    Conversation state and agent memory isolation

    Scope memory to a user and task, define retention, and prevent one session's content from influencing another's.

    TypeScript
  • practitioner authoring

    AI provider data handling and privacy

    Understand what prompts, files, telemetry, and outputs leave the system and the provider's retention and training settings.

  • practitioner authoring

    Model, dataset, and plugin supply-chain risk

    Verify provenance and permissions for models, fine-tuning data, connectors, plugins, and other components.

  • practitioner authoring

    Unbounded token use, loops, and cost abuse

    Set budgets, deadlines, output limits, and stopping rules for model calls and agent loops.

    TypeScriptGo
  • practitioner authoring

    LLM security evaluations and regression tests

    Test security properties across prompt variations and workflow states; retain reproducible cases while recognizing model variability.

    TypeScriptGo
  • practitioner authoring

    Red-team an AI feature safely

    Probe a local or authorized test system for data exposure, tool misuse, policy bypass, and resource abuse.

    TypeScriptGo
  • practitioner authoring

    AI security incident response

    Preserve relevant prompts, tool-call decisions, retrieved sources, model/provider versions, and outcomes without logging unnecessary sensitive content.

Security testing and code review

practitioner

Turn security properties into reviewable, repeatable tests.

  • practitioner authoring

    Turn a threat into a test

    Express the expected security property as a testable invariant.

    TypeScriptGo
  • practitioner authoring

    Negative authorization tests

    Assert that the wrong user, tenant, role, or workflow state is rejected.

    TypeScriptGo
  • practitioner authoring

    Unit, integration, and end-to-end security tests

    Place each check where it can exercise the real boundary without overclaiming coverage.

    TypeScriptGo
  • practitioner authoring

    Regression tests for vulnerabilities

    Preserve a minimal failing input and prove the fixed behavior at the relevant layer.

    TypeScriptGo
  • practitioner authoring

    Static analysis and lint rules

    Use tools to find classes of mistakes; triage findings and understand blind spots.

  • practitioner authoring

    Dynamic and interactive application testing

    Exercise a running test deployment safely and interpret scanner results rather than treating them as proof.

  • practitioner authoring

    Fuzzing parsers and validators

    Generate unexpected inputs to find crashes, hangs, and invariant failures.

    TypeScriptGo
  • practitioner authoring

    Dependency and container scanning

    Track components and investigate findings in the context of actual usage and exposure.

  • practitioner authoring

    Secure code review checklist

    Follow sources, trust boundaries, sinks, authorization decisions, secrets, and failure paths.

  • practitioner authoring

    False positives, false negatives, and test coverage

    Understand why scanners and passing tests cannot establish that an application is secure.

  • practitioner authoring

    Security test environments and safe fixtures

    Use synthetic data, scoped credentials, and isolated targets; do not test real systems without authorization.

Files, uploads, and content processing

practitioner

Handle uploaded files and complex content as hostile input.

  • practitioner authoring

    Secure file upload pipeline

    Enforce size, type, content, storage, and authorization checks as separate controls.

    TypeScriptGo
  • practitioner authoring

    MIME type and extension validation

    Treat client-provided filenames and content types as claims, not evidence.

    TypeScriptGo
  • practitioner authoring

    Safe file names and storage locations

    Generate server-side names and keep untrusted content out of executable or public paths.

    TypeScriptGo
  • practitioner authoring

    Malware scanning and quarantine workflow

    Define pending, scanned, rejected, and available states without trusting a scan as perfect.

    TypeScriptGo
  • practitioner authoring

    Archive extraction and path traversal

    Prevent entries from escaping the intended destination and bound expansion.

    TypeScriptGo
  • practitioner authoring

    Image, document, and media parser risks

    Isolate complex parsers and apply resource limits and updates.

    TypeScriptGo
  • practitioner authoring

    Content-Disposition and download safety

    Serve untrusted files with deliberate content types and download behavior.

    TypeScriptGo
  • practitioner authoring

    Import, export, and CSV formula injection

    Treat exported values as active content when opened by spreadsheet software.

    TypeScriptGo
  • practitioner authoring

    XML external entities and unsafe XML features

    Disable unnecessary entity resolution and bound parsing.

    TypeScriptGo
  • practitioner authoring

    Rich text sanitization and safe rendering

    Define allowed markup, sanitize with maintained tooling, and preserve context-safe rendering.

    TypeScriptGo

Dependencies, build systems, and software supply chain

practitioner

Know what enters builds and reduce risk in dependencies and delivery pipelines.

  • practitioner authoring

    Dependency inventory and transitive risk

    Know what is in the build, where it came from, and which paths execute it.

  • practitioner authoring

    Vulnerability advisories and triage

    Consider affected versions, reachability, exposure, available fixes, and compensating controls.

  • practitioner authoring

    Lockfiles, registries, and package confusion

    Pin expected sources and prevent untrusted packages or namespaces from entering a build.

  • practitioner authoring

    Dependency updates and patch policy

    Automate discovery while retaining review, testing, and a way to respond quickly.

  • practitioner authoring

    Secrets committed to source control

    Detect exposed credentials, revoke and rotate them immediately, and remove them from future history without mistaking history rewriting for revocation.

  • practitioner authoring

    Typosquatting and malicious packages

    Verify package identity and provenance before adding dependencies.

  • practitioner authoring

    Build isolation and reproducibility

    Reduce ambient access and make artifacts traceable to reviewed source and build inputs.

  • practitioner authoring

    SBOMs and component provenance

    Produce useful component and build-origin records; distinguish inventory from a security guarantee.

  • practitioner authoring

    Artifact signing and verification

    Establish who produced an artifact and verify integrity at consumption.

  • practitioner authoring

    CI/CD secret exposure

    Use scoped, short-lived credentials and keep untrusted pull requests away from privileged secrets.

  • practitioner authoring

    Pipeline permissions and workflow injection

    Treat workflow files, actions, build scripts, and user-controlled parameters as executable attack surface.

  • practitioner authoring

    Third-party actions, plugins, and build extensions

    Pin and review external code that runs with pipeline privileges.

  • practitioner authoring

    Coordinated vulnerability disclosure and patch response

    Provide a safe reporting path, assess impact, ship fixes, and communicate clearly.

Browser, frontend, and privacy security

practitioner

Understand browser protections and preserve user privacy in client experiences.

  • practitioner authoring

    Same-origin policy and origin model

    Understand scheme, host, and port as browser isolation boundaries.

  • practitioner authoring

    CORS preflight and credentialed requests

    Configure explicit origin and credential behavior without using wildcard shortcuts for private data.

  • practitioner authoring

    postMessage and cross-window messaging

    Validate sender origin, source window, and message shape before trusting data from popups, frames, or embedded widgets.

    TypeScript
  • practitioner authoring

    Browser storage trade-offs

    Compare cookies, local storage, session storage, and in-memory state by threat and use case.

    TypeScript
  • practitioner authoring

    Content Security Policy deployment

    Start with report-only observation, remove unsafe allowances, and test real application flows.

  • practitioner authoring

    Subresource Integrity and third-party scripts

    Reduce the risk of changed remote assets and minimize the scripts trusted with page access.

  • practitioner authoring

    Referrer, permissions, and security headers

    Set browser policy deliberately and verify actual deployed responses.

  • practitioner authoring

    DOM clobbering and unsafe URL schemes

    Avoid named-property collisions and validate navigable or executable URLs.

    TypeScript
  • practitioner authoring

    Cross-site leaks and side channels

    Recognize that observable response differences can expose sensitive state across origins.

    TypeScript
  • practitioner authoring

    Privacy-preserving telemetry

    Avoid collecting secrets and sensitive personal data in analytics, logs, or replay tools.

    TypeScript

Runtime, infrastructure, and cloud security

advanced

Reduce the privileges and exposure of the systems that run the application.

  • advanced authoring

    Security configuration and hardened defaults

    Make secure configuration explicit, reviewable, environment-specific, and checked at startup.

  • advanced authoring

    Least privilege for application processes

    Limit database, filesystem, network, cloud, and operating-system permissions.

  • advanced authoring

    Memory safety and unsafe code

    Understand where unsafe and native boundaries—from Rust unsafe and Go cgo to Node extensions—bypass language safeguards and require explicit review.

    TypeScriptGo
  • advanced authoring

    Environment variables and secret stores

    Know exposure paths and choose a managed secret mechanism appropriate to deployment.

  • advanced authoring

    Containers and image hygiene

    Run as non-root where possible, minimize images, pin sources, and scan the resulting artifact.

  • advanced authoring

    Network segmentation and egress control

    Limit which components can reach each other and where an application can connect outbound.

  • advanced authoring

    Cloud IAM and workload identity

    Grant narrowly scoped access through identities rather than embedded static keys.

  • advanced authoring

    Database account and network security

    Separate application roles, restrict reachable services, and avoid administrative credentials at runtime.

  • advanced authoring

    Production and non-production separation

    Keep real data and production secrets out of developer machines, previews, and test fixtures.

  • advanced authoring

    Backups, restore, and ransomware resilience

    Protect backup access and prove recovery rather than assuming that a backup is usable.

  • advanced authoring

    Patch management and exposed services

    Inventory reachable components, prioritize fixes, and retire unused services.

  • advanced authoring

    Infrastructure as code review

    Treat permissions, network rules, storage exposure, and deployment configuration as code requiring review and tests.

Logging, detection, and incident response

advanced

Create useful signals, respond to security incidents, and learn from them.

  • advanced authoring

    Security event logging

    Record enough evidence to investigate while excluding credentials, tokens, and unnecessary personal data.

  • advanced authoring

    Authentication and authorization signals

    Capture useful events and context for detecting abuse without treating every failure as an incident.

  • advanced authoring

    Log integrity, access, and retention

    Protect logs from tampering, limit readers, and keep them only as long as justified.

  • advanced authoring

    Alert quality and operational ownership

    Give each alert a clear signal, severity, responder, and first action.

  • advanced authoring

    Vulnerability triage and severity

    Combine technical severity with reachability, exploitability, affected assets, and business impact.

  • advanced authoring

    Incident response roles and first steps

    Preserve evidence, contain impact, communicate, and restore service through a prepared process.

  • advanced authoring

    Credential and key compromise

    Revoke, rotate, identify use, invalidate sessions, and check downstream copies.

  • advanced authoring

    Security incident retrospectives

    Identify control and process gaps without reducing the review to blame or one patch.

  • advanced authoring

    Vulnerability disclosure handling

    Receive reports safely, acknowledge them, reproduce in authorized environments, and coordinate a fix.

  • advanced authoring

    Tabletop exercises and response readiness

    Rehearse realistic scenarios and record what people, access, or telemetry were missing.

Governance, assurance, and certification crosswalk

advanced

Connect engineering practices to versioned verification standards and exam objectives.

  • advanced authoring

    Security policies versus implemented controls

    A written policy is not evidence that a control works in code or operations.

  • advanced authoring

    Secure development lifecycle

    Place requirements, review, testing, release, and vulnerability response across the software lifecycle.

  • advanced authoring

    OWASP ASVS as a verification catalog

    Use versioned requirements to plan and check web application controls; scope the verification level to the system.

  • advanced authoring

    OWASP Top 10 and common risk taxonomies

    Use risk lists as awareness and prioritization aids, not complete curricula or pass/fail standards.

  • advanced authoring

    NIST SSDF practices in a small team

    Translate outcome-oriented secure development practices into proportionate team habits.

  • advanced authoring

    Evidence, audit trails, and control ownership

    Connect a control to a person, system evidence, review cadence, and remediation process.

  • advanced authoring

    Risk acceptance and exceptions

    Record who accepts residual risk, for how long, with what compensating controls and review date.

  • advanced authoring

    Security roles and shared responsibility

    Clarify product, engineering, operations, security, and provider responsibilities.

  • advanced authoring

    CompTIA Security+ crosswalk

    Optional exam-oriented index for applicable security foundations, threats, architecture, operations, and governance topics.

  • advanced authoring

    CompTIA CySA+ crosswalk

    Optional analyst-oriented index for monitoring, vulnerability management, incident response, and threat analysis.

  • advanced authoring

    Exam objective versioning

    State the exam code and objectives version beside every mapping; never imply the catalog alone prepares someone to pass.

  • advanced authoring

    Jurisdiction- and standard-specific compliance

    Link out to separately maintained, dated material rather than presenting one universal compliance checklist.