Skip to content

Repository files navigation

AppSec Atlas Logo

πŸ—ΊοΈ AppSec Atlas

An Open-Source Security Knowledge Base Across the Full AppSec Landscape

Map the entire security landscape. One repo. Zero excuses.

License: CC BY 4.0 Guides Website GitHub Stars PRs Welcome


🌐 Live Site Β· πŸ“š Browse Guides Β· πŸ—ΊοΈ Learning Paths Β· 🀝 Contribute Β· πŸ’¬ Discord Β· πŸ’– Sponsor Β· β˜• Ko-fi


πŸš€ AppSec Atlas is now live at appsecatlas.com! β€” Star ⭐ the repo to help others discover it.

🌟 Why AppSec Atlas?

AppSec Atlas is the only open-source security knowledge base that covers the full spectrum of modern security β€” from timeless application security fundamentals to the bleeding edge of AI/LLM security.

Feature AppSec Atlas Other Resources
Covers AI/LLM Security deeply βœ… ❌
Real code β€” exploits AND fixes βœ… Partial
MCP & Agentic AI Security βœ… ❌
Hands-on Docker labs βœ… Partial
Role-based learning paths βœ… Partial
100% Free, no paywalls βœ… βœ…
Active community & Discord βœ… Varies

54 guides. 9 security domains. One atlas.


πŸ“š Guides

Core concepts every security professional and developer must know

Guide Status Level
OWASP Top 10 Deep Dive βœ… Available Beginner
Secure Coding Practices βœ… Available Beginner
Cryptography for Developers βœ… Available Intermediate
Post-Quantum Cryptography βœ… Available Advanced
Authentication & Authorization Masterclass βœ… Available Intermediate
Zero Trust Architecture Guide βœ… Available Advanced
Security Design Patterns βœ… Available Intermediate

From classic web vulnerabilities to modern API attack surfaces

Guide Status Level
Web Application Security Handbook βœ… Available Intermediate
API Security Guide βœ… Available Intermediate
Modern API Identity βœ… Available Advanced
Frontend Security Playbook βœ… Available Intermediate
Mobile App Security Guide βœ… Available Intermediate
CORS & Same-Origin Policy Explained βœ… Available Beginner

Securing modern cloud-native and infrastructure environments

Guide Status Level
Cloud Security Fundamentals βœ… Available Intermediate
Cross-Cloud IAM Federation βœ… Available Advanced
Confidential Computing Enclaves βœ… Available Advanced
Cloud Zero-Day Playbooks βœ… Available Advanced
Container & Kubernetes Security βœ… Available Intermediate
Kubernetes & eBPF Runtime Security βœ… Available Advanced
Infrastructure as Code Security βœ… Available Intermediate
Serverless Security Guide βœ… Available Intermediate
CI/CD Pipeline Security βœ… Available Intermediate
Secrets Management Guide βœ… Available Intermediate

πŸ€– Section 4: AI/ML Security ⭐ Our Flagship

The most comprehensive open-source AI security resource β€” from LLMs to agentic systems

Guide Status Level
Agentic AI Security Guide βœ… Available Advanced
LLM Security & Prompt Injection βœ… Available Intermediate
ML Model Security & Adversarial Attacks βœ… Available Advanced
RAG Security Guide βœ… Available Advanced
AI Red Teaming Playbook βœ… Available Advanced
MCP & Tool-Use Security βœ… Available Advanced

Red team techniques, penetration testing, and ethical hacking

Guide Status Level
Penetration Testing Methodology βœ… Available Intermediate
Enterprise Security Assessment βœ… Available Advanced
Social Engineering & Phishing βœ… Available Beginner
Network Security & Attack Techniques βœ… Available Intermediate
Bug Bounty Hunting Guide βœ… Available Intermediate
CTF Learning Guide βœ… Available Beginner

Blue team playbooks, incident response, and security operations

Guide Status Level
Incident Response Playbook βœ… Available Intermediate
Security Chaos Engineering βœ… Available Advanced
Security Logging & Monitoring βœ… Available Intermediate
Digital Forensics Basics βœ… Available Intermediate
Vulnerability Management Guide βœ… Available Intermediate
SOC Operations Guide βœ… Available Advanced

Hardware, IoT, Blockchain, and Supply Chain security

Guide Status Level
Software Supply Chain Security βœ… Available Advanced
Blockchain & Smart Contract Security βœ… Available Advanced
IoT Security Guide βœ… Available Intermediate
Privacy Engineering Guide βœ… Available Intermediate
Hardware Security Basics βœ… Available Advanced
Browser Extension Security βœ… Available Intermediate

Frameworks, standards, and regulatory compliance

Guide Status Level
NIST Cybersecurity Framework Guide βœ… Available Intermediate
SOC 2 Compliance Guide βœ… Available Intermediate
GDPR Technical Implementation βœ… Available Intermediate
DevSecOps Handbook βœ… Available Intermediate

Practice makes perfect β€” build your skills with real exercises

Guide Status Level
CTF Challenge Set βœ… Available All Levels
Vulnerable App Lab βœ… Available All Levels
Security Code Review Guide βœ… Available Intermediate

πŸ—ΊοΈ Learning Paths

Not sure where to start? Pick your role:

I am a... Start here
πŸ§‘β€πŸ’» Developer wanting to write secure code Secure Coding β†’ OWASP Top 10 β†’ API Security
☁️ Cloud Engineer Secrets Management β†’ CI/CD Security β†’ Cloud Security
πŸ€– AI/ML Engineer Agentic AI Security β†’ LLM Security β†’ RAG Security
πŸ”΄ Aspiring Pentester OWASP Top 10 β†’ Web App Security β†’ Pentest Methodology
πŸ”΅ Blue Teamer / SOC Analyst Logging & Monitoring β†’ IR Playbook β†’ Vulnerability Management
πŸŽ“ Complete Beginner OWASP Top 10 β†’ Auth & AuthZ β†’ CTF Guide

πŸ“‹ Checklists

Quick-reference printable checklists for common security tasks:


πŸš€ AppSec Ecosystem & Open-Source Projects

Check out our specialized open-source security tools and companion repositories:

Project Description Link
πŸ” DevCipher Premium Developer Cryptography & Security Toolkit Platform devcipher.dev Β· GitHub
πŸ€– Agentic AI Security Guide Specialized guide for securing autonomous AI agents, tool execution, and LLM orchestration GitHub Repo
πŸ›‘οΈ Threat Modelling Basics Practical frameworks, templates, and methodologies for threat modeling (STRIDE, PASTA, DREAD) GitHub Repo
βš›οΈ Quantum-Safe Py Python library implementing Post-Quantum Cryptography (NIST ML-KEM, ML-DSA, SLH-DSA) GitHub Repo
πŸ” Quantum Safe Auditor Automated SAST scanner for detecting quantum-vulnerable cryptography across codebase repositories GitHub Repo

⭐ Explore and star these companion projects to support the open-source security ecosystem!


🀝 Contributing

AppSec Atlas is built by the community, for the community. Every contribution matters.

Ways to contribute:

  • ✍️ Write or improve a guide
  • πŸ› Fix errors, typos, outdated information
  • πŸ§ͺ Add lab exercises or CTF challenges
  • 🌍 Translate guides to other languages
  • ⭐ Star the repo and spread the word

Read CONTRIBUTING.md to get started. First-time contributors: look for issues labeled good first issue.


πŸ’ Support This Project

AppSec Atlas is 100% free and open-source. If this project has saved you time, helped you pass an audit, or advanced your career, consider supporting ongoing research:

  • πŸ’– GitHub Sponsors β€” Become a monthly sponsor to sustain ongoing research & development
  • β˜• Ko-fi β€” Buy the author a coffee to show your appreciation
  • ⭐ Star this repository β€” Help more security engineers and developers discover the Atlas

πŸ“œ License

All guides and content in this repository are licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).

You are free to share and adapt the material for any purpose, even commercially, as long as you give appropriate credit.


Built with ❀️ by the security community, for the security community.

🌐 appsecatlas.com Β· πŸ’¬ Discord Β· πŸ’– GitHub Sponsors Β· β˜• Ko-fi

If AppSec Atlas helped you, please ⭐ star it to help others find it.

About

Open-source application security knowledge base: 54 modules across web & API, cloud, AI/ML, offensive, defensive and compliance security.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Used by

Contributors

Languages