AppSec is all about protecting your application from the adversaries such as SAST, SCA, Secure Code Review, Security Architecture etc. Attacking an app can fall under web or app pentest
- Agile Application Security - Highly Recommended
- The Web Application Hacker's Handbook
- Threat Modeling: Designing for Security or
- Threat Modeling: A practical guide for development teams
- The Tangled Web
- Web Security for Developers: Real Threats, Practical Defense
- Web Application Security: Exploitation and Countermeasures for Modern Web Applications
- Application Security Program Handbook: A Guide for Software Engineers and Team Leaders
- Enterprise Security Architect
- Youtube video on semgrep's taint mode
- OWASP Global AppSec conference talks
- LocoMoco Security Conf - AppSec deep dives
- Clint Gibler (tl;dr sec) talks on scaling AppSec
- LiveOverflow - deep web/binary exploitation
- PwnFunction - web vuln concepts
- IppSec - HackTheBox walkthroughs
- PortSwigger Web Security Academy (free)
- OWASP Juice Shop Companion Guide (free)
- SANS SEC540: Cloud Security and DevSecOps Automation
- SANS SEC522: Defending Web Applications Security Essentials
- SANS SEC540 / SEC542 / SEC642
- Practical DevSecOps - Certified Application Security Practitioner
- AppSec Engineer by We Hack Purple / Tanya Janca
- Pentester Academy - AppSec paths
- Coursera - Software Security (University of Maryland)
- application.security - free gamified challenges on API, Web, Cloud, front-end.
- Secure Code Warrior - Commercial developer training.
- Security Journey (formerly HackEDU)
- OWASP Juice Shop - Most popular intentionally vulnerable web app.
- PentesterLab - Hands-on exercises.
- GitHub Security Lab CTF
- Google Gruyere
- Django.nv
- DVWA - Damn Vulnerable Web App
- WebGoat - OWASP's legacy but still useful Java learning app.
- OWASP Security Shepherd
- HackMyVM - Free boot2root style VMs.
- Root-Me - Large CTF-style challenges repository.
- Vulnerable Web Applications Directory by OWASP
It will include tools for SAST, SCA, OAST, Threat Modeling, Secure Code Review, secrets management etc
Open source
- SonarQube
- Bandit (Python)
- Brakeman (Ruby on Rails)
- FindSecBugs / SpotBugs (Java)
- Semgrep (multi-language, customizable rules)
- CodeQL (semantic, free for OSS)
- gosec (Go)
- njsscan (Node.js)
Paid 9. Checkmarx One 10. Veracode 11. Snyk Code 12. Coverity (Black Duck) 13. Fortify by OpenText
- OWASP Dependency-Check
- OWASP Dependency-Track - SBOM-centric continuous monitoring.
- Retire.js
- CycloneDX CLI - SBOM generation/manipulation.
- Syft - SBOM generator.
- Trivy - Scans dependencies across many ecosystems.
- Snyk Open Source
- Checkmarx SCA
- JFrog Xray
- Socket.dev - Supply-chain / malicious package detection for npm, PyPI.
- gitleaks
- TruffleHog
- Talisman
- detect-secrets (Yelp)
- git-secrets (AWS)
- Repo-supervisor - (maintenance mode)
- HashiCorp Vault
- CyberArk Conjur
- GitGuardian - commercial scanning.
- OWASP ThreatDragon
- SDElements
- IriusRisk
- Threagile
- ThreatModeler
- Microsoft Threat Modeling tool
- STRIDE GPT
- ThreatSpec
- PyTM
- CISSP - Certified Information Systems Security Professional
- CSSLP Certified Secure Software Lifecycle Professional
- ISSAP – Information Systems Security Architecture Professional
- CASE (Certified Application Security Engineer) Java or CASE .Net
- CompTIA SecurityX (formerly CASP+) - Rebranded Dec 2024; exam CAS-005.
- Scaling your AppSec Program with semgrep
- TOP 10 THINGS TO KNOW ABOUT SECURITY AS A SOFTWARE ARCHITECT
- System Design for Security
- Top 25 software security errors
- Security prioritization
- CWE top 25 2023 list
- Open Policy Agent (OPA) documentation
- semgrep documentation
- MITRE ATT&CK and Defender (MAD) Program
- A dive into web application authentication
- Taint Analysis or Taint Checking
- log4j vulnerability walkthrough
- Zero day exploitation of confluence
- Python cryptography library (pyca/cryptography) - use this instead of the deprecated PyCrypto
- Secure Coding with Python
- OWASP Python Security Project (archived but still referenced)
- Hacking Python Application
- Secure Design Principles
- OWASP ASVS (Application Security Verification Standard)
- OWASP SAMM (Software Assurance Maturity Model)
- OWASP Cheat Sheet Series
- OWASP Proactive Controls
- tl;dr sec newsletter by Clint Gibler
- We Hack Purple AppSec Podcast
- CWE Top 25 Most Dangerous Software Weaknesses (latest)
- OWASP Top 10 2025 - Updated Jan 2026; Security Misconfiguration at #2, Supply Chain Failures at #3 (new), SSRF merged into Broken Access Control.
