Skip to content

Repository files navigation

AppSec Atlas Logo

🗺️ AppSec Atlas

The World's Most Comprehensive Open-Source Security Knowledge Base

Map the entire security landscape. One repo. Zero excuses.

License: CC BY 4.0 Guides Website GitHub Stars PRs Welcome


🌐 Live Site · 📚 Browse Guides · 🗺️ Learning Paths · 🤝 Contribute · 💬 Discord · 💖 Sponsor · ☕ Ko-fi


🚀 AppSec Atlas is now live at appsecatlas.com! — Star ⭐ the repo to help others discover it.

🌟 Why AppSec Atlas?

AppSec Atlas is the only open-source security knowledge base that covers the full spectrum of modern security — from timeless application security fundamentals to the bleeding edge of AI/LLM security.

Feature AppSec Atlas Other Resources
Covers AI/LLM Security deeply
Real code — exploits AND fixes Partial
MCP & Agentic AI Security
Hands-on Docker labs Partial
Role-based learning paths Partial
100% Free, no paywalls
Active community & Discord Varies

54 guides. 9 security domains. One atlas.


📚 Guides

Core concepts every security professional and developer must know

Guide Status Level
OWASP Top 10 Deep Dive ✅ Available Beginner
Secure Coding Practices ✅ Available Beginner
Cryptography for Developers ✅ Available Intermediate
Post-Quantum Cryptography ✅ Available Advanced
Authentication & Authorization Masterclass ✅ Available Intermediate
Zero Trust Architecture Guide ✅ Available Advanced
Security Design Patterns ✅ Available Intermediate

From classic web vulnerabilities to modern API attack surfaces

Guide Status Level
Web Application Security Handbook ✅ Available Intermediate
API Security Guide ✅ Available Intermediate
Modern API Identity ✅ Available Advanced
Frontend Security Playbook ✅ Available Intermediate
Mobile App Security Guide ✅ Available Intermediate
CORS & Same-Origin Policy Explained ✅ Available Beginner

Securing modern cloud-native and infrastructure environments

Guide Status Level
Cloud Security Fundamentals ✅ Available Intermediate
Cross-Cloud IAM Federation ✅ Available Advanced
Confidential Computing Enclaves ✅ Available Advanced
Cloud Zero-Day Playbooks ✅ Available Advanced
Container & Kubernetes Security ✅ Available Intermediate
Kubernetes & eBPF Runtime Security ✅ Available Advanced
Infrastructure as Code Security ✅ Available Intermediate
Serverless Security Guide ✅ Available Intermediate
CI/CD Pipeline Security ✅ Available Intermediate
Secrets Management Guide ✅ Available Intermediate

🤖 Section 4: AI/ML SecurityOur Flagship

The most comprehensive open-source AI security resource — from LLMs to agentic systems

Guide Status Level
Agentic AI Security Guide ✅ Available Advanced
LLM Security & Prompt Injection ✅ Available Intermediate
ML Model Security & Adversarial Attacks ✅ Available Advanced
RAG Security Guide ✅ Available Advanced
AI Red Teaming Playbook ✅ Available Advanced
MCP & Tool-Use Security ✅ Available Advanced

Red team techniques, penetration testing, and ethical hacking

Guide Status Level
Penetration Testing Methodology ✅ Available Intermediate
Enterprise Security Assessment ✅ Available Advanced
Social Engineering & Phishing ✅ Available Beginner
Network Security & Attack Techniques ✅ Available Intermediate
Bug Bounty Hunting Guide ✅ Available Intermediate
CTF Learning Guide ✅ Available Beginner

Blue team playbooks, incident response, and security operations

Guide Status Level
Incident Response Playbook ✅ Available Intermediate
Security Chaos Engineering ✅ Available Advanced
Security Logging & Monitoring ✅ Available Intermediate
Digital Forensics Basics ✅ Available Intermediate
Vulnerability Management Guide ✅ Available Intermediate
SOC Operations Guide ✅ Available Advanced

Hardware, IoT, Blockchain, and Supply Chain security

Guide Status Level
Software Supply Chain Security ✅ Available Advanced
Blockchain & Smart Contract Security ✅ Available Advanced
IoT Security Guide ✅ Available Intermediate
Privacy Engineering Guide ✅ Available Intermediate
Hardware Security Basics ✅ Available Advanced
Browser Extension Security ✅ Available Intermediate

Frameworks, standards, and regulatory compliance

Guide Status Level
NIST Cybersecurity Framework Guide ✅ Available Intermediate
SOC 2 Compliance Guide ✅ Available Intermediate
GDPR Technical Implementation ✅ Available Intermediate
DevSecOps Handbook ✅ Available Intermediate

Practice makes perfect — build your skills with real exercises

Guide Status Level
CTF Challenge Set ✅ Available All Levels
Vulnerable App Lab ✅ Available All Levels
Security Code Review Guide ✅ Available Intermediate

🗺️ Learning Paths

Not sure where to start? Pick your role:

I am a... Start here
🧑‍💻 Developer wanting to write secure code Secure CodingOWASP Top 10API Security
☁️ Cloud Engineer Secrets ManagementCI/CD SecurityCloud Security
🤖 AI/ML Engineer Agentic AI SecurityLLM SecurityRAG Security
🔴 Aspiring Pentester OWASP Top 10Web App SecurityPentest Methodology
🔵 Blue Teamer / SOC Analyst Logging & MonitoringIR PlaybookVulnerability Management
🎓 Complete Beginner OWASP Top 10Auth & AuthZCTF Guide

📋 Checklists

Quick-reference printable checklists for common security tasks:


🚀 AppSec Ecosystem & Open-Source Projects

Check out our specialized open-source security tools and companion repositories:

Project Description Link
🔐 DevCipher Premium Developer Cryptography & Security Toolkit Platform devcipher.dev · GitHub
🤖 Agentic AI Security Guide Specialized guide for securing autonomous AI agents, tool execution, and LLM orchestration GitHub Repo
🛡️ Threat Modelling Basics Practical frameworks, templates, and methodologies for threat modeling (STRIDE, PASTA, DREAD) GitHub Repo
⚛️ Quantum-Safe Py Python library implementing Post-Quantum Cryptography (NIST ML-KEM, ML-DSA, SLH-DSA) GitHub Repo
🔍 Quantum Safe Auditor Automated SAST scanner for detecting quantum-vulnerable cryptography across codebase repositories GitHub Repo

Explore and star these companion projects to support the open-source security ecosystem!


🤝 Contributing

AppSec Atlas is built by the community, for the community. Every contribution matters.

Ways to contribute:

  • ✍️ Write or improve a guide
  • 🐛 Fix errors, typos, outdated information
  • 🧪 Add lab exercises or CTF challenges
  • 🌍 Translate guides to other languages
  • ⭐ Star the repo and spread the word

Read CONTRIBUTING.md to get started. First-time contributors: look for issues labeled good first issue.


💝 Support This Project

AppSec Atlas is 100% free and open-source. If this project has saved you time, helped you pass an audit, or advanced your career, consider supporting ongoing research:

  • 💖 GitHub Sponsors — Become a monthly sponsor to sustain ongoing research & development
  • Ko-fi — Buy the author a coffee to show your appreciation
  • Star this repository — Help more security engineers and developers discover the Atlas

📜 License

All guides and content in this repository are licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).

You are free to share and adapt the material for any purpose, even commercially, as long as you give appropriate credit.


Built with ❤️ by the security community, for the security community.

🌐 appsecatlas.com · 💬 Discord · 💖 GitHub Sponsors · ☕ Ko-fi

If AppSec Atlas helped you, please ⭐ star it to help others find it.