Map the entire security landscape. One repo. Zero excuses.
🌐 Live Site · 📚 Browse Guides · 🗺️ Learning Paths · 🤝 Contribute · 💬 Discord · 💖 Sponsor · ☕ Ko-fi
🚀 AppSec Atlas is now live at appsecatlas.com! — Star ⭐ the repo to help others discover it.
AppSec Atlas is the only open-source security knowledge base that covers the full spectrum of modern security — from timeless application security fundamentals to the bleeding edge of AI/LLM security.
| Feature | AppSec Atlas | Other Resources |
|---|---|---|
| Covers AI/LLM Security deeply | ✅ | ❌ |
| Real code — exploits AND fixes | ✅ | Partial |
| MCP & Agentic AI Security | ✅ | ❌ |
| Hands-on Docker labs | ✅ | Partial |
| Role-based learning paths | ✅ | Partial |
| 100% Free, no paywalls | ✅ | ✅ |
| Active community & Discord | ✅ | Varies |
54 guides. 9 security domains. One atlas.
Core concepts every security professional and developer must know
| Guide | Status | Level |
|---|---|---|
| OWASP Top 10 Deep Dive | ✅ Available | Beginner |
| Secure Coding Practices | ✅ Available | Beginner |
| Cryptography for Developers | ✅ Available | Intermediate |
| Post-Quantum Cryptography | ✅ Available | Advanced |
| Authentication & Authorization Masterclass | ✅ Available | Intermediate |
| Zero Trust Architecture Guide | ✅ Available | Advanced |
| Security Design Patterns | ✅ Available | Intermediate |
From classic web vulnerabilities to modern API attack surfaces
| Guide | Status | Level |
|---|---|---|
| Web Application Security Handbook | ✅ Available | Intermediate |
| API Security Guide | ✅ Available | Intermediate |
| Modern API Identity | ✅ Available | Advanced |
| Frontend Security Playbook | ✅ Available | Intermediate |
| Mobile App Security Guide | ✅ Available | Intermediate |
| CORS & Same-Origin Policy Explained | ✅ Available | Beginner |
Securing modern cloud-native and infrastructure environments
| Guide | Status | Level |
|---|---|---|
| Cloud Security Fundamentals | ✅ Available | Intermediate |
| Cross-Cloud IAM Federation | ✅ Available | Advanced |
| Confidential Computing Enclaves | ✅ Available | Advanced |
| Cloud Zero-Day Playbooks | ✅ Available | Advanced |
| Container & Kubernetes Security | ✅ Available | Intermediate |
| Kubernetes & eBPF Runtime Security | ✅ Available | Advanced |
| Infrastructure as Code Security | ✅ Available | Intermediate |
| Serverless Security Guide | ✅ Available | Intermediate |
| CI/CD Pipeline Security | ✅ Available | Intermediate |
| Secrets Management Guide | ✅ Available | Intermediate |
🤖 Section 4: AI/ML Security ⭐ Our Flagship
The most comprehensive open-source AI security resource — from LLMs to agentic systems
| Guide | Status | Level |
|---|---|---|
| Agentic AI Security Guide | ✅ Available | Advanced |
| LLM Security & Prompt Injection | ✅ Available | Intermediate |
| ML Model Security & Adversarial Attacks | ✅ Available | Advanced |
| RAG Security Guide | ✅ Available | Advanced |
| AI Red Teaming Playbook | ✅ Available | Advanced |
| MCP & Tool-Use Security | ✅ Available | Advanced |
Red team techniques, penetration testing, and ethical hacking
| Guide | Status | Level |
|---|---|---|
| Penetration Testing Methodology | ✅ Available | Intermediate |
| Enterprise Security Assessment | ✅ Available | Advanced |
| Social Engineering & Phishing | ✅ Available | Beginner |
| Network Security & Attack Techniques | ✅ Available | Intermediate |
| Bug Bounty Hunting Guide | ✅ Available | Intermediate |
| CTF Learning Guide | ✅ Available | Beginner |
Blue team playbooks, incident response, and security operations
| Guide | Status | Level |
|---|---|---|
| Incident Response Playbook | ✅ Available | Intermediate |
| Security Chaos Engineering | ✅ Available | Advanced |
| Security Logging & Monitoring | ✅ Available | Intermediate |
| Digital Forensics Basics | ✅ Available | Intermediate |
| Vulnerability Management Guide | ✅ Available | Intermediate |
| SOC Operations Guide | ✅ Available | Advanced |
Hardware, IoT, Blockchain, and Supply Chain security
| Guide | Status | Level |
|---|---|---|
| Software Supply Chain Security | ✅ Available | Advanced |
| Blockchain & Smart Contract Security | ✅ Available | Advanced |
| IoT Security Guide | ✅ Available | Intermediate |
| Privacy Engineering Guide | ✅ Available | Intermediate |
| Hardware Security Basics | ✅ Available | Advanced |
| Browser Extension Security | ✅ Available | Intermediate |
Frameworks, standards, and regulatory compliance
| Guide | Status | Level |
|---|---|---|
| NIST Cybersecurity Framework Guide | ✅ Available | Intermediate |
| SOC 2 Compliance Guide | ✅ Available | Intermediate |
| GDPR Technical Implementation | ✅ Available | Intermediate |
| DevSecOps Handbook | ✅ Available | Intermediate |
Practice makes perfect — build your skills with real exercises
| Guide | Status | Level |
|---|---|---|
| CTF Challenge Set | ✅ Available | All Levels |
| Vulnerable App Lab | ✅ Available | All Levels |
| Security Code Review Guide | ✅ Available | Intermediate |
Not sure where to start? Pick your role:
| I am a... | Start here |
|---|---|
| 🧑💻 Developer wanting to write secure code | Secure Coding → OWASP Top 10 → API Security |
| ☁️ Cloud Engineer | Secrets Management → CI/CD Security → Cloud Security |
| 🤖 AI/ML Engineer | Agentic AI Security → LLM Security → RAG Security |
| 🔴 Aspiring Pentester | OWASP Top 10 → Web App Security → Pentest Methodology |
| 🔵 Blue Teamer / SOC Analyst | Logging & Monitoring → IR Playbook → Vulnerability Management |
| 🎓 Complete Beginner | OWASP Top 10 → Auth & AuthZ → CTF Guide |
Quick-reference printable checklists for common security tasks:
- 📄 Web Application Security Checklist
- 📄 API Security Checklist
- 📄 Cloud Deployment Checklist
- 📄 Code Review Security Checklist
- 📄 Incident Response Checklist
Check out our specialized open-source security tools and companion repositories:
| Project | Description | Link |
|---|---|---|
| 🔐 DevCipher | Premium Developer Cryptography & Security Toolkit Platform | devcipher.dev · GitHub |
| 🤖 Agentic AI Security Guide | Specialized guide for securing autonomous AI agents, tool execution, and LLM orchestration | GitHub Repo |
| 🛡️ Threat Modelling Basics | Practical frameworks, templates, and methodologies for threat modeling (STRIDE, PASTA, DREAD) | GitHub Repo |
| ⚛️ Quantum-Safe Py | Python library implementing Post-Quantum Cryptography (NIST ML-KEM, ML-DSA, SLH-DSA) | GitHub Repo |
| 🔍 Quantum Safe Auditor | Automated SAST scanner for detecting quantum-vulnerable cryptography across codebase repositories | GitHub Repo |
⭐ Explore and star these companion projects to support the open-source security ecosystem!
AppSec Atlas is built by the community, for the community. Every contribution matters.
Ways to contribute:
- ✍️ Write or improve a guide
- 🐛 Fix errors, typos, outdated information
- 🧪 Add lab exercises or CTF challenges
- 🌍 Translate guides to other languages
- ⭐ Star the repo and spread the word
Read CONTRIBUTING.md to get started. First-time contributors: look for issues labeled good first issue.
AppSec Atlas is 100% free and open-source. If this project has saved you time, helped you pass an audit, or advanced your career, consider supporting ongoing research:
- 💖 GitHub Sponsors — Become a monthly sponsor to sustain ongoing research & development
- ☕ Ko-fi — Buy the author a coffee to show your appreciation
- ⭐ Star this repository — Help more security engineers and developers discover the Atlas
All guides and content in this repository are licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).
You are free to share and adapt the material for any purpose, even commercially, as long as you give appropriate credit.
Built with ❤️ by the security community, for the security community.
🌐 appsecatlas.com · 💬 Discord · 💖 GitHub Sponsors · ☕ Ko-fi
If AppSec Atlas helped you, please ⭐ star it to help others find it.