Security
Once by the book.
Safer code, by design.
A practical map of software security, from threat modeling and secure coding to identity, AI application security, testing, delivery, and incident response.
Work in progress. The first lessons are available to explore. The rest of the catalog is still taking shape.
Taking shape Ready lessons are open to explore alongside planned and in-progress topics.
Security mindset and core vocabulary
foundationBuild a practical vocabulary for reasoning about software risk and controls.
Security goals: confidentiality, integrity, availability
Which property a control protects, and what it cannot protect.
Assets, actors, trust boundaries, and attack surface
Start from what matters, who can influence it, and where data crosses ownership.
Threat, vulnerability, exploit, impact, and risk
Distinguish a weakness from its possible use and consequence.
Least privilege and secure defaults
Grant only the access needed; make the safe path the default.
Defense in depth and security boundaries
Layer controls without treating any single layer as a substitute for the others.
Fail open or fail closed
Choose behavior when a control or dependency is unavailable, based on the protected action.
Security by design versus security by obscurity
Keep useful design secrecy distinct from controls that must hold even when implementation is known.
Threat modeling and secure design
foundationStart with assets and boundaries; use threats to decide which controls matter.
Threat modeling a small feature
Identify assets, actors, boundaries, abuse cases, and the controls that change the risk.
Data-flow diagrams and trust boundaries
Draw only the flows needed to make security assumptions visible and reviewable.
STRIDE and alternative threat prompts
Use a structured prompt as a completeness aid, not as a scoring oracle.
Abuse cases and business logic
Ask how a valid feature can be misused, combined, repeated, or accessed out of sequence.
Security requirements and acceptance criteria
Turn risks into explicit, testable requirements before implementation.
Secure architecture decisions
Record assumptions, rejected options, residual risk, and revisit triggers.
Attack surface reduction
Remove unused routes, permissions, dependencies, endpoints, and data.
Third-party and integration trust
Define what each provider may send, read, change, and trigger.
Privacy and security design review
Include data minimization, user expectations, and misuse impact alongside technical controls.
Lightweight threat-model review in pull requests
Revisit the model when a change adds a new boundary, privilege, data type, or external dependency.
Web and API trust boundaries
foundationIdentify the trust boundaries where web requests and data enter the system.
The browser is an untrusted client
UI state and client-side checks can improve experience but cannot authorize a server action.
TypeScriptGoTrace untrusted data end to end
Follow a value from URL, form, header, cookie, or webhook to every sink that uses it.
TypeScriptGoParse, validate, normalize, and encode are different
Validate data for its domain; encode for the output context; avoid treating these steps as interchangeable.
TypeScriptGoAllowlist validation and bounded input
Define accepted shapes, sizes, ranges, and formats at each boundary.
TypeScriptGoCanonicalization and double-decoding bugs
Agree on one representation before validation and use; reject ambiguous encodings.
TypeScriptGoHTTP security-relevant behavior
Understand methods, status codes, headers, cookies, origins, caching, redirects, and content types as part of the security contract.
TypeScriptGoClient-side versus server-side validation
Duplicate user-friendly checks when useful, but enforce the actual security rule at the trusted boundary.
TypeScriptGoError messages and information leakage
Return useful errors without disclosing secrets, stack traces, internal topology, or account existence unnecessarily.
TypeScriptGo
Output handling and injection
foundationKeep untrusted data from becoming executable code or query structure.
Reflected, stored, and DOM-based XSS
Where attacker-controlled content enters and how it reaches an executable browser context.
TypeScriptGoContextual output encoding
HTML text, attributes, URLs, JavaScript, CSS, and rich text require different safe handling.
TypeScriptGoSafe DOM APIs and dangerous HTML escape hatches
Prefer text and structured APIs; isolate and sanitize rich HTML when it is genuinely required.
TypeScriptFramework escaping and its limits
Know what a framework escapes automatically and identify raw HTML, unsafe URL, and template escape hatches.
TypeScriptNoSQL and search-query injection
Treat query operators and search syntax as untrusted structure, not harmless strings.
TypeScriptGoOS command injection
Avoid shell construction; call a process with argument arrays and constrained inputs when process execution is necessary.
TypeScriptGoTemplate, expression, and code injection
Separate data from executable templates and avoid evaluating untrusted expressions.
TypeScriptGoLDAP, XPath, and other interpreter injection
Recognize that every interpreter needs its own parameterization or safe construction strategy.
TypeScriptGoHeader, CRLF, and log injection
Keep untrusted values from creating response headers, splitting messages, or forging log records.
TypeScriptGoDeserialization and object construction
Avoid unsafe polymorphic deserialization; constrain types and validate parsed data.
TypeScriptGoPrototype pollution
Prevent attacker-controlled object keys from changing inherited properties, configuration, or later authorization checks in JavaScript.
TypeScriptReDoS and parser complexity
Bound input and algorithmic work so valid-looking inputs cannot monopolize CPU or memory.
TypeScriptGo
Authentication, credentials, and sessions
practitionerProtect account access, credentials, and the sessions that represent a user.
Password storage and verification
Use a maintained password-hashing function with its intended salt and work parameters; never encrypt or fast-hash passwords as a substitute.
TypeScriptGoLogin abuse and credential stuffing
Combine throttling, abuse signals, MFA, and safe recovery without creating easy denial-of-service lockouts.
TypeScriptGoMulti-factor authentication and passkeys
Understand factor independence, phishing resistance, recovery, and the risk of weak fallback paths.
TypeScriptGoAccount recovery and password reset
Use short-lived, single-use reset capabilities; avoid account enumeration and insecure reset questions.
TypeScriptGoSession identifiers and entropy
Generate unpredictable session identifiers with cryptographic randomness.
TypeScriptGoCSRF and same-site request defenses
Protect cookie-authenticated state changes with an explicit request-origin strategy.
TypeScriptGoOAuth 2.0 and OpenID Connect roles
Distinguish authorization from authentication and keep client, resource server, and identity provider responsibilities clear.
TypeScriptGoAPI keys, bearer tokens, and signed tokens
Decide who can see a credential, its scope and lifetime, and how it is revoked; never treat a decoded token as trusted.
TypeScriptGoService identities and workload credentials
Prefer short-lived, narrowly scoped machine identity over copied long-lived secrets.
TypeScriptGoSensitive-action confirmation and reauthentication
Add stronger proof for account, payment, or permission changes where risk justifies it.
TypeScriptGo
Data protection and cryptography
practitionerChoose sound ways to protect sensitive data, secrets, and cryptographic keys.
Data classification and minimization
Collect, retain, expose, and log only what the feature needs.
TLS, certificate validation, and trust stores
Verify peers and configure the transport; encryption without correct certificate validation is incomplete.
TypeScriptGoEncryption at rest and field-level protection
Choose what is protected from which threat and account for application access to decryption keys.
TypeScriptGoHashing, encryption, encoding, and signing
Explain the distinct security properties each operation provides.
Cryptographically secure randomness
Use platform cryptographic APIs for tokens, reset links, and unpredictable secrets—not general-purpose PRNGs.
TypeScriptGoKey lifecycle and key management
Generate, store, grant access to, rotate, back up, and retire keys deliberately.
TypeScriptGoTiming attacks and constant-time comparison
Avoid leaking secrets through data-dependent comparison or other observable timing where constant-time primitives are appropriate.
TypeScriptGoMessage authentication and digital signatures
Verify integrity and sender authenticity without confusing signatures with encryption.
TypeScriptGoNonces, IVs, and authenticated encryption
Use library-managed, unique parameters and authenticated modes; never invent a crypto protocol.
TypeScriptGoToken and URL leakage
Keep credentials out of URLs, referrers, analytics, error reports, and logs.
TypeScriptGoBackups, deletion, and cryptographic erasure
Align copies, retention, access, and key destruction with the data lifecycle.
API, workflow, and abuse resistance
practitionerProtect APIs and business workflows from unauthorized use and resource abuse.
Request size, pagination, and resource limits
Bound payloads, nested structures, result sizes, and expensive operations.
TypeScriptGoRate limiting and abuse controls
Apply limits to the right identity and operation while considering distributed clients and shared infrastructure.
TypeScriptGoIdempotency and replay resistance
Make retries safe and protect sensitive one-time actions from replay.
TypeScriptGoWorkflow and business-logic abuse
Validate allowed state transitions on the server, not just individual fields.
TypeScriptGoPrice, quota, and entitlement tampering
Derive sensitive values and eligibility from trusted state.
TypeScriptGoWebhook signature verification
Verify the exact raw body and timestamp using the provider's documented scheme, then handle duplicates safely.
TypeScriptGoSSRF and server-side fetches
Restrict destinations and redirects, validate resolved addresses including cloud metadata ranges, and isolate outbound network access.
TypeScriptGoClickjacking and framing controls
Decide which trusted origins may embed the application and set frame protections accordingly.
TypeScriptGoGraphQL and query-shape abuse
Bound depth, complexity, batching, and object-level authorization.
TypeScriptGoWebSocket and long-lived connection security
Authenticate connection setup, authorize each relevant message/action, and handle expiry and origin checks.
TypeScriptGoRedirects, callbacks, and deep links
Validate destinations against explicit rules; prevent open redirect and unsafe callback behavior.
TypeScriptGoHTTP request smuggling and parser disagreement
Investigate when a proxy and origin parse message boundaries differently, and verify consistent handling across the request path.
TypeScriptGoWeb cache poisoning and cache deception
Check whether cache keys and origin behavior can store attacker-influenced content or expose a private response to other users.
TypeScriptGo
LLM and AI application security
practitionerSecure AI features by treating model inputs, outputs, retrieved content, and tool proposals as untrusted.
Threat-model an LLM feature
Map user prompts, system instructions, retrieved content, model providers, tools, and sinks as separate trust boundaries.
Direct and indirect prompt injection
Understand that instructions in user input or retrieved content can manipulate model behavior; prompt wording alone is not a security boundary.
TypeScriptUntrusted model output and dangerous sinks
Validate and authorize structured outputs before they reach HTML, SQL, shell, URLs, code execution, or state-changing tools.
TypeScriptGoData exfiltration through rendered output
Prevent rendered model-authored links or media from making unintended external requests that disclose sensitive context.
TypeScriptTool calls as untrusted requests
Treat every proposed tool call as data; validate its schema, caller, target, scope, and current user permissions in ordinary application code.
TypeScriptGoAgent permissions and excessive agency
Limit available tools, operation scope, autonomy, and downstream identities to what the task actually needs.
TypeScriptGoMCP and tool server security
Assess server identity, untrusted tool descriptions and results, authorization scope, and credential exposure across the client-server boundary.
TypeScriptGoHuman approval for high-impact actions
Require explicit, contextual confirmation before irreversible, externally visible, or privileged actions.
TypeScriptGoPoisoned and hostile retrieved content
Treat documents, web pages, email, and tool results as untrusted context that can contain indirect instructions.
TypeScriptGoVector stores, embeddings, and sensitive data
Protect access to source documents, derived embeddings, metadata, and retrieval results; consider leakage and cross-tenant exposure.
TypeScriptGoSystem prompts are not secrets
Keep credentials and access decisions out of prompts; assume instructions can be exposed and enforce controls elsewhere.
Conversation state and agent memory isolation
Scope memory to a user and task, define retention, and prevent one session's content from influencing another's.
TypeScriptAI provider data handling and privacy
Understand what prompts, files, telemetry, and outputs leave the system and the provider's retention and training settings.
Model, dataset, and plugin supply-chain risk
Verify provenance and permissions for models, fine-tuning data, connectors, plugins, and other components.
Unbounded token use, loops, and cost abuse
Set budgets, deadlines, output limits, and stopping rules for model calls and agent loops.
TypeScriptGoLLM security evaluations and regression tests
Test security properties across prompt variations and workflow states; retain reproducible cases while recognizing model variability.
TypeScriptGoRed-team an AI feature safely
Probe a local or authorized test system for data exposure, tool misuse, policy bypass, and resource abuse.
TypeScriptGoAI security incident response
Preserve relevant prompts, tool-call decisions, retrieved sources, model/provider versions, and outcomes without logging unnecessary sensitive content.
Security testing and code review
practitionerTurn security properties into reviewable, repeatable tests.
Turn a threat into a test
Express the expected security property as a testable invariant.
TypeScriptGoUnit, integration, and end-to-end security tests
Place each check where it can exercise the real boundary without overclaiming coverage.
TypeScriptGoRegression tests for vulnerabilities
Preserve a minimal failing input and prove the fixed behavior at the relevant layer.
TypeScriptGoStatic analysis and lint rules
Use tools to find classes of mistakes; triage findings and understand blind spots.
Dynamic and interactive application testing
Exercise a running test deployment safely and interpret scanner results rather than treating them as proof.
Fuzzing parsers and validators
Generate unexpected inputs to find crashes, hangs, and invariant failures.
TypeScriptGoDependency and container scanning
Track components and investigate findings in the context of actual usage and exposure.
Secure code review checklist
Follow sources, trust boundaries, sinks, authorization decisions, secrets, and failure paths.
False positives, false negatives, and test coverage
Understand why scanners and passing tests cannot establish that an application is secure.
Security test environments and safe fixtures
Use synthetic data, scoped credentials, and isolated targets; do not test real systems without authorization.
Files, uploads, and content processing
practitionerHandle uploaded files and complex content as hostile input.
Secure file upload pipeline
Enforce size, type, content, storage, and authorization checks as separate controls.
TypeScriptGoMIME type and extension validation
Treat client-provided filenames and content types as claims, not evidence.
TypeScriptGoSafe file names and storage locations
Generate server-side names and keep untrusted content out of executable or public paths.
TypeScriptGoMalware scanning and quarantine workflow
Define pending, scanned, rejected, and available states without trusting a scan as perfect.
TypeScriptGoArchive extraction and path traversal
Prevent entries from escaping the intended destination and bound expansion.
TypeScriptGoImage, document, and media parser risks
Isolate complex parsers and apply resource limits and updates.
TypeScriptGoContent-Disposition and download safety
Serve untrusted files with deliberate content types and download behavior.
TypeScriptGoImport, export, and CSV formula injection
Treat exported values as active content when opened by spreadsheet software.
TypeScriptGoXML external entities and unsafe XML features
Disable unnecessary entity resolution and bound parsing.
TypeScriptGoRich text sanitization and safe rendering
Define allowed markup, sanitize with maintained tooling, and preserve context-safe rendering.
TypeScriptGo
Dependencies, build systems, and software supply chain
practitionerKnow what enters builds and reduce risk in dependencies and delivery pipelines.
Dependency inventory and transitive risk
Know what is in the build, where it came from, and which paths execute it.
Vulnerability advisories and triage
Consider affected versions, reachability, exposure, available fixes, and compensating controls.
Lockfiles, registries, and package confusion
Pin expected sources and prevent untrusted packages or namespaces from entering a build.
Dependency updates and patch policy
Automate discovery while retaining review, testing, and a way to respond quickly.
Secrets committed to source control
Detect exposed credentials, revoke and rotate them immediately, and remove them from future history without mistaking history rewriting for revocation.
Typosquatting and malicious packages
Verify package identity and provenance before adding dependencies.
Build isolation and reproducibility
Reduce ambient access and make artifacts traceable to reviewed source and build inputs.
SBOMs and component provenance
Produce useful component and build-origin records; distinguish inventory from a security guarantee.
Artifact signing and verification
Establish who produced an artifact and verify integrity at consumption.
CI/CD secret exposure
Use scoped, short-lived credentials and keep untrusted pull requests away from privileged secrets.
Pipeline permissions and workflow injection
Treat workflow files, actions, build scripts, and user-controlled parameters as executable attack surface.
Third-party actions, plugins, and build extensions
Pin and review external code that runs with pipeline privileges.
Coordinated vulnerability disclosure and patch response
Provide a safe reporting path, assess impact, ship fixes, and communicate clearly.
Browser, frontend, and privacy security
practitionerUnderstand browser protections and preserve user privacy in client experiences.
Same-origin policy and origin model
Understand scheme, host, and port as browser isolation boundaries.
CORS preflight and credentialed requests
Configure explicit origin and credential behavior without using wildcard shortcuts for private data.
postMessage and cross-window messaging
Validate sender origin, source window, and message shape before trusting data from popups, frames, or embedded widgets.
TypeScriptBrowser storage trade-offs
Compare cookies, local storage, session storage, and in-memory state by threat and use case.
TypeScriptContent Security Policy deployment
Start with report-only observation, remove unsafe allowances, and test real application flows.
Subresource Integrity and third-party scripts
Reduce the risk of changed remote assets and minimize the scripts trusted with page access.
Referrer, permissions, and security headers
Set browser policy deliberately and verify actual deployed responses.
DOM clobbering and unsafe URL schemes
Avoid named-property collisions and validate navigable or executable URLs.
TypeScriptCross-site leaks and side channels
Recognize that observable response differences can expose sensitive state across origins.
TypeScriptPrivacy-preserving telemetry
Avoid collecting secrets and sensitive personal data in analytics, logs, or replay tools.
TypeScriptConsent, retention, deletion, and export
Implement user-facing data promises as backend behavior, not only interface copy.
TypeScriptGo
Runtime, infrastructure, and cloud security
advancedReduce the privileges and exposure of the systems that run the application.
Security configuration and hardened defaults
Make secure configuration explicit, reviewable, environment-specific, and checked at startup.
Least privilege for application processes
Limit database, filesystem, network, cloud, and operating-system permissions.
Memory safety and unsafe code
Understand where unsafe and native boundaries—from Rust unsafe and Go cgo to Node extensions—bypass language safeguards and require explicit review.
TypeScriptGoEnvironment variables and secret stores
Know exposure paths and choose a managed secret mechanism appropriate to deployment.
Containers and image hygiene
Run as non-root where possible, minimize images, pin sources, and scan the resulting artifact.
Network segmentation and egress control
Limit which components can reach each other and where an application can connect outbound.
Cloud IAM and workload identity
Grant narrowly scoped access through identities rather than embedded static keys.
Database account and network security
Separate application roles, restrict reachable services, and avoid administrative credentials at runtime.
Production and non-production separation
Keep real data and production secrets out of developer machines, previews, and test fixtures.
Backups, restore, and ransomware resilience
Protect backup access and prove recovery rather than assuming that a backup is usable.
Patch management and exposed services
Inventory reachable components, prioritize fixes, and retire unused services.
Infrastructure as code review
Treat permissions, network rules, storage exposure, and deployment configuration as code requiring review and tests.
Logging, detection, and incident response
advancedCreate useful signals, respond to security incidents, and learn from them.
Security event logging
Record enough evidence to investigate while excluding credentials, tokens, and unnecessary personal data.
Log integrity, access, and retention
Protect logs from tampering, limit readers, and keep them only as long as justified.
Alert quality and operational ownership
Give each alert a clear signal, severity, responder, and first action.
Vulnerability triage and severity
Combine technical severity with reachability, exploitability, affected assets, and business impact.
Incident response roles and first steps
Preserve evidence, contain impact, communicate, and restore service through a prepared process.
Credential and key compromise
Revoke, rotate, identify use, invalidate sessions, and check downstream copies.
Security incident retrospectives
Identify control and process gaps without reducing the review to blame or one patch.
Vulnerability disclosure handling
Receive reports safely, acknowledge them, reproduce in authorized environments, and coordinate a fix.
Tabletop exercises and response readiness
Rehearse realistic scenarios and record what people, access, or telemetry were missing.
Governance, assurance, and certification crosswalk
advancedConnect engineering practices to versioned verification standards and exam objectives.
Security policies versus implemented controls
A written policy is not evidence that a control works in code or operations.
Secure development lifecycle
Place requirements, review, testing, release, and vulnerability response across the software lifecycle.
OWASP ASVS as a verification catalog
Use versioned requirements to plan and check web application controls; scope the verification level to the system.
OWASP Top 10 and common risk taxonomies
Use risk lists as awareness and prioritization aids, not complete curricula or pass/fail standards.
NIST SSDF practices in a small team
Translate outcome-oriented secure development practices into proportionate team habits.
Evidence, audit trails, and control ownership
Connect a control to a person, system evidence, review cadence, and remediation process.
Risk acceptance and exceptions
Record who accepts residual risk, for how long, with what compensating controls and review date.
CompTIA Security+ crosswalk
Optional exam-oriented index for applicable security foundations, threats, architecture, operations, and governance topics.
CompTIA CySA+ crosswalk
Optional analyst-oriented index for monitoring, vulnerability management, incident response, and threat analysis.
Exam objective versioning
State the exam code and objectives version beside every mapping; never imply the catalog alone prepares someone to pass.
Jurisdiction- and standard-specific compliance
Link out to separately maintained, dated material rather than presenting one universal compliance checklist.