Media Library
Curated books, courses, and research papers focused on SAST, application security, secure coding, and vulnerability research.
The Web Application Hacker's Handbook
Stuttard & Pinto
Comprehensive guide to finding and exploiting web application security flaws. Covers injection, authentication, session management, and more.
The Art of Software Security Assessment
Dowd, McDonald & Schuh
Deep dive into source code auditing and vulnerability discovery across C, C++, Java, and web technologies. The definitive SAST reference for practitioners.
Secure Coding in C and C++
Robert C. Seacord
Covers buffer overflows, integer overflows, memory safety, and secure coding practices for systems programming languages.
Iron-Clad Java: Building Secure Web Applications
Manico & Detlefsen
Java-focused security guide covering XSS, SQL injection, CSRF, authentication, and secure development lifecycle.
Threat Modeling: Designing for Security
Adam Shostack
Framework for identifying, communicating, and understanding threats and mitigations. Essential for integrating security into the SDLC.
The Tangled Web
Michal Zalewski
A guide to securing modern web applications, focusing on browser security models, HTTP, and the quirks of the web platform.
Alice and Bob Learn Application Security
Tanya Janca
Beginner-friendly introduction to application security concepts, secure coding, and DevSecOps practices.
Hacking: The Art of Exploitation
Jon Erickson
Hands-on introduction to exploitation techniques including buffer overflows, shellcode, and network programming from a low-level perspective.
Software Security: Building Security In
Gary McGraw
Foundational book on integrating security into the software development lifecycle through risk analysis, code review, and testing.
Static Analysis with Semgrep — freeCodeCamp
freeCodeCamp.org
Full course on using Semgrep for static analysis, writing custom rules, and integrating SAST into CI/CD pipelines.
OWASP Top 10 Deep Dive — SANS Institute
SANS Institute
Comprehensive walkthrough of the OWASP Top 10 vulnerabilities with real-world examples, detection techniques, and mitigations.
Secure Code Review Fundamentals — Snyk
Snyk
Learn how to perform effective code reviews with a security mindset — identifying injection flaws, logic bugs, and insecure patterns.
Static Application Security Testing (SAST) Explained
PentesterAcademy
An overview of SAST concepts, tool categories, and how to evaluate SAST tools for enterprise use.
Threat Modeling in Practice — Adam Shostack
Adam Shostack
Conference talk from the author of Threat Modeling: Designing for Security on applying threat modeling to real systems.
Web Security Academy — PortSwigger (Burp Suite Labs)
PortSwigger
Free interactive labs covering SQL injection, XSS, CSRF, SSRF, XXE, deserialization, and more with hands-on challenges.
DevSecOps: Integrating Security into CI/CD — GitHub
GitHub
Learn to embed SAST, DAST, and dependency scanning into GitHub Actions pipelines for shift-left security.
OWASP Top 10 — 2021
OWASP Foundation
The definitive standard for the top 10 most critical web application security risks, backed by data from hundreds of organizations.
NIST Special Publication 800-53: Security Controls
NIST
Comprehensive catalog of security and privacy controls for federal information systems, widely adopted in enterprise security programs.
Common Weakness Enumeration (CWE) Top 25
MITRE Corporation
Annually updated list of the most dangerous software weaknesses. Essential reference for SAST rule development and code review.
Evaluation of Static Analysis Tools — IEEE
IEEE / Various Authors
Academic evaluation of popular SAST tools comparing precision, recall, and false positive rates across real codebases.
State of Software Security Report — Veracode
Veracode
Annual industry report on the state of software security, application vulnerability trends, and remediation benchmarks across thousands of apps.
OWASP SAMM — Software Assurance Maturity Model
OWASP Foundation
Framework to help organizations formulate and implement a security strategy for software development that fits their risk profile.
CIS Software Supply Chain Security Guide
Center for Internet Security
Best practices for securing the software supply chain including dependency management, build pipelines, and artifact signing.
SANS Top 25 Most Dangerous Programming Errors
SANS Institute
A list of the most widespread and critical programming errors that can lead to serious software vulnerabilities, co-produced with MITRE.