Security Learning Resources

Media Library

Curated books, courses, and research papers focused on SAST, application security, secure coding, and vulnerability research.

BookIntermediate

The Web Application Hacker's Handbook

Stuttard & Pinto

Comprehensive guide to finding and exploiting web application security flaws. Covers injection, authentication, session management, and more.

Web SecurityOWASPPenetration Testing
Open resource
BookAdvanced

The Art of Software Security Assessment

Dowd, McDonald & Schuh

Deep dive into source code auditing and vulnerability discovery across C, C++, Java, and web technologies. The definitive SAST reference for practitioners.

SASTCode ReviewC/C++Java
Open resource
BookIntermediate

Secure Coding in C and C++

Robert C. Seacord

Covers buffer overflows, integer overflows, memory safety, and secure coding practices for systems programming languages.

C/C++Memory SafetySecure Coding
Open resource
BookIntermediate

Iron-Clad Java: Building Secure Web Applications

Manico & Detlefsen

Java-focused security guide covering XSS, SQL injection, CSRF, authentication, and secure development lifecycle.

JavaWeb SecuritySecure Coding
Open resource
BookIntermediate

Threat Modeling: Designing for Security

Adam Shostack

Framework for identifying, communicating, and understanding threats and mitigations. Essential for integrating security into the SDLC.

Threat ModelingSDLCArchitecture
Open resource
BookAdvanced

The Tangled Web

Michal Zalewski

A guide to securing modern web applications, focusing on browser security models, HTTP, and the quirks of the web platform.

Web SecurityBrowser SecurityHTTP
Open resource
BookBeginner

Alice and Bob Learn Application Security

Tanya Janca

Beginner-friendly introduction to application security concepts, secure coding, and DevSecOps practices.

AppSecDevSecOpsBeginner
Open resource
BookAdvanced

Hacking: The Art of Exploitation

Jon Erickson

Hands-on introduction to exploitation techniques including buffer overflows, shellcode, and network programming from a low-level perspective.

ExploitationBuffer OverflowC
Open resource
BookIntermediate

Software Security: Building Security In

Gary McGraw

Foundational book on integrating security into the software development lifecycle through risk analysis, code review, and testing.

SDLCSASTRisk Analysis
Open resource
Videos & CourseIntermediate

Static Analysis with Semgrep — freeCodeCamp

freeCodeCamp.org

Full course on using Semgrep for static analysis, writing custom rules, and integrating SAST into CI/CD pipelines.

SASTSemgrepCI/CD
Open resource
Videos & CourseBeginner

OWASP Top 10 Deep Dive — SANS Institute

SANS Institute

Comprehensive walkthrough of the OWASP Top 10 vulnerabilities with real-world examples, detection techniques, and mitigations.

OWASPWeb SecurityBeginner
Open resource
Videos & CourseIntermediate

Secure Code Review Fundamentals — Snyk

Snyk

Learn how to perform effective code reviews with a security mindset — identifying injection flaws, logic bugs, and insecure patterns.

Code ReviewAppSecSAST
Open resource
Videos & CourseBeginner

Static Application Security Testing (SAST) Explained

PentesterAcademy

An overview of SAST concepts, tool categories, and how to evaluate SAST tools for enterprise use.

SASTToolsEnterprise
Open resource
Videos & CourseIntermediate

Threat Modeling in Practice — Adam Shostack

Adam Shostack

Conference talk from the author of Threat Modeling: Designing for Security on applying threat modeling to real systems.

Threat ModelingSDLCArchitecture
Open resource
Videos & CourseAll Levels

Web Security Academy — PortSwigger (Burp Suite Labs)

PortSwigger

Free interactive labs covering SQL injection, XSS, CSRF, SSRF, XXE, deserialization, and more with hands-on challenges.

Web SecurityLabsHands-on
Open resource
Videos & CourseIntermediate

DevSecOps: Integrating Security into CI/CD — GitHub

GitHub

Learn to embed SAST, DAST, and dependency scanning into GitHub Actions pipelines for shift-left security.

DevSecOpsCI/CDGitHub Actions
Open resource
Studies & PaperAll Levels

OWASP Top 10 — 2021

OWASP Foundation

The definitive standard for the top 10 most critical web application security risks, backed by data from hundreds of organizations.

OWASPWeb SecurityStandard
Open resource
Studies & PaperAdvanced

NIST Special Publication 800-53: Security Controls

NIST

Comprehensive catalog of security and privacy controls for federal information systems, widely adopted in enterprise security programs.

ComplianceControlsNIST
Open resource
Studies & PaperAll Levels

Common Weakness Enumeration (CWE) Top 25

MITRE Corporation

Annually updated list of the most dangerous software weaknesses. Essential reference for SAST rule development and code review.

CWESASTReference
Open resource
Studies & PaperAdvanced

Evaluation of Static Analysis Tools — IEEE

IEEE / Various Authors

Academic evaluation of popular SAST tools comparing precision, recall, and false positive rates across real codebases.

SASTResearchTool Evaluation
Open resource
Studies & PaperAll Levels

State of Software Security Report — Veracode

Veracode

Annual industry report on the state of software security, application vulnerability trends, and remediation benchmarks across thousands of apps.

Industry ReportMetricsTrends
Open resource
Studies & PaperIntermediate

OWASP SAMM — Software Assurance Maturity Model

OWASP Foundation

Framework to help organizations formulate and implement a security strategy for software development that fits their risk profile.

SDLCMaturity ModelDevSecOps
Open resource
Studies & PaperIntermediate

CIS Software Supply Chain Security Guide

Center for Internet Security

Best practices for securing the software supply chain including dependency management, build pipelines, and artifact signing.

Supply ChainSCADevSecOps
Open resource
Studies & PaperAll Levels

SANS Top 25 Most Dangerous Programming Errors

SANS Institute

A list of the most widespread and critical programming errors that can lead to serious software vulnerabilities, co-produced with MITRE.

Secure CodingCWEReference
Open resource
SentinelSASTby 386 LLC
🔐 End-to-End Encrypted
⚖️ GDPR & CCPA Compliant
🚫 Data Never Sold

© 2026 386 LLC. All rights reserved. SentinelSAST is a product of 386 LLC. Unauthorized reproduction, copying, or distribution of this platform or any portion thereof is strictly prohibited and constitutes a material breach of the Terms of Service.