Source library · 320 curated entries

Where every claim in SecProve comes from.

A dense reading catalog. Every claim is footnoted. Sort by source, filter by pillar, type, or recency. Built for analysts who want to see what we are standing on.

320SOURCES
143ORGS
50DOMAINS
320ADDED · 90 DAYS
Pillar · multi-selectall 4 selected
Domainsselect pillar(s) above
Browsing the full corpus. Pick pillars above to narrow to specific domains.
8 sources · matching filters · sorted by citation density
Sort
ACybersecurity8 sources
01

Top 10 security risks for APIs. Covers broken object-level authorization, authentication failures, excessive data exposure, and more.

FrameworkIntermediateA4 · Application SecurityNEW · 1mo ago
Test your knowledge · A4
02
Black Hat / DEF CON ArchivesBlack Hat / DEF CON

Conference presentations covering novel attack techniques and defensive research. Essential for cutting-edge offensive/defensive questions. AI Village talks particularly relevant for Pillars B and C.

Test your knowledge · A4
03

Framework of security requirements for designing, developing, and testing secure web applications. Three verification levels.

FrameworkIntermediateA4 · Application SecurityNEW · 1mo ago
Test your knowledge · A4
04

Five business functions (Governance, Design, Implementation, Verification, Operations) for measuring and improving AppSec programs. Good for maturity model questions.

Test your knowledge · A4
05

The most widely referenced web application security awareness document. Covers injection, broken auth, XSS, and more.

FrameworkFoundationalA4 · Application SecurityNEW · 1mo ago
Test your knowledge · A4
06

Fast, open-source static analysis tool for finding bugs and enforcing code standards. Supports 30+ languages with custom rules.

ToolIntermediateA4 · Application SecurityNEW · 1mo ago
Test your knowledge · A4
07

Annual analysis of open source usage and vulnerability data. Key stats on open source in commercial codebases (typically 70-80%+). Grounds supply chain and AppSec questions in real data.

Test your knowledge · A4
08

Annual report with empirical data on flaw prevalence by language, fix rates, and security debt. Useful for data-driven AppSec questions. Vendor but based on scan data across thousands of orgs.

GuideIntermediateA4 · Application SecurityNEW · 22d ago
Test your knowledge · A4

Ready to test what you've learned?

Our questions are built directly from these resources. Take a quiz and see how your knowledge stacks up.