Content

We test all things appsec, from web applications and APIs of all types, to mobile applications, to thick clients, to even applications leveraging Generative AI. There's some great content available, especially with the surge of awesome creators in the bug bounty space. After finding so many intricate vulnerabilities over the years, we felt we could share our experiences and methodology with the InfoSec community.

The main goal with our content is to cause a systemic change in how you look at applications. We take a different approach, tackling appsec and pentesting from a more holistic perspective.

YouTube | PortSwigger's Web Security Academy Series

Our goal with this series is to take a deep dive reviewing application functionality, with a focus on breaking down discovery methodology.

When you learn about the "how" and "why" of vulnerabilities like XSS, SQLi and SSTI, the discovery methodology is often less clear, especially from a gray box or black box perspective. That gap is the hard part of learning to test web applications comprehensively, so we break it down lab by lab.

We have a lot more in store that we want to put out there, so stay tuned.


Twitch | It Takes A Village w/ Hack The Box

We co-hosted It Takes A Village, a live hacking stream on Hack The Box's own Twitch channel. The premise is in the name: nobody learns this alone, and sometimes you need a helping hand to grow.

Episodes ran live and unedited! We worked through HTB machines and web challenges alongside the community, including the parts where an approach goes nowhere. That is usually where the useful thinking happens.

Episodes went out on the Hack The Box channel. Our own Twitch streams run at twitch.tv/garr_7 and used to run twice a week! Now, we stream monthly, with giveaways included on every stream!