Resource Library
Curated cybersecurity resources across all topics
The industry-standard web application security testing proxy. Intercept, modify, and replay HTTP requests. Essential for web pentesting, bug bounty, and learning how web attacks work.
The 10 most critical web application security risks according to real-world data. Mandatory knowledge for every web developer and security professional.
PortSwigger's free Web Security Academy — hands-on labs for every web vulnerability type. The best free resource for learning web application security testing.
PortSwigger's comprehensive SQLi reference covering syntax for MySQL, MSSQL, Oracle, and PostgreSQL — comments, string concat, batched queries, and time-based blind injection.
The most comprehensive XSS payload reference available. Categorised by event handlers, HTML tags, and encoding bypass techniques. Updated regularly with new bypasses.
The most comprehensive web application penetration testing methodology. Covers all OWASP Top 10 vulnerabilities with testing procedures, tools, and remediation guidance.