Follow a browser-security story
Use a short presenter path or work through every current mission. Compare review and repaired targets without losing access to the wider corpus.
Choose a guided pathBrowser security where behaviour is the evidence
Explore browser code, live runtime flows, authenticated requests, response metadata and loaded dependencies through deterministic vulnerable and repaired targets.
Start here
Guidance and complete coverage use the same canonical challenge definitions.
Use a short presenter path or work through every current mission. Compare review and repaired targets without losing access to the wider corpus.
Choose a guided pathFilter all focused cases, controls and retained historical labs by engine, readiness, automation support or browser behaviour.
Open the full catalogueWhy browser context matters
Inspect scripts and HTML paths even when the vulnerable feature has not executed.
Explore SAST casesConnect browser-controlled sources to live DOM, navigation, storage, messaging and request sinks.
Explore IAST casesObserve and safely mutate requests using the authentication, routes and application state available to the browser.
Explore DAST casesIdentify components loaded initially or only after a user action, lazy route or child document.
Explore SCA casesComplete fixture migration
— SAST and — IAST assertions have separate review and repaired files. — DAST assertions and — SCA scenarios have deterministic public contracts. Broad historical pages remain available as compatibility labs.