Browser security where behaviour is the evidence

Find what source-only and traffic-only scanners can miss.

Explore browser code, live runtime flows, authenticated requests, response metadata and loaded dependencies through deterministic vulnerable and repaired targets.

Start here

One corpus. Two clear ways in.

Guidance and complete coverage use the same canonical challenge definitions.

Play

Follow a browser-security story

Use a short presenter path or work through every current mission. Compare review and repaired targets without losing access to the wider corpus.

Choose a guided path
Explore

Search the complete catalogue

Filter all focused cases, controls and retained historical labs by engine, readiness, automation support or browser behaviour.

Open the full catalogue

Why browser context matters

Different engines observe different parts of one application.

SAST

Code that is delivered

Inspect scripts and HTML paths even when the vulnerable feature has not executed.

Explore SAST cases
IAST

Code that actually runs

Connect browser-controlled sources to live DOM, navigation, storage, messaging and request sinks.

Explore IAST cases
DAST

Traffic with real state

Observe and safely mutate requests using the authentication, routes and application state available to the browser.

Explore DAST cases
SCA

Dependencies that really load

Identify components loaded initially or only after a user action, lazy route or child document.

Explore SCA cases

Complete fixture migration

Every tracked scenario has an explicit role.

SAST and IAST assertions have separate review and repaired files. DAST assertions and SCA scenarios have deterministic public contracts. Broad historical pages remain available as compatibility labs.

Review Advanced labs