πŸ‘Ύ Join our AppSec Village Wargame at DEF CON 34 and win prizes

Developer Security Wargame

Learn security through real-world incidents or CVEs. Identify, exploit, and fix security vulnerabilities in real applications.

Real Vulnerabilities, Hands-On Practice

Every challenge is built on a real vulnerability class, in a codebase. You find it, exploit it, and patch it. You skill up and get ranked.

Find, hack and fix

Master the full spectrum of security vulnerabilities. You don't just identify and exploit flaws, you fix them robustly.

FindHackFix

Developer-centric

Familiar GitOps workflow and in-repository challenges. Use your favourite IDE, or our secure in-browser sandbox.

Strengthen your skills

A personalised learning path with progressive difficulty and instant feedback.

740 points Level 1 Expert

SQL Injection

Trivial

Prompt Injection

Medium

Race Condition

Battle

Climb the Hacker Lobby

In Attack & Defence challenge, Hack another player's app and you take their spot on the leaderboard. Get hacked, and you drop until you secure your app.

+20+20

Real security bugs

Each challenge mimics a real security vulnerability (CVE) or incident, building hands-on skills you'll actually use in production code β€” including full coverage of the OWASP Top 10 and the OWASP LLM Top 10.

Challenges modelled on real-world security incidents

Get recognised

Collect badges and certificates that showcase your secure coding skills to peers and employers.

Secure Coding
Fundamentals Badge.ts

is proudly presented to

Harley Wilson

Secure Coding Fundamentals badge

SecDim is the platform I was looking for in my secure coding studies. Developer-oriented tests prove the code is vulnerable, and vulnerabilities go way beyond the basics. The supporting material is great, talking about fundamentals, principles, and specifics. Totally recommend it for anyone looking to improve their secure coding skills.

MΓ‘rio Areias
MΓ‘rio AreiasSoftware and Security Engineer

Frequently Asked Questions

Is the wargame free to play?

Yes. A rotating set of free challenges is open to everyone on the Community plan β€” see our pricing for what Professional unlocks.

Do I need to install anything to play?

No. Play directly in our in-browser sandbox, or clone a challenge into your own IDE and use your usual editor, debugger, and git workflow.

What is Attack & Defence and the Hacker Lobby?

It's our live scoring format: hack another player's running app and you take their spot on the leaderboard; get hacked yourself and you drop until you patch your app and reclaim it.

Are the challenges based on real vulnerabilities?

Yes. Every challenge is modelled on a real CVE or incident, with full coverage of the OWASP Top 10 and OWASP LLM Top 10 β€” browse our standards library for the frameworks we map to.

Do I get a badge or certificate for completing challenges?

Yes. You earn badges and certificates as you progress, which you can share with peers or employers to prove hands-on skill.

Can my company run a private wargame with enterprise support?

Yes. Host an all-inclusive private wargame for your org, with Single Sign-On, roles, and reporting mapped to frameworks like SOC 2, ISO 27001, and PCI DSS β€” see our product page for details.

Are there live wargame events I can join?

Yes. SecDim runs live wargames at conferences like Black Hat and DEF CON, plus regular community events like the Holiday 7x7 β€” keep an eye on our news for upcoming dates.

Start Your Security Training Now

Sign up for free and see the difference the wargame makes in your professional growth.