Developer Security Wargame
Learn security through real-world incidents or CVEs. Identify, exploit, and fix security vulnerabilities in real applications.
Real Vulnerabilities, Hands-On Practice
Every challenge is built on a real vulnerability class, in a codebase. You find it, exploit it, and patch it. You skill up and get ranked.
Find, hack and fix
Master the full spectrum of security vulnerabilities. You don't just identify and exploit flaws, you fix them robustly.
Developer-centric
Familiar GitOps workflow and in-repository challenges. Use your favourite IDE, or our secure in-browser sandbox.
Strengthen your skills
A personalised learning path with progressive difficulty and instant feedback.
SQL Injection
Trivial
Prompt Injection
Medium
Race Condition
Battle
Climb the Hacker Lobby
In Attack & Defence challenge, Hack another player's app and you take their spot on the leaderboard. Get hacked, and you drop until you secure your app.
Real security bugs
Each challenge mimics a real security vulnerability (CVE) or incident, building hands-on skills you'll actually use in production code β including full coverage of the OWASP Top 10 and the OWASP LLM Top 10.
Get recognised
Collect badges and certificates that showcase your secure coding skills to peers and employers.
Secure Coding
Fundamentals Badge.ts
is proudly presented to
Harley Wilson
A Glimpse of the Challenge Library
Recommended starting pointsFrequently Asked Questions
Is the wargame free to play?
Yes. A rotating set of free challenges is open to everyone on the Community plan β see our pricing for what Professional unlocks.
Do I need to install anything to play?
No. Play directly in our in-browser sandbox, or clone a challenge into your own IDE and use your usual editor, debugger, and git workflow.
What is Attack & Defence and the Hacker Lobby?
It's our live scoring format: hack another player's running app and you take their spot on the leaderboard; get hacked yourself and you drop until you patch your app and reclaim it.
Are the challenges based on real vulnerabilities?
Yes. Every challenge is modelled on a real CVE or incident, with full coverage of the OWASP Top 10 and OWASP LLM Top 10 β browse our standards library for the frameworks we map to.
Do I get a badge or certificate for completing challenges?
Yes. You earn badges and certificates as you progress, which you can share with peers or employers to prove hands-on skill.
Can my company run a private wargame with enterprise support?
Yes. Host an all-inclusive private wargame for your org, with Single Sign-On, roles, and reporting mapped to frameworks like SOC 2, ISO 27001, and PCI DSS β see our product page for details.
Are there live wargame events I can join?
Yes. SecDim runs live wargames at conferences like Black Hat and DEF CON, plus regular community events like the Holiday 7x7 β keep an eye on our news for upcoming dates.
Start Your Security Training Now
Sign up for free and see the difference the wargame makes in your professional growth.
