pr0h0
Security Training

Blue Team Defence

A hands-on secure-coding course for working developers: fix real vulnerabilities in a realistic codebase and get feedback on exactly why a patch falls short.

You can generate code faster than you can review it. This is where you learn to review it.

AI-assisted development has made writing code cheap, but reviewing it for security has not got any easier. Most secure-coding training is slides and multiple-choice quizzes, which teach developers to recognise a vulnerability's name rather than to actually fix one in code they own.

Blue Team Defence is a browser-based course built the other way around. Learners inherit one fictional application, AcmeBoard, and keep it for the whole curriculum. Each lesson is an event in its life: a feature ships, a problem is reported, the learner reads the evidence and patches the real code. The fix is then checked against the original issue and against variants designed to catch incomplete patches, while the feature still has to work afterwards.

The feedback is what makes it different. Instead of a bare "incorrect", learners are told precisely what their patch missed, for example that a value is now handled safely in one context but still reaches another. The course covers recurring root causes such as injection, broken authorization, missing trust boundaries, unsafe file handling and weak account recovery, in Node/Express, Python/Django, PHP/Laravel and Ruby on Rails.

Key features

  • Twelve lessons and seven drills, each in four language tracks: Node/Express, Python/Django, PHP/Laravel and Ruby on Rails
  • One realistic application carried through the whole curriculum
  • Fixes are verified against variants that catch incomplete patches, and the feature must keep working
  • More than 170 known-incomplete-fix cases, each checked in CI to produce a specific explanation
  • Every submission runs in its own isolated gVisor sandbox
  • A generic lesson runtime: new lessons need no new routes, tables or components
  • An authoring CLI that proves a lesson holds up before it can be published

Architecture

Lessons are data, not code: a generic runtime with twelve step types renders every lesson, so the platform has no lesson-specific branches. Submissions go through an ephemeral execution pipeline in which each one runs in its own gVisor container, and functional results, security checks, variant checks and platform errors are reported separately.