logo
Red wilds
Web application defence
  • Privacy greenhouse
  • Defence blues
  • Purple crossroads
  • Indigo observatory
  • Contact
Initializing search
      • Unseen University Power & Light Co.
      • The Scarlet Semaphore
      • Myrddin’s menagerie
      • Creating all kinds of labs
      • Where the falcons and foxes roam
        • A canopy of apple-blossom
          • Field notes from the fragrant branches of web app exploitation
          • Web application attack runbooks
          • Web application attack playbooks
          • Portswigger Academy labs: Controlled burn
          • Root-me: Orchard foraging
          • Petals and pentesting priorities
          • Web application defence
            • Reducing web application attack surface
            • Detect web application attacks
          • Web application defence
            • Reducing web application attack surface
            • Detect web application attacks
        • Social engineering
        • Where wild boars plough through endpoints
        • Wolverines do not ask for permissions
        • Riches in the ground
        • The device is just the keyring
        • Poking physics with network packets
      • Where the raccoons burrow and rummage
      • Where squirrels swipe the crown jewels

    Web application defence¶

    Controls for reducing attack surface and detecting abuse. Organised around two questions: what reduces the chance of exploitation, and what makes exploitation visible when it happens.

    • Reducing web application attack surface
    • Detect web application attacks
    2026-03-25 00:01
    © Copyright 2025, TyMyrddin.
    Created using Sphinx 7.2.6. and Sphinx-Immaterial

    Made with love in the Unseen University, 2025, with a forest garden fostered by /ut7