AI & AppSecKnowledge Hub.
Free resources, research, and open-source tools for security professionals working at the intersection of AI and AppSec. Created by Viswanath Chirravuri, GSE #335, SANS Associate Instructor & D.Eng. Cybersecurity candidate.
> cat focus-areas.md
Three Knowledge Pillars
Everything published here falls under one of these three areas — the full scope of AI and AppSec security work today.
AI for AppSec
Using AI and LLMs to enhance application security work — from AI-assisted code review and threat modeling to automating vulnerability triage, SAST tuning, and DevSecOps pipelines.
ExploreSecuring AI
Defending AI systems against adversarial threats — OWASP LLM Top 10, prompt injection, RAG security, model supply chain risks, agentic AI vulnerabilities, and MLSecOps practices.
ExploreSecurely Using Vendor AI
Safe adoption of OpenAI, Anthropic, Google Gemini, Microsoft Copilot, and other commercial AI services — covering data governance, API security, access controls, and compliance.
Explore> ls ./content
What You'll Find Here
Blog & Articles
In-depth posts on AI security topics — LLM security, agentic AI risks, RAG architectures, guardrails, and practical AppSec techniques.
Open-Source Projects
Tools and frameworks you can use today — Secure-ML, OWASP Secure Coding rules, Agentic AI Design Patterns, RAG Strategies, and more.
Resource Library
Curated resources, cheatsheets, and guides organized across the three knowledge pillars. All free, no login needed.
Videos & Webinars
Recorded SANS webinars and conference talks on AI/ML security, GenAI application security, and modern AppSec practices.
Custom GPTs
Purpose-built GPT tools for threat modeling, security review, and professional knowledge exchange — free to use on ChatGPT.
About the Author
GSE #335, SANS Associate Instructor, RSA Conference speaker, CompTIA SME, and D.Eng. Cybersecurity candidate at GWU.
About the Author
Viswanath Chirravuri publishes all content here as a free contribution to the security community. No paywalls, no subscriptions — just practical knowledge for practitioners building and securing AI systems.