THE SECURITY WORKBENCH

Larry Rust.

Application Security | Identity | API Security | Cloud | AI Security

Understand the system.
Question the boundaries.

I’m building and documenting hands-on application-security work—turning questions about how systems fail into experiments, evidence, and clear explanations.

ACROSS THE LIFECYCLE

Threat modeling / Secure development / Security testing / DevSecOps

ON THE WORKBENCH

A foundation for deeper work.

All projects

These are planned directions. Repositories, findings, and case studies will be added as the work takes shape.

01 / IDENTITYPlanned

Identity & access lab

Explore how authentication, authorization, and session boundaries hold up in a deliberately scoped lab.

  • OAuth 2.0
  • OpenID Connect
  • Authorization
02 / APPLICATION SECURITYPlanned

API security review

Trace an API from request to data access, with a focus on object authorization and input boundaries.

  • REST APIs
  • Access control
  • Security testing
03 / CLOUD & DEVSECOPSPlanned

Secure delivery pipeline

Investigate practical security checks across source code, dependencies, and cloud configuration.

  • CI/CD
  • Dependency analysis
  • Cloud configuration

RESEARCH & NOTES

Follow the questions.

A place for threat models, AppSec writeups, experiments, and AI-security research—with assumptions and limitations in view.

Explore research