This document presents an overview of application security, focusing on threat defense in client/server applications, highlighting the various types of attackers and common application vulnerabilities. It emphasizes threat modeling, detailing strategies to identify, rank, and defend against attacks such as authentication failures, SQL injection, cross-site scripting, and buffer overflows. Additionally, it provides resources for best practices, tools, and training to improve application security.