# riramar/Web-Attack-Cheat-Sheet

Web Attack Cheat Sheet

Repository: https://github.com/riramar/Web-Attack-Cheat-Sheet
Canonical: https://ross.abutalabs.com/products/web-attack-cheat-sheet
License Family: other
Last push: 2026-08-16T18:50:32+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 2426, "days_push": 17, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4433, forks 672 (observed 2026-08-28T04:08:49.196032+00:00)

## What it is
A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and exploitation. It organizes links across categories like SQL injection, XSS, SSRF, subdomain takeover, and bug bounty reconnaissance.

## Use cases
- find tools for web application penetration testing
- learn common web attack techniques like SQLi and XSS
- reconnaissance resources for bug bounty hunting
- find wordlists and tools for directory bruteforcing
- reference payloads for SSRF and XXE attacks
- discover subdomain enumeration and takeover tools

## When to choose
- you need a quick reference of offensive web security tools and techniques
- you are preparing for bug bounty or pentest engagements
- you want a curated starting point for learning web attacks

## When to avoid
- you need defensive security guidance or secure coding practices
- you want a runnable tool rather than a list of links
- you need a formal training course with structured lessons

## Facets
- artifact type: learning-resource
- maturity: active
- function: penetration-testing, security, osint, vulnerability-scanning
- domain: security, penetration-testing, web-development, awesome-lists
- platform: cli, cross-platform
- tags: cheat-sheet, bug-bounty, web-security, offensive-security, curated-list, sqli, xss, ssrf, web-server

## Member repositories
- riramar/Web-Attack-Cheat-Sheet (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:49.196032+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:20:53.427801+00:00, confidence not recorded.
  - readme: https://github.com/riramar/Web-Attack-Cheat-Sheet (fetched 2026-08-28T04:08:49.196032+00:00, sha af68ad7a2b9e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
