resource: fuzzing
39 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| danielmiessler/SecLists SecLists is a curated collection of security testing lists including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads,… | 83 | 73106 | active |
| minimaxir/big-list-of-naughty-strings A curated list of strings with a high probability of causing issues when used as user input, provided as newline-delimited text and JSON fi… | 32 | 47712 | maintenance |
| secfigo/Awesome-Fuzzing A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I… | 32 | 5904 | active |
| arainho/awesome-api-security A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin… | 10 | 3862 | active |
| antonio-morales/Fuzzing101 A step-by-step fuzzing course from GitHub Security Lab with 10 exercises targeting real software like Xpdf, libexif, and Chrome/V8. Learner… | 71 | 3817 | stable |
| google/fuzzing A Google-hosted collection of tutorials, examples, documentation, and research proposals about fuzz testing, primarily aimed at C/C++ devel… | 10 | 3782 | active |
| Bo0oM/fuzz.txt A curated wordlist of potentially dangerous and sensitive file paths for web fuzzing and directory brute-forcing. It is commonly used with … | 75 | 3321 | active |
| six2dez/OneListForAll A curated collection of wordlists for web fuzzing, aggregating ~36 source repositories into categorized short/long lists and combined 'onel… | 67 | 3231 | active |
| gh0stkey/Web-Fuzzing-Box A curated collection of web fuzzing dictionaries and payloads covering brute force, directory enumeration, and common web vulnerabilities l… | 65 | 2792 | active |
| wcventure/FuzzingPaper A curated collection of recent academic papers on fuzzing and fuzz testing, organized by publication venue and maintained via community pul… | 65 | 2768 | active |
| asatarin/testing-distributed-systems A curated list of resources on testing distributed systems, including research papers, tools, and case studies. It covers approaches like J… | 75 | 2635 | active |
| crytic/building-secure-contracts A Trail of Bits maintained collection of guidelines, best practices, and training material for developing secure smart contracts. It covers… | 57 | 2481 | active |
| TheKingOfDuck/fuzzDicts A curated collection of Chinese-community-maintained wordlists for web penetration testing, covering parameters, XSS payloads, usernames, p… | 32 | 8422 | maintenance |
| evilc0deooo/PentesterSpecialDict A curated collection of fuzzing and penetration-testing dictionaries covering payloads, usernames, passwords, file paths, DNS subnames, and… | 44 | 1909 | active |
| tnballo/high-assurance-rust A free online book, 'High Assurance Rust', teaching secure and robust systems software development in Rust through a project-based approach… | 46 | 1413 | active |
| gmelodie/awesome-wordlists A curated awesome-list of wordlists for brute-forcing and fuzzing, covering enumeration, passwords, usernames, emails, and vulnerabilities.… | 73 | 1276 | active |
| uds-se/fuzzingbook An interactive online textbook on automated software testing and fuzzing, with executable code available as Jupyter notebooks, web pages, s… | 61 | 1269 | active |
| tandasat/Hypervisor-101-in-Rust Course materials for 'Hypervisor 101 in Rust', a one-day class on hardware-assisted virtualization and its use for high-performance fuzzing… | 51 | 1207 | active |
| nst/JSONTestSuite A comprehensive test suite of JSON files for validating RFC 8259 compliant JSON parsers, with files named to indicate whether content must … | 32 | 1163 | stable |
| foospidy/payloads A curated collection of web attack payloads (XSS, SQLi, CRLF, open redirect, password lists, and more) aggregated from many well-known secu… | 32 | 3979 | maintenance |
| 1N3/IntruderPayloads A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodol… | 32 | 3970 | maintenance |
| ashemery/exploitation-course A free online course on offensive security and reverse engineering (OSRE), originally taught at Champlain College, with labs, slides, notes… | 32 | 2523 | maintenance |
| insightglacier/Dictionary-Of-Pentesting A curated collection of dictionaries and wordlists for penetration testing, SRC bug bounty hunting, bruteforcing, and fuzzing. It aggregate… | 23 | 2072 | maintenance |
| google/fuzzer-test-suite A suite of fuzzing benchmarks derived from real-life C/C++ libraries with interesting bugs and hard-to-reach code paths, designed to evalua… | 10 | 1471 | maintenance |
| tennc/fuzzdb A curated dictionary collection of attack patterns, payloads, and brute-force wordlists for black-box application fault injection and resou… | 23 | 1399 | maintenance |
| Dor1s/libfuzzer-workshop Workshop materials for 'Modern fuzzing of C/C++ Projects', teaching coverage-guided fuzzing with libFuzzer through hands-on examples like f… | 32 | 1307 | maintenance |
| mykter/afl-training A hands-on workshop and set of exercises for learning how to fuzz C programs with American Fuzzy Lop (and afl++), including challenges base… | 32 | 1283 | maintenance |
| Stardustsky/SaiDict A curated collection of attack dictionaries for penetration testing, including weak passwords, common usernames, sensitive directory and fi… | 32 | 1219 | maintenance |
| lcatro/Source-and-Fuzzing A Chinese-language tutorial repository teaching source-code reading and fuzzing, covering black-box and white-box testing with real-world e… | 32 | 1082 | maintenance |
| 3had0w/Fuzzing-Dicts A curated collection of dictionaries and wordlists for web security testing, including payloads for fuzzing, directory brute-forcing, and v… | 32 | 1028 | maintenance |
| spacejam/tla-rust A tutorial-style repository and work-in-progress project for writing correct lock-free and distributed stateful systems in Rust, verified w… | 32 | 1068 | abandoned |
| Hack-with-Github/Awesome-Hacking A curated meta-collection of awesome lists for hackers, pentesters, and security researchers. It aggregates links to specialized repositori… | 75 | 119102 | active |
| xairy/linux-kernel-exploitation A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic… | 76 | 6602 | active |
| euphrat1ca/Security-List A curated Chinese-language security knowledge index (awesome-style list) covering the full red team attack lifecycle, from reconnaissance a… | 32 | 1529 | active |
| ayoubfathi/leaky-paths A curated wordlist of special web paths linked to sensitive APIs, devops internals, framework configs, and known misconfigurations. It is d… | 66 | 1193 | active |
| scadastrangelove/awesome-ai-security-tools A curated awesome-list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. It catalogs tools ac… | 59 | 1095 | active |
| parsiya/Hacking-with-Go A free tutorial series teaching Go programming to security professionals, modeled on the Black Hat Python/C# book series. It covers Go fund… | 10 | 1815 | maintenance |
| cn0xroot/RFSec-ToolKit A curated collection of radio frequency communication protocol hacking tools, tutorials, and resources covering SDR hardware/software, GSM,… | 32 | 1721 | maintenance |
| sergey-pronin/Awesome-Vulnerability-Research A curated awesome-list of resources for vulnerability research, including books, articles, courses, tools, write-ups, and methodologies. It… | 32 | 1348 | maintenance |
page 1 / 1