Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: penetration-testing

422 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
Hack-with-Github/Awesome-Hacking
A curated meta-collection of awesome lists for hackers, pentesters, and security researchers. It aggregates links to specialized repositori…
75119102active
swisskyrepo/PayloadsAllTheThings
A curated collection of payloads, bypasses, and exploitation techniques for web application security testing. It serves as a reference chea…
6680407active
danielmiessler/SecLists
SecLists is a curated collection of security testing lists including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads,…
8373106active
The-Art-of-Hacking/h4cker
A large curated collection of cybersecurity resources covering ethical hacking, penetration testing, DFIR, AI security, exploit development…
7629141active
enaqx/awesome-pentest
A curated awesome-list of penetration testing and offensive security resources, tools, books, conferences, and training materials. It organ…
7527017active
elder-plinius/L1B3RT4S
A public collection of jailbreak prompts and adversarial attack techniques targeting flagship LLMs, maintained by researcher elder-plinius.…
5521185active
vulhub/vulhub
Vulhub is an open-source collection of pre-built vulnerable Docker environments, each launched with a single docker compose command and doc…
7421167active
farhanashrafdev/90DaysOfCyberSecurity
A curated 90-day self-paced cybersecurity study plan organized into daily tasks with links to tutorials, reading materials, and hands-on ex…
6318659active
vitalysim/Awesome-Hacking-Resources
A curated awesome-list of hacking, penetration testing, and AI red-teaming resources including courses, YouTube channels, labs, and tools. …
7017359active
sbilly/awesome-security
A curated, community-driven awesome list of security software, libraries, books, documents, and resources. It organizes tools across catego…
6014797active
Hacker0x01/hacker101
Hacker101 is a free online web and mobile security class from HackerOne, offering video lessons and capture-the-flag exercises. This reposi…
3614512active
qazbnm456/awesome-web-security
A curated list of web security materials and resources covering vulnerabilities like XSS, SQL injection, SSRF, CSRF, and more. It also ship…
7613732active
GTFOBins/GTFOBins.github.io
GTFOBins is a curated, community-maintained dataset and reference website of Unix-like executables that can be abused to bypass local secur…
7013590active
OWASP/mastg
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and rever…
9513137active
projectdiscovery/nuclei-templates
A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misco…
9912849active
brannondorsey/wifi-cracking
A tutorial repository teaching how to crack WPA/WPA2 Wi-Fi passwords using Airodump-ng, Aircrack-ng, and Hashcat. It walks through monitor …
2312594stable
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A curated list of resources for people getting started in bug bounty hunting and web security. It links to tools, labs, books, talks, and v…
3212201active
HackTricks-wiki/hacktricks
HackTricks is a community-maintained wiki/book of hacking tricks, techniques, and notes gathered from CTFs, real-world pentests, and resear…
8212174active
apsdehal/awesome-ctf
A curated list of Capture The Flag (CTF) frameworks, libraries, tools, platforms, and tutorials. It aggregates resources for both creating …
3211798active
knownsec/404StarLink
404StarLink is a curated showcase program by Knownsec 404 Lab that collects, tracks, and promotes high-quality open-source security project…
7511131active
infosecn1nja/Red-Teaming-Toolkit
A curated list of cutting-edge open-source security tools for red teamers and threat hunters, organized by attack lifecycle stages such as …
6910654active
OWASP/wstg
The OWASP Web Security Testing Guide (WSTG) is a comprehensive, community-maintained guide to testing the security of web applications and …
679755active
juliocesarfort/public-pentesting-reports
A curated collection of publicly available penetration test reports published by consulting firms and academic security groups. It serves a…
719693active
A-poc/RedTeam-Tools
A curated collection of 150+ tools, techniques, and tips for red teaming and penetration testing, organized by category with links to exter…
679664active
ashishb/android-security-awesome
A curated awesome-list of Android security-related resources, including tools, academic publications, and exploit/vulnerability references.…
769646active
ctf-wiki/ctf-wiki
CTF Wiki is a community-maintained, open documentation site that systematically teaches Capture The Flag (CTF) cybersecurity competition sk…
779594active
toniblyx/my-arsenal-of-aws-security-tools
A curated list of open-source security tools for AWS, organized into defensive, offensive, purple teaming, continuous auditing, DFIR, and d…
739502active
WebGoat/WebGoat
OWASP WebGoat is a deliberately insecure web application designed to teach web application security lessons through hands-on exercises. It …
799293active
We5ter/Scanners-Box
A curated awesome-list of 9,000+ open-source cybersecurity tools covering subdomain enumeration, SQL injection, red team/blue team tooling,…
769024active
LOLBAS-Project/LOLBAS
A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques…
778771active
Orange-Cyberdefense/GOAD
GOAD (Game Of Active Directory) is a pentest lab project that provisions intentionally vulnerable Active Directory environments using Vagra…
648240active
guchangan1/All-Defense-Tool
A curated, weekly auto-updated collection of open-source offensive and defensive security tools, covering information gathering, vulnerabil…
777949active
jakejarvis/awesome-shodan-queries
A curated awesome-list of interesting, funny, and alarming search queries (dorks) for Shodan, the internet-connected device search engine. …
327674active
0xInfection/Awesome-WAF
A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, d…
777592active
Mr-xn/Penetration_Testing_POC
A curated collection of penetration testing resources including POCs, exploits, scripts, privilege escalation tools, and write-ups for web …
777471active
infoslack/awesome-web-hacking
A curated awesome-list of resources for learning web application security, including books, documentation, tools, cheat sheets, courses, la…
767246active
KathanP19/HowToHunt
HowToHunt is a community-curated collection of practical guides, methodologies, and test cases for hunting web vulnerabilities, aimed at bu…
457189active
I-Am-Jakoby/Flipper-Zero-BadUSB
A collection of BadUSB payloads for the Flipper Zero device, formatted to be largely plug-and-play. Payloads are written mostly in PowerShe…
327034active
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
A curated cheat sheet of common enumeration and attack techniques for Windows Active Directory environments. It serves as a quick reference…
706715active
xairy/linux-kernel-exploitation
A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic…
766602active
CarterPerez-dev/Cybersecurity-Projects
A curated repository of 70 hands-on cybersecurity projects ranging from foundations to advanced, with full source code, certification roadm…
616235active
vavkamil/awesome-bugbounty-tools
A curated awesome-list of bug bounty and web security tools, organized by recon and exploitation categories. It catalogs tools for subdomai…
766199active
rmusser01/Infosec_Reference
A large curated reference of information security tools, techniques, and learning resources covering offensive and defensive security topic…
535986active
hak5/usbrubberducky-payloads
The official community payload repository for the Hak5 USB Rubber Ducky, containing DuckyScript payloads, extensions, and language files fo…
715953active
secfigo/Awesome-Fuzzing
A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I…
325904active
djadmin/awesome-bug-bounty
A curated awesome-list of bug bounty and responsible disclosure programs, hunter write-ups, and getting-started resources. It serves as a r…
645871active
madhuakula/kubernetes-goat
Kubernetes Goat is an intentionally vulnerable-by-design Kubernetes cluster environment that serves as an interactive, hands-on playground …
575756active
onlurking/awesome-infosec
A curated awesome-style list of information security learning resources, including MOOCs, academic courses, labs, CTFs, books, and challeng…
765726active
KingOfBugbounty/KingOfBugBountyTips
A curated collection of bug bounty reconnaissance tips and one-liner commands shared by well-known bug hunters, with explanations to help n…
735521active
LyleMi/Learn-Web-Hacking
A comprehensive set of study notes on web security covering network protocols, information gathering, common vulnerabilities, intranet pene…
765514active
devsecops/awesome-devsecops
A curated awesome-list of free and open-source DevSecOps resources, including tools, guidelines, presentations, training labs, podcasts, an…
325461active
Awesome-POC
A curated knowledge base of 1k+ vulnerability Proof-of-Concept (PoC) writeups covering CVEs across CMSs, servers, and network devices. It i…
685171active
s0md3v/AwesomeXSS
A curated awesome-list of cross-site scripting (XSS) resources including payloads, polyglots, cheatsheets, tools, challenges, and papers. I…
325138active
jassics/security-study-plan
A curated, role-based study plan repository for becoming a cybersecurity engineer, covering paths like penetration testing, AppSec, cloud s…
765048active
hahwul/WebHackersWeapons
A curated awesome-list cataloging tools, bookmarklets, browser addons, and Burp/Caido/ZAP extensions used by web hackers for bug bounty and…
685042active
google/google-ctf
A repository of most challenges used in the Google CTF since 2017, along with infrastructure for hosting them. It serves as an archive of s…
625012active
infosecn1nja/AD-Attack-Defense
A curated knowledge base mapping the Active Directory attack kill chain to detection, mitigation, and prevention guidance. It catalogs atta…
484858active
mantvydasb/RedTeaming-Tactics-and-Techniques
ired.team is a publicly accessible collection of personal red teaming and offensive security notes documenting hands-on experiments with at…
714679active
joe-shenouda/awesome-cyber-skills
A curated list of hacking environments and platforms where users can legally and safely practice cybersecurity skills. It catalogs free tra…
234639active
google/security-research
A repository of security advisories and proof-of-concept exploits from Google security research affecting third-party (non-Google) software…
774615active
riramar/Web-Attack-Cheat-Sheet
A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and explo…
764433active
skerkour/black-hat-rust
The companion repository for the book 'Black Hat Rust', teaching applied offensive security by building real-world attack tools in Rust. It…
524391active
Threekiii/Awesome-Redteam
A curated knowledge base for red teaming and offensive security, collecting cheatsheets, scripts, tips, and links to open-source tools. It …
714315active
bikini/exploitarium
A consolidated archive of public exploit proof-of-concept code and vulnerability research writeups, organized as self-contained folders per…
554241active
0xsyr0/Awesome-Cybersecurity-Handbooks
A curated collection of cybersecurity handbooks compiled from the author's personal notes on CTFs and red teaming. It covers offensive and …
764069active
0xor0ne/awesome-list
A curated awesome list of cybersecurity blog posts, write-ups, and papers organized by year, plus a companion list of security tools and re…
774068active
Mr-xn/BurpSuite-collections
A curated collection of Burp Suite plugins (mostly non-BApp Store), articles, and usage tips for web penetration testing. It aggregates lin…
763964active
jekil/awesome-hacking
A curated list of hacking and security tools for hackers, pentesters, and security researchers, organized by categories like CTF, forensics…
693959active
carpedm20/awesome-hacking
A curated awesome-list of hacking tutorials, tools, and resources covering system exploitation, reverse engineering, web security, forensic…
3216945maintenance
JoasASantos/OSCE3-Complete-Guide
A curated study guide and resource collection for Offensive Security certifications OSCE3 (OSWE, OSEP, OSED) and OSEE. It aggregates refere…
593888active
Samsar4/Ethical-Hacking-Labs
A collection of hands-on tutorials and labs for learning ethical hacking, aligned with CEH content. It guides beginners from core networkin…
323887active
hackerschoice/thc-tips-tricks-hacks-cheat-sheet
A curated cheat sheet of Linux command-line tips, tricks, and hacks from The Hacker's Choice, covering bash stealth techniques, SSH tunneli…
733874active
arainho/awesome-api-security
A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin…
103862active
0xsyr0/OSCP
A comprehensive cheat sheet repository of commands and techniques for preparing for the OSCP (Offensive Security Certified Professional) pe…
763831active
antonio-morales/Fuzzing101
A step-by-step fuzzing course from GitHub Security Lab with 10 exercises targeting real software like Xpdf, libexif, and Chrome/V8. Learner…
713817stable
husnainfareed/awesome-ethical-hacking-resources
A curated awesome list of resources for learning ethical hacking and penetration testing, including books, courses, CTF platforms, vulnerab…
673745active
Az0x7/vulnerability-Checklist
A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40…
303634active
Ignitetechnologies/Privilege-Escalation
A curated cheat sheet and reference guide covering Linux and Windows privilege escalation techniques with worked examples from CTF and Vuln…
653630active
Acmesec/PromptJailbreakManual
A Chinese-language manual (handbook) covering prompt engineering, prompt injection, prompt leaking, and LLM jailbreak techniques, with secu…
123608active
vaib25vicky/awesome-mobile-security
A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes…
323525active
V33RU/awesome-connected-things-sec
A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin…
763524active
0x4D31/awesome-oscp
A curated awesome-list of resources for preparing for the OSCP (Offensive Security Certified Professional) certification. It collects guide…
323466active
snoopysecurity/awesome-burp-extensions
A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and …
763439active
matro7sh/BypassAV
A curated mindmap (markdown rendered via Markmap) listing essential techniques for bypassing antivirus and EDR software. It serves as a ref…
273433active
Hamed233/Cybersecurity-Mastery-Roadmap
A curated, step-by-step roadmap guiding learners from beginner to expert in cybersecurity, organized into phases covering foundations, tech…
623367active
blaCCkHatHacEEkr/PENTESTING-BIBLE
A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi…
3213939maintenance
dwisiswant0/awesome-oneliner-bugbounty
A curated awesome-list collection of one-liner shell scripts for bug bounty hunting, covering tasks like LFI, open-redirect, XSS, prototype…
323188active
neargle/re0-kubernetes-sec-archive
A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap…
553164active
ljagiello/ctf-skills
A collection of Agent Skills (SKILL.md files) that teach AI coding agents like Claude Code, Codex, and Gemini CLI how to solve Capture The …
603104active
hacksysteam/HackSysExtremeVulnerableDriver
HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche…
263083active
awake1t/HackReport
A curated Chinese-language collection of penetration testing report templates, security books, conference slides, and hands-on offensive/de…
323014active
w181496/Web-CTF-Cheatsheet
A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads …
542982active
SnailSploit/Claude-Red
A curated library of 58 offensive security skill files (SKILL.md) for the Claude skills system, covering attack surfaces from SQL injection…
622976active
Flangvik/SharpCollection
SharpCollection is a repository of nightly-built precompiled C# offensive security tool binaries (Rubeus, Certify, KrbRelay, etc.), automat…
752969active
hak5/bashbunny-payloads
The official community payload repository for the Hak5 Bash Bunny USB attack platform, containing payloads written in DuckyScript and Bash.…
622947active
ivRodriguezCA/RE-iOS-Apps
A free, open-source online course teaching reverse engineering of iOS applications across five modules, from environment setup to binary pa…
322901active
dloss/python-pentest-tools
A curated list of Python tools, libraries, and bindings useful for penetration testers, vulnerability researchers, and reverse engineers. I…
742883active
orangetw/My-CTF-Web-Challenges
A curated collection of CTF web challenges created by Orange Tsai, including source code, ideas, and write-ups from HITCON and other compet…
502857active
dafthack/CloudPentestCheatsheets
A collection of cheatsheets for tools used in penetration testing of cloud provider environments, covering Azure/O365, AWS, and GCP. It foc…
662836active
bugcrowd/bugcrowd_university
Bugcrowd University is a free, open-source collection of educational modules for security researchers, including slides, videos, and hands-…
772800active

page 1 / 5 next →