resource: penetration-testing
422 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| Hack-with-Github/Awesome-Hacking A curated meta-collection of awesome lists for hackers, pentesters, and security researchers. It aggregates links to specialized repositori… | 75 | 119102 | active |
| swisskyrepo/PayloadsAllTheThings A curated collection of payloads, bypasses, and exploitation techniques for web application security testing. It serves as a reference chea… | 66 | 80407 | active |
| danielmiessler/SecLists SecLists is a curated collection of security testing lists including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads,… | 83 | 73106 | active |
| The-Art-of-Hacking/h4cker A large curated collection of cybersecurity resources covering ethical hacking, penetration testing, DFIR, AI security, exploit development… | 76 | 29141 | active |
| enaqx/awesome-pentest A curated awesome-list of penetration testing and offensive security resources, tools, books, conferences, and training materials. It organ… | 75 | 27017 | active |
| elder-plinius/L1B3RT4S A public collection of jailbreak prompts and adversarial attack techniques targeting flagship LLMs, maintained by researcher elder-plinius.… | 55 | 21185 | active |
| vulhub/vulhub Vulhub is an open-source collection of pre-built vulnerable Docker environments, each launched with a single docker compose command and doc… | 74 | 21167 | active |
| farhanashrafdev/90DaysOfCyberSecurity A curated 90-day self-paced cybersecurity study plan organized into daily tasks with links to tutorials, reading materials, and hands-on ex… | 63 | 18659 | active |
| vitalysim/Awesome-Hacking-Resources A curated awesome-list of hacking, penetration testing, and AI red-teaming resources including courses, YouTube channels, labs, and tools. … | 70 | 17359 | active |
| sbilly/awesome-security A curated, community-driven awesome list of security software, libraries, books, documents, and resources. It organizes tools across catego… | 60 | 14797 | active |
| Hacker0x01/hacker101 Hacker101 is a free online web and mobile security class from HackerOne, offering video lessons and capture-the-flag exercises. This reposi… | 36 | 14512 | active |
| qazbnm456/awesome-web-security A curated list of web security materials and resources covering vulnerabilities like XSS, SQL injection, SSRF, CSRF, and more. It also ship… | 76 | 13732 | active |
| GTFOBins/GTFOBins.github.io GTFOBins is a curated, community-maintained dataset and reference website of Unix-like executables that can be abused to bypass local secur… | 70 | 13590 | active |
| OWASP/mastg The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and rever… | 95 | 13137 | active |
| projectdiscovery/nuclei-templates A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misco… | 99 | 12849 | active |
| brannondorsey/wifi-cracking A tutorial repository teaching how to crack WPA/WPA2 Wi-Fi passwords using Airodump-ng, Aircrack-ng, and Hashcat. It walks through monitor … | 23 | 12594 | stable |
| nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters A curated list of resources for people getting started in bug bounty hunting and web security. It links to tools, labs, books, talks, and v… | 32 | 12201 | active |
| HackTricks-wiki/hacktricks HackTricks is a community-maintained wiki/book of hacking tricks, techniques, and notes gathered from CTFs, real-world pentests, and resear… | 82 | 12174 | active |
| apsdehal/awesome-ctf A curated list of Capture The Flag (CTF) frameworks, libraries, tools, platforms, and tutorials. It aggregates resources for both creating … | 32 | 11798 | active |
| knownsec/404StarLink 404StarLink is a curated showcase program by Knownsec 404 Lab that collects, tracks, and promotes high-quality open-source security project… | 75 | 11131 | active |
| infosecn1nja/Red-Teaming-Toolkit A curated list of cutting-edge open-source security tools for red teamers and threat hunters, organized by attack lifecycle stages such as … | 69 | 10654 | active |
| OWASP/wstg The OWASP Web Security Testing Guide (WSTG) is a comprehensive, community-maintained guide to testing the security of web applications and … | 67 | 9755 | active |
| juliocesarfort/public-pentesting-reports A curated collection of publicly available penetration test reports published by consulting firms and academic security groups. It serves a… | 71 | 9693 | active |
| A-poc/RedTeam-Tools A curated collection of 150+ tools, techniques, and tips for red teaming and penetration testing, organized by category with links to exter… | 67 | 9664 | active |
| ashishb/android-security-awesome A curated awesome-list of Android security-related resources, including tools, academic publications, and exploit/vulnerability references.… | 76 | 9646 | active |
| ctf-wiki/ctf-wiki CTF Wiki is a community-maintained, open documentation site that systematically teaches Capture The Flag (CTF) cybersecurity competition sk… | 77 | 9594 | active |
| toniblyx/my-arsenal-of-aws-security-tools A curated list of open-source security tools for AWS, organized into defensive, offensive, purple teaming, continuous auditing, DFIR, and d… | 73 | 9502 | active |
| WebGoat/WebGoat OWASP WebGoat is a deliberately insecure web application designed to teach web application security lessons through hands-on exercises. It … | 79 | 9293 | active |
| We5ter/Scanners-Box A curated awesome-list of 9,000+ open-source cybersecurity tools covering subdomain enumeration, SQL injection, red team/blue team tooling,… | 76 | 9024 | active |
| LOLBAS-Project/LOLBAS A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques… | 77 | 8771 | active |
| Orange-Cyberdefense/GOAD GOAD (Game Of Active Directory) is a pentest lab project that provisions intentionally vulnerable Active Directory environments using Vagra… | 64 | 8240 | active |
| guchangan1/All-Defense-Tool A curated, weekly auto-updated collection of open-source offensive and defensive security tools, covering information gathering, vulnerabil… | 77 | 7949 | active |
| jakejarvis/awesome-shodan-queries A curated awesome-list of interesting, funny, and alarming search queries (dorks) for Shodan, the internet-connected device search engine. … | 32 | 7674 | active |
| 0xInfection/Awesome-WAF A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, d… | 77 | 7592 | active |
| Mr-xn/Penetration_Testing_POC A curated collection of penetration testing resources including POCs, exploits, scripts, privilege escalation tools, and write-ups for web … | 77 | 7471 | active |
| infoslack/awesome-web-hacking A curated awesome-list of resources for learning web application security, including books, documentation, tools, cheat sheets, courses, la… | 76 | 7246 | active |
| KathanP19/HowToHunt HowToHunt is a community-curated collection of practical guides, methodologies, and test cases for hunting web vulnerabilities, aimed at bu… | 45 | 7189 | active |
| I-Am-Jakoby/Flipper-Zero-BadUSB A collection of BadUSB payloads for the Flipper Zero device, formatted to be largely plug-and-play. Payloads are written mostly in PowerShe… | 32 | 7034 | active |
| S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet A curated cheat sheet of common enumeration and attack techniques for Windows Active Directory environments. It serves as a quick reference… | 70 | 6715 | active |
| xairy/linux-kernel-exploitation A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic… | 76 | 6602 | active |
| CarterPerez-dev/Cybersecurity-Projects A curated repository of 70 hands-on cybersecurity projects ranging from foundations to advanced, with full source code, certification roadm… | 61 | 6235 | active |
| vavkamil/awesome-bugbounty-tools A curated awesome-list of bug bounty and web security tools, organized by recon and exploitation categories. It catalogs tools for subdomai… | 76 | 6199 | active |
| rmusser01/Infosec_Reference A large curated reference of information security tools, techniques, and learning resources covering offensive and defensive security topic… | 53 | 5986 | active |
| hak5/usbrubberducky-payloads The official community payload repository for the Hak5 USB Rubber Ducky, containing DuckyScript payloads, extensions, and language files fo… | 71 | 5953 | active |
| secfigo/Awesome-Fuzzing A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I… | 32 | 5904 | active |
| djadmin/awesome-bug-bounty A curated awesome-list of bug bounty and responsible disclosure programs, hunter write-ups, and getting-started resources. It serves as a r… | 64 | 5871 | active |
| madhuakula/kubernetes-goat Kubernetes Goat is an intentionally vulnerable-by-design Kubernetes cluster environment that serves as an interactive, hands-on playground … | 57 | 5756 | active |
| onlurking/awesome-infosec A curated awesome-style list of information security learning resources, including MOOCs, academic courses, labs, CTFs, books, and challeng… | 76 | 5726 | active |
| KingOfBugbounty/KingOfBugBountyTips A curated collection of bug bounty reconnaissance tips and one-liner commands shared by well-known bug hunters, with explanations to help n… | 73 | 5521 | active |
| LyleMi/Learn-Web-Hacking A comprehensive set of study notes on web security covering network protocols, information gathering, common vulnerabilities, intranet pene… | 76 | 5514 | active |
| devsecops/awesome-devsecops A curated awesome-list of free and open-source DevSecOps resources, including tools, guidelines, presentations, training labs, podcasts, an… | 32 | 5461 | active |
| Awesome-POC A curated knowledge base of 1k+ vulnerability Proof-of-Concept (PoC) writeups covering CVEs across CMSs, servers, and network devices. It i… | 68 | 5171 | active |
| s0md3v/AwesomeXSS A curated awesome-list of cross-site scripting (XSS) resources including payloads, polyglots, cheatsheets, tools, challenges, and papers. I… | 32 | 5138 | active |
| jassics/security-study-plan A curated, role-based study plan repository for becoming a cybersecurity engineer, covering paths like penetration testing, AppSec, cloud s… | 76 | 5048 | active |
| hahwul/WebHackersWeapons A curated awesome-list cataloging tools, bookmarklets, browser addons, and Burp/Caido/ZAP extensions used by web hackers for bug bounty and… | 68 | 5042 | active |
| google/google-ctf A repository of most challenges used in the Google CTF since 2017, along with infrastructure for hosting them. It serves as an archive of s… | 62 | 5012 | active |
| infosecn1nja/AD-Attack-Defense A curated knowledge base mapping the Active Directory attack kill chain to detection, mitigation, and prevention guidance. It catalogs atta… | 48 | 4858 | active |
| mantvydasb/RedTeaming-Tactics-and-Techniques ired.team is a publicly accessible collection of personal red teaming and offensive security notes documenting hands-on experiments with at… | 71 | 4679 | active |
| joe-shenouda/awesome-cyber-skills A curated list of hacking environments and platforms where users can legally and safely practice cybersecurity skills. It catalogs free tra… | 23 | 4639 | active |
| google/security-research A repository of security advisories and proof-of-concept exploits from Google security research affecting third-party (non-Google) software… | 77 | 4615 | active |
| riramar/Web-Attack-Cheat-Sheet A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and explo… | 76 | 4433 | active |
| skerkour/black-hat-rust The companion repository for the book 'Black Hat Rust', teaching applied offensive security by building real-world attack tools in Rust. It… | 52 | 4391 | active |
| Threekiii/Awesome-Redteam A curated knowledge base for red teaming and offensive security, collecting cheatsheets, scripts, tips, and links to open-source tools. It … | 71 | 4315 | active |
| bikini/exploitarium A consolidated archive of public exploit proof-of-concept code and vulnerability research writeups, organized as self-contained folders per… | 55 | 4241 | active |
| 0xsyr0/Awesome-Cybersecurity-Handbooks A curated collection of cybersecurity handbooks compiled from the author's personal notes on CTFs and red teaming. It covers offensive and … | 76 | 4069 | active |
| 0xor0ne/awesome-list A curated awesome list of cybersecurity blog posts, write-ups, and papers organized by year, plus a companion list of security tools and re… | 77 | 4068 | active |
| Mr-xn/BurpSuite-collections A curated collection of Burp Suite plugins (mostly non-BApp Store), articles, and usage tips for web penetration testing. It aggregates lin… | 76 | 3964 | active |
| jekil/awesome-hacking A curated list of hacking and security tools for hackers, pentesters, and security researchers, organized by categories like CTF, forensics… | 69 | 3959 | active |
| carpedm20/awesome-hacking A curated awesome-list of hacking tutorials, tools, and resources covering system exploitation, reverse engineering, web security, forensic… | 32 | 16945 | maintenance |
| JoasASantos/OSCE3-Complete-Guide A curated study guide and resource collection for Offensive Security certifications OSCE3 (OSWE, OSEP, OSED) and OSEE. It aggregates refere… | 59 | 3888 | active |
| Samsar4/Ethical-Hacking-Labs A collection of hands-on tutorials and labs for learning ethical hacking, aligned with CEH content. It guides beginners from core networkin… | 32 | 3887 | active |
| hackerschoice/thc-tips-tricks-hacks-cheat-sheet A curated cheat sheet of Linux command-line tips, tricks, and hacks from The Hacker's Choice, covering bash stealth techniques, SSH tunneli… | 73 | 3874 | active |
| arainho/awesome-api-security A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin… | 10 | 3862 | active |
| 0xsyr0/OSCP A comprehensive cheat sheet repository of commands and techniques for preparing for the OSCP (Offensive Security Certified Professional) pe… | 76 | 3831 | active |
| antonio-morales/Fuzzing101 A step-by-step fuzzing course from GitHub Security Lab with 10 exercises targeting real software like Xpdf, libexif, and Chrome/V8. Learner… | 71 | 3817 | stable |
| husnainfareed/awesome-ethical-hacking-resources A curated awesome list of resources for learning ethical hacking and penetration testing, including books, courses, CTF platforms, vulnerab… | 67 | 3745 | active |
| Az0x7/vulnerability-Checklist A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40… | 30 | 3634 | active |
| Ignitetechnologies/Privilege-Escalation A curated cheat sheet and reference guide covering Linux and Windows privilege escalation techniques with worked examples from CTF and Vuln… | 65 | 3630 | active |
| Acmesec/PromptJailbreakManual A Chinese-language manual (handbook) covering prompt engineering, prompt injection, prompt leaking, and LLM jailbreak techniques, with secu… | 12 | 3608 | active |
| vaib25vicky/awesome-mobile-security A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes… | 32 | 3525 | active |
| V33RU/awesome-connected-things-sec A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin… | 76 | 3524 | active |
| 0x4D31/awesome-oscp A curated awesome-list of resources for preparing for the OSCP (Offensive Security Certified Professional) certification. It collects guide… | 32 | 3466 | active |
| snoopysecurity/awesome-burp-extensions A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and … | 76 | 3439 | active |
| matro7sh/BypassAV A curated mindmap (markdown rendered via Markmap) listing essential techniques for bypassing antivirus and EDR software. It serves as a ref… | 27 | 3433 | active |
| Hamed233/Cybersecurity-Mastery-Roadmap A curated, step-by-step roadmap guiding learners from beginner to expert in cybersecurity, organized into phases covering foundations, tech… | 62 | 3367 | active |
| blaCCkHatHacEEkr/PENTESTING-BIBLE A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi… | 32 | 13939 | maintenance |
| dwisiswant0/awesome-oneliner-bugbounty A curated awesome-list collection of one-liner shell scripts for bug bounty hunting, covering tasks like LFI, open-redirect, XSS, prototype… | 32 | 3188 | active |
| neargle/re0-kubernetes-sec-archive A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap… | 55 | 3164 | active |
| ljagiello/ctf-skills A collection of Agent Skills (SKILL.md files) that teach AI coding agents like Claude Code, Codex, and Gemini CLI how to solve Capture The … | 60 | 3104 | active |
| hacksysteam/HackSysExtremeVulnerableDriver HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche… | 26 | 3083 | active |
| awake1t/HackReport A curated Chinese-language collection of penetration testing report templates, security books, conference slides, and hands-on offensive/de… | 32 | 3014 | active |
| w181496/Web-CTF-Cheatsheet A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads … | 54 | 2982 | active |
| SnailSploit/Claude-Red A curated library of 58 offensive security skill files (SKILL.md) for the Claude skills system, covering attack surfaces from SQL injection… | 62 | 2976 | active |
| Flangvik/SharpCollection SharpCollection is a repository of nightly-built precompiled C# offensive security tool binaries (Rubeus, Certify, KrbRelay, etc.), automat… | 75 | 2969 | active |
| hak5/bashbunny-payloads The official community payload repository for the Hak5 Bash Bunny USB attack platform, containing payloads written in DuckyScript and Bash.… | 62 | 2947 | active |
| ivRodriguezCA/RE-iOS-Apps A free, open-source online course teaching reverse engineering of iOS applications across five modules, from environment setup to binary pa… | 32 | 2901 | active |
| dloss/python-pentest-tools A curated list of Python tools, libraries, and bindings useful for penetration testers, vulnerability researchers, and reverse engineers. I… | 74 | 2883 | active |
| orangetw/My-CTF-Web-Challenges A curated collection of CTF web challenges created by Orange Tsai, including source code, ideas, and write-ups from HITCON and other compet… | 50 | 2857 | active |
| dafthack/CloudPentestCheatsheets A collection of cheatsheets for tools used in penetration testing of cloud provider environments, covering Azure/O365, AWS, and GCP. It foc… | 66 | 2836 | active |
| bugcrowd/bugcrowd_university Bugcrowd University is a free, open-source collection of educational modules for security researchers, including slides, videos, and hands-… | 77 | 2800 | active |
page 1 / 5 next →