Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: penetration-testing

422 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
gh0stkey/Web-Fuzzing-Box
A curated collection of web fuzzing dictionaries and payloads covering brute force, directory enumeration, and common web vulnerabilities l…
652792active
Integration-IT/Active-Directory-Exploitation-Cheat-Sheet
A curated cheat sheet covering common enumeration and attack techniques for Windows Active Directory environments, organized as a kill-chai…
462761active
Hacking-the-Cloud/hackingthe.cloud
Hacking the Cloud is a community-maintained encyclopedia of offensive and defensive security techniques for cloud native technologies, cove…
842746active
imran-parray/Mind-Maps
A curated collection of visual mind maps covering bug bounty hunting, penetration testing, and offensive/defensive security methodologies. …
322725stable
gracenolan/Notes
A curated set of interview study notes for Security Engineering roles, written by a Google security engineer. It covers networking, web app…
622711active
threedr3am/learnjavabug
A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jac…
322687active
tennc/webshell
A curated open-source collection of webshells written in PHP, JSP, ASP, ASPX, Perl, and Python, maintained as a reference repository for se…
2310774maintenance
JoyChou93/java-sec-code
A Spring Boot-based Java web application containing intentionally vulnerable code examples for common vulnerability types like SQLi, SSRF, …
232673active
netbiosX/Checklists
A curated collection of penetration testing and red teaming checklists covering techniques like privilege escalation, persistence, credenti…
472657active
Mr-xn/RedTeam_BlueTeam_HW
A curated collection of red team and blue team tools, documents, and reference materials for Chinese HW (HVV) attack-defense exercises. It …
762643active
Lifka/hacking-resources
A curated collection of hacking resources, cheat sheets, tools, scripts, and tutorials for offensive and defensive security professionals. …
322611active
Ignitetechnologies/BurpSuite-For-Pentester
A curated cheat sheet and learning guide for using Burp Suite in web application penetration testing and bug bounty hunting. It links struc…
652588active
Crypto-Cat/CTF
A collection of CTF challenge files, write-ups, and exploit scripts (mostly pwn/binary exploitation) accompanying CryptoCat's video walkthr…
622544active
rawfilejson/awesome-osint-arsenal
A curated awesome-list of 753+ open-source OSINT and security tools across 50 categories, paired with shell installer scripts for one-comma…
562538active
cujanovic/SSRF-Testing
A collection of SSRF (Server Side Request Forgery) testing resources including URL bypass payloads and a public test server that generates …
322505active
coffeehb/Some-PoC-oR-ExP
A curated collection of proof-of-concept (PoC) scripts and exploits for various software vulnerabilities, written and gathered in Python. I…
452502active
gtworek/Priv2Admin
A reference guide mapping Windows OS privileges to exploitation paths for privilege escalation and other security impacts. It catalogs each…
322500active
OWASP/masvs
The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard defining baseline security and privacy require…
492437active
fkie-cad/awesome-embedded-and-iot-security
A curated awesome-list of resources for embedded and IoT security, including software and hardware tools, books, research papers, case stud…
322430active
bst04/CyberSources
A curated list (awesome-list style) of cybersecurity tools, resources, and educational materials covering OSINT, pentesting, cryptography, …
662395active
terjanq/Tiny-XSS-Payloads
A curated collection of minimal cross-site scripting (XSS) payloads organized by injection context, with an interactive demo site. It serve…
322386active
swisskyrepo/InternalAllTheThings
A collection of cheatsheets covering Active Directory and internal network penetration testing techniques, payloads, and bypasses. It is ma…
752385active
kkrypt0nn/wordlists
A curated collection of wordlists for security tasks such as password brute-forcing, username enumeration, and directory scanning, sorted b…
772352active
elementalsouls/Claude-OSINT
A collection of eight drop-in SKILL.md files for the Claude skills system that prime Claude with expert offensive OSINT and external recon …
592342active
OpenZeppelin/ethernaut
Ethernaut is a Web3/Solidity-based wargame played in the Ethereum Virtual Machine, where each level is a smart contract that must be hacked…
772330active
Y4tacker/JavaSec
A personal study repository documenting the author's Java security learning journey, from fundamentals like reflection and dynamic proxies …
662300active
fuzzdb-project/fuzzdb
FuzzDB is a comprehensive open-source dictionary of attack payloads, predictable resource locations, and regex patterns for black-box appli…
328980maintenance
SecWiki/windows-kernel-exploits
A curated collection of Windows kernel privilege escalation exploits and proof-of-concept code, organized by CVE and security bulletin with…
328719maintenance
iknowjason/Awesome-CloudSec-Labs
A curated list of free cloud native security learning labs, including CTFs, self-hosted workshops, guided vulnerability labs, and research …
492182active
biggerduck/RedTeamNotes
A collection of practical red team notes documenting small, specific problems and solutions encountered during real-world offensive securit…
652180active
eeeeeeeeee-code/POC
A curated backup of the wy876 vulnerability database collecting proof-of-concept exploits (POC/EXP) for a wide range of software, mostly Ch…
612180active
TheKingOfDuck/fuzzDicts
A curated collection of Chinese-community-maintained wordlists for web penetration testing, covering parameters, XSS payloads, usernames, p…
328422maintenance
center-for-threat-informed-defense/adversary_emulation_library
An open library of adversary emulation plans from MITRE's Center for Threat-Informed Defense, mapping real-world adversary TTPs to MITRE AT…
332156active
greshake/llm-security
A research repository demonstrating indirect prompt injection attacks against application-integrated LLMs like Bing Chat, GPT-4, and LangCh…
452130active
0xmaximus/Galaxy-Bugbounty-Checklist
A curated collection of checklists, tips, and tutorials for bug bounty hunting and penetration testing. It organizes attack techniques (e.g…
522115active
notthehiddenwiki/NTHW
A large community-maintained wiki of over 5,000 curated cybersecurity links, including tools, publications, and recordings. It also hosts r…
702112active
gquere/pwn_jenkins
A collection of notes, scripts, and references for attacking and pentesting Jenkins CI/CD servers, covering known CVEs like arbitrary file …
322096active
six2dez/pentest-book
A GitBook-hosted pentesting wiki containing commands, scripts, techniques, and cheatsheets used by the author during penetration tests. It …
752087active
microsoft/AI-Red-Teaming-Playground-Labs
A set of hands-on AI red teaming playground labs from Microsoft, built on a modified Chat Copilot, used to teach adversarial attacks on AI …
492049active
m14r41/PentestingEverything
A structured penetration testing knowledge base covering 23 security domains (web, mobile, API, cloud, network, Active Directory, SAST, Dev…
832044active
saeidshirazi/awesome-android-security
A curated list of Android security materials and resources for pentesters and bug hunters, covering blogs, papers, books, trainings, tools,…
732014active
hslatman/awesome-industrial-control-system-security
A curated awesome-list of resources, tools, and references for Industrial Control System (ICS) and SCADA security. It catalogs tools for IC…
532004active
FalsePhilosopher/badusb
A community-maintained library of BadUSB payloads for the Flipper Zero, organized into categories like exfiltration, phishing, remote_acces…
961963active
ReAbout/web-sec
A continuously updated Chinese-language web security handbook (red team skill stack) organized as a curated knowledge base covering vulnera…
741943active
ihebski/A-Red-Teamer-diaries
A public collection of red team and penetration testing notes, cheatsheets, and command snippets tested on controlled lab infrastructures. …
541932active
fabionoth/awesome-cyber-security
A curated awesome-list collecting cybersecurity software, libraries, documents, books, certifications, CTF resources, and tools. It organiz…
761930active
evilc0deooo/PentesterSpecialDict
A curated collection of fuzzing and penetration-testing dictionaries covering payloads, usernames, passwords, file paths, DNS subnames, and…
441909active
BullsEye0/google_dork_list
A regularly updated plain-text dataset of over 13,700 Google dork search queries used to locate vulnerable, misconfigured, or exposed websi…
751906active
RoseSecurity/Red-Teaming-TTPs
A curated collection of cheatsheets, guides, and scripts covering red teaming tactics, techniques, and procedures across Windows, Linux, ma…
761897active
yogsec/Hacking-Tools
A curated list of penetration testing and ethical hacking tools organized by category, drawing from Kali Linux and other notable sources. I…
651892active
yaklang/hack-skills
A curated knowledge base of 101 installable 'SKILL.md' security skills for AI agents, organized into a master entry, six category entries, …
531879active
safe6Sec/Fastjson
A curated collection of Fastjson exploitation techniques, payloads, and fingerprinting tricks for Java JSON deserialization vulnerabilities…
321860active
lutfumertceylan/top25-parameter
OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XS…
231847stable
xalgord/Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
A curated collection of notes, tutorials, and resources for learning web application penetration testing and bug bounty hunting. It covers …
511845active
AabyssZG/WebShell-Bypass-Guide
A Chinese-language open-source manual for learning WebShell antivirus-evasion (bypass) techniques from scratch, primarily covering PHP with…
311837active
Ignitetechnologies/HackTheBox-CTF-Writeups
A curated collection of Hack The Box machine write-ups and CTF walkthroughs from Hacking Articles, organized by operating system and diffic…
651831active
aleff-github/my-flipper-shits
A curated collection of free and open-source BadUSB payloads written in DuckyScript for the Flipper Zero device, covering Windows, GNU/Linu…
721824active
strandjs/IntroLabs
A collection of hands-on lab exercises for an introductory security/penetration testing class. It is publicly available course material rat…
741819active
daffainfo/AllAboutBugBounty
A curated collection of bug bounty notes covering web vulnerabilities, bypass techniques, and payloads gathered from various sources. It is…
326835maintenance
rootkit-io/awesome-malware-development
A curated awesome-list of resources for malware development, rootkits, EDR evasion, and red-team tooling, intended for educational and defe…
661816active
coinspect/learn-evm-attacks
A collection of Foundry tests reproducing real-world smart contract exploits, bug bounty reports, and theoretical vulnerabilities across EV…
531802active
jeanphorn/wordlist
A curated collection of password wordlists, username lists, and default credentials (SSH, RDP, FTP, databases, IoT, IP cameras) for authori…
681801active
eastmountyxz/NetworkSecuritySelf-study
A curated series of self-study notes and tutorials on network security, covering tools like Burp Suite, Nmap, Wireshark, Sqlmap, IDA Pro, a…
321794active
trickest/wordlists
A regularly updated collection of real-world infosec wordlists maintained by Trickest, including technology-specific path lists (WordPress,…
771791active
rootsecdev/Azure-Red-Team
A curated collection of notes, links, and resources for Microsoft Azure and Microsoft 365 red teaming and penetration testing. It covers en…
631773active
arch3rPro/PentestTools
A curated awesome-list cataloging open-source penetration testing tools, organized by category and modeled on the Kali Tools listing. It se…
671763active
EdOverflow/bugbounty-cheatsheet
A curated cheat sheet of payloads, tips, and tricks for bug bounty hunters, covering vulnerabilities like XSS, SQLi, SSRF, XXE, and RCE. It…
326536maintenance
protectai/ai-exploits
A collection of real-world AI/ML exploits and scanning templates for responsibly disclosed vulnerabilities in machine learning tools and in…
271746active
yeahhub/Hacking-Security-Ebooks
A curated collection of roughly 100 free PDF e-books on hacking, penetration testing, and information security, with links to each title. I…
326439maintenance
duyet/bruteforce-database
A curated collection of wordlists (11+ million entries) for password cracking, username enumeration, subdomain discovery, and web path brut…
741726active
WADComs/WADComs.github.io
WADComs is an interactive cheat sheet website hosting a curated list of offensive security tools and their commands for attacking Windows a…
761713active
hmaverickadams/Beginner-Network-Pentesting
A collection of course notes for a free Beginner Network Pentesting course taught by The Cyber Mentor, covering ethical hacking fundamental…
326348maintenance
B3nac/Android-Reports-and-Resources
A curated list of disclosed HackerOne bug bounty reports and security resources focused on Android application vulnerabilities. It organize…
511706active
wgpsec/AboutSecurity
A large structured penetration testing knowledge base containing 200+ skill methodologies covering recon, exploitation, lateral movement, a…
651702active
ctf-wiki/ctf-challenges
A curated collection of CTF (Capture The Flag) challenges organized by category, including source files, writeups, and related materials. I…
411697active
randorisec/MobileHackingCheatSheet
A cheat sheet summarizing commands, tools, and techniques for assessing the security of Android and iOS mobile applications. It is availabl…
561683active
LandGrey/SpringBootVulExploit
A curated collection of Spring Boot vulnerability learning materials, exploitation methods, and a black-box security assessment checklist. …
326144maintenance
TCM-Course-Resources/Practical-Ethical-Hacking-Resources
A curated compilation of links, tools, and references accompanying TCM Security's Practical Ethical Hacking Udemy course. It organizes reso…
326113maintenance
RPISEC/MBE
Course materials for RPISEC's Modern Binary Exploitation, a university course teaching binary exploitation, reverse engineering, and vulner…
236033maintenance
The-XSS-Rat/SecurityTesting
A Python-based repository by The XSS Rat focused on security testing, likely containing scripts, labs, or educational material for web appl…
641623active
Anugrahsr/Awesome-web3-Security
A curated awesome-list of web3 security materials and resources aimed at pentesters and bug hunters. It collects vulnerable CTF platforms, …
641620active
psiinon/open-source-web-scanners
A curated list of open source web security scanners hosted on GitHub and GitLab, ordered by stars. It serves as a discovery resource coveri…
411615active
m0nad/awesome-privilege-escalation
A curated awesome-list of resources for privilege escalation on Linux, Windows, Docker, and cloud platforms. It aggregates guides, papers, …
651595active
Audi-1/sqli-labs
SQLI-LABS is a self-hosted PHP web application of deliberately vulnerable SQL injection labs for learning and practicing SQL injection tech…
325833maintenance
tkmru/awesome-edr-bypass
A curated awesome-list of resources, proof-of-concept code, and tools for bypassing Endpoint Detection and Response (EDR) software, aimed a…
591585active
xairy/kernel-exploits
A collection of proof-of-concept exploits for Linux kernel vulnerabilities written in C, covering CVEs from 2016 to 2025. Each exploit demo…
511582active
SexyBeast233/SecDictionary
A curated collection of wordlists and dictionaries for security testing, built from real-world penetration testing experience. It includes …
751581active
Berkanktk/CyberSecurity
A curated collection of foundational cybersecurity knowledge organized into topics like security models, threat intelligence, penetration t…
631581active
0xJs/RedTeaming_CheatSheet
A community-maintained pentesting and red teaming cheatsheet collecting commands and techniques across infrastructure, Windows Active Direc…
561576active
rapid7/metasploitable3
Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit developme…
355681maintenance
SecWiki/linux-kernel-exploits
A curated collection of Linux kernel privilege escalation exploits organized by CVE, with descriptions and affected kernel versions. It ser…
325650maintenance
OlivierLaflamme/Cheatsheet-God
A curated collection of penetration testing cheatsheets, scripts, and how-to guides compiled for OSCP/PTP/PTX exam preparation and general …
325622maintenance
euphrat1ca/Security-List
A curated Chinese-language security knowledge index (awesome-style list) covering the full red team attack lifecycle, from reconnaissance a…
321529active
I-Am-Jakoby/PowerShell-for-Hackers
A curated collection of PowerShell functions useful for hackers and payload developers, contributed by the top Hak5 payload creator. Each f…
321523active
vavkamil/awesome-vulnerable-apps
A curated awesome-list of intentionally vulnerable applications, VMs, and CTF platforms for practicing security skills. It covers web explo…
711471active
skyw4tch3r/RootKits-List-Download
A curated list of links to rootkit projects and resources found on GitHub and other sites, covering Linux, Windows, BSD, and Android rootki…
501465active
chvancooten/OSEP-Code-Snippets
A collection of code snippets and boilerplate tools for Offensive Security's PEN-300 (OSEP) course, covering Windows privilege escalation, …
471464active
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
A curated collection of study notes covering over 110 PortSwigger Web Security Academy labs used to pass the Burp Suite Certified Practitio…
751461active
rootphantomer/Blasting_dictionary
A collection of dictionaries (wordlists) for brute-force attacks, commonly used with tools like Hydra, Burp Suite, and other password-crust…
325284maintenance
BehiSecc/First-Bounty
A beginner-friendly bug bounty roadmap repository that guides readers from zero knowledge in web application security to earning their firs…
361459active

← prev page 2 / 5 next →