resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| trimstray/the-book-of-secret-knowledge A curated awesome-list collection of manuals, cheatsheets, one-liners, blogs, hacks, and CLI/web tools for system and network administrator… | 32 | 240530 | active |
| Hack-with-Github/Awesome-Hacking A curated meta-collection of awesome lists for hackers, pentesters, and security researchers. It aggregates links to specialized repositori… | 75 | 119102 | active |
| swisskyrepo/PayloadsAllTheThings A curated collection of payloads, bypasses, and exploitation techniques for web application security testing. It serves as a reference chea… | 66 | 80407 | active |
| danielmiessler/SecLists SecLists is a curated collection of security testing lists including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads,… | 83 | 73106 | active |
| bannedbook/fanqiang A large Chinese-language repository collecting censorship circumvention (fanqiang) tools, one-click proxy packages, and step-by-step tutori… | 67 | 50901 | active |
| elder-plinius/CL4R1T4S A curated collection of extracted and leaked system prompts, guidelines, and tool definitions from major AI systems such as ChatGPT, Claude… | 64 | 47163 | active |
| OWASP/CheatSheetSeries The OWASP Cheat Sheet Series is a curated collection of concise, high-value reference documents covering application security best practice… | 77 | 32996 | active |
| StevenBlack/hosts A hosts file aggregator that consolidates and merges several well-curated hosts files into unified, deduplicated hosts files for DNS-level … | 95 | 30954 | active |
| imthenachoman/How-To-Secure-A-Linux-Server An evolving, community-maintained how-to guide for securing a Linux server, covering SSH hardening, firewalls, intrusion detection, auditin… | 74 | 30315 | active |
| Johnshall/Shadowrocket-ADBlock-Rules-Forever A collection of regularly regenerated Shadowrocket (iOS proxy app) rule files that define which domains go through a proxy versus direct co… | 67 | 29418 | active |
| The-Art-of-Hacking/h4cker A large curated collection of cybersecurity resources covering ethical hacking, penetration testing, DFIR, AI security, exploit development… | 76 | 29141 | active |
| jivoi/awesome-osint A curated awesome-list of open-source intelligence (OSINT) tools and resources covering search engines, social media investigation, people/… | 88 | 28349 | active |
| Loyalsoldier/clash-rules A continuously auto-built collection of rule-sets (RULE-SET) for the Clash Premium proxy core, aggregating domain and IP lists from sources… | 95 | 28173 | active |
| hagezi/dns-blocklists A collection of curated DNS blocklists for blocking ads, trackers, malware, phishing, scams, and other unwanted domains. Lists are provided… | 88 | 25714 | active |
| gfwlist/gfwlist GFWList is the canonical community-maintained blocklist of censored domains used by proxy tools to bypass the Great Firewall of China. It i… | 77 | 25554 | active |
| djsime1/awesome-flipperzero A curated awesome-list of resources for the Flipper Zero multi-tool device, covering databases/dumps, applications, plugins, firmwares, ani… | 32 | 24176 | active |
| shieldfy/API-Security-Checklist A community-maintained checklist of essential API security countermeasures covering authentication, authorization, input validation, and mo… | 74 | 23306 | active |
| GoogleContainerTools/distroless Distroless is a set of minimal Docker base images published by Google that contain only an application's runtime dependencies, with no pack… | 77 | 23037 | active |
| drduh/macOS-Security-and-Privacy-Guide A community-maintained guide collecting techniques for hardening and improving the privacy of macOS on Apple silicon Macs. It covers threat… | 77 | 22492 | active |
| lissy93/personal-security-checklist A curated checklist of 300+ actionable tips for protecting digital security and privacy, published as a website at digital-defense.io. It s… | 63 | 22192 | active |
| elder-plinius/L1B3RT4S A public collection of jailbreak prompts and adversarial attack techniques targeting flagship LLMs, maintained by researcher elder-plinius.… | 55 | 21185 | active |
| vulhub/vulhub Vulhub is an open-source collection of pre-built vulnerable Docker environments, each launched with a single docker compose command and doc… | 74 | 21167 | active |
| Loyalsoldier/v2ray-rules-dat Enhanced replacement data files (geoip.dat and geosite.dat) for V2Ray-compatible proxy clients, built daily via GitHub Actions from sources… | 95 | 20556 | active |
| pluja/awesome-privacy A curated awesome-list of privacy-respecting, mostly open-source services and apps as alternatives to mainstream proprietary products. It c… | 74 | 19605 | active |
| vxunderground/MalwareSourceCode A large curated collection of malware source code spanning many platforms (Windows, Linux, Android, macOS, MS-DOS, PHP, Java, and more) and… | 70 | 18675 | active |
| farhanashrafdev/90DaysOfCyberSecurity A curated 90-day self-paced cybersecurity study plan organized into daily tasks with links to tutorials, reading materials, and hands-on ex… | 63 | 18659 | active |
| sbilly/awesome-security A curated, community-driven awesome list of security software, libraries, books, documents, and resources. It organizes tools across catego… | 60 | 14797 | active |
| analysis-tools.dev A curated, community-maintained list of static analysis (SAST) tools, linters, and formatters for virtually all programming languages, conf… | 71 | 14751 | active |
| Hacker0x01/hacker101 Hacker101 is a free online web and mobile security class from HackerOne, offering video lessons and capture-the-flag exercises. This reposi… | 36 | 14512 | active |
| trimstray/nginx-admins-handbook A comprehensive community handbook of notes, cheatsheets, and best practices for administering NGINX, covering performance tuning, security… | 32 | 14305 | stable |
| DiningFactory/panda-vpn-pro A curated, actively maintained Chinese-language guide recommending paid VPN 'airport' (proxy subscription) services for circumventing the G… | 74 | 14194 | active |
| mytechnotalent/Reverse-Engineering A free, comprehensive reverse engineering tutorial covering x86, x64, ARM, AVR, and RISC-V architectures, with an accompanying e-book and P… | 77 | 14171 | active |
| qazbnm456/awesome-web-security A curated list of web security materials and resources covering vulnerabilities like XSS, SQL injection, SSRF, CSRF, and more. It also ship… | 76 | 13732 | active |
| GTFOBins/GTFOBins.github.io GTFOBins is a curated, community-maintained dataset and reference website of Unix-like executables that can be abused to bypass local secur… | 70 | 13590 | active |
| phanan/htaccess A curated awesome-list collection of useful Apache .htaccess snippets covering redirects, security, caching, and more. It is reference docu… | 64 | 13181 | active |
| OWASP/mastg The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and rever… | 95 | 13137 | active |
| projectdiscovery/nuclei-templates A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misco… | 99 | 12849 | active |
| arkenfox/user.js A comprehensive, curated user.js template that overrides hundreds of Firefox preferences to maximize privacy and security while reducing tr… | 84 | 12811 | stable |
| brannondorsey/wifi-cracking A tutorial repository teaching how to crack WPA/WPA2 Wi-Fi passwords using Airodump-ng, Aircrack-ng, and Hashcat. It walks through monitor … | 23 | 12594 | stable |
| drduh/YubiKey-Guide A community-maintained guide for storing GnuPG and SSH credentials on YubiKey hardware tokens, covering key creation, subkey transfer, agen… | 77 | 12453 | stable |
| nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters A curated list of resources for people getting started in bug bounty hunting and web security. It links to tools, labs, books, talks, and v… | 32 | 12201 | active |
| HackTricks-wiki/hacktricks HackTricks is a community-maintained wiki/book of hacking tricks, techniques, and notes gathered from CTFs, real-world pentests, and resear… | 82 | 12174 | active |
| apsdehal/awesome-ctf A curated list of Capture The Flag (CTF) frameworks, libraries, tools, platforms, and tutorials. It aggregates resources for both creating … | 32 | 11798 | active |
| h5bp/server-configs-nginx A collection of Nginx configuration files and snippets from the HTML5 Boilerplate project that improve website performance and security. It… | 62 | 11560 | active |
| Linkerd Linkerd is an ultralight, security-first service mesh for Kubernetes that adds mutual TLS, observability, and reliability features to clust… | 95 | 11480 | active |
| Hackl0us/SS-Rule-Snippet A curated collection of proxy rule snippets and ready-made configuration files for tools like Surge, Quantumult X, Shadowrocket, Surfboard,… | 32 | 11253 | active |
| knownsec/404StarLink 404StarLink is a curated showcase program by Knownsec 404 Lab that collects, tracks, and promotes high-quality open-source security project… | 75 | 11131 | active |
| edoardottt/awesome-hacker-search-engines A curated awesome-list of search engines useful for penetration testing, vulnerability assessment, red/blue team operations, and bug bounty… | 76 | 11089 | active |
| SigmaHQ/sigma The main SigmaHQ repository containing over 3000 community-maintained Sigma detection rules written in a generic YAML format for describing… | 92 | 10943 | active |
| LouisShark/chatgpt_system_prompt A curated collection of system prompts extracted from ChatGPT, other AI products, and custom GPTs, along with knowledge about prompt inject… | 71 | 10745 | active |
| privacy-protection-tools/anti-AD anti-AD is a curated, regularly updated ad-blocking and privacy-protection domain filter list targeting the highest hit rate for the Chines… | 67 | 10696 | active |
| infosecn1nja/Red-Teaming-Toolkit A curated list of cutting-edge open-source security tools for red teamers and threat hunters, organized by attack lifecycle stages such as … | 69 | 10654 | active |
| hslatman/awesome-threat-intelligence A curated list of threat intelligence resources including feeds, formats, frameworks, tools, and research. It serves as a reference directo… | 70 | 10578 | active |
| paralax/awesome-honeypots A curated awesome list of honeypot tools, resources, and related components for network and security deception, organized into categories l… | 70 | 10534 | active |
| wtwang1998/LiTiaotiao-Custom-Rules A collection of custom ad-blocking rules for the Li Tiaotiao (李跳跳) Android app, which skips splash-screen ads and in-app advertisements. Th… | 10 | 10241 | active |
| timschneeb/awesome-shizuku A curated awesome-list of Android apps and development libraries that leverage Shizuku, a framework letting normal apps use system APIs wit… | 77 | 9919 | active |
| lissy93/awesome-privacy A curated, community-maintained directory of privacy- and security-respecting software and services, organized into categories like encrypt… | 77 | 9797 | active |
| OWASP/wstg The OWASP Web Security Testing Guide (WSTG) is a comprehensive, community-maintained guide to testing the security of web applications and … | 67 | 9755 | active |
| juliocesarfort/public-pentesting-reports A curated collection of publicly available penetration test reports published by consulting firms and academic security groups. It serves a… | 71 | 9693 | active |
| bottlerocket-os/bottlerocket Bottlerocket is a free, open-source Linux-based operating system purpose-built for hosting containers on worker nodes in orchestrated clust… | 98 | 9664 | active |
| A-poc/RedTeam-Tools A curated collection of 150+ tools, techniques, and tips for red teaming and penetration testing, organized by category with links to exter… | 67 | 9664 | active |
| ashishb/android-security-awesome A curated awesome-list of Android security-related resources, including tools, academic publications, and exploit/vulnerability references.… | 76 | 9646 | active |
| ctf-wiki/ctf-wiki CTF Wiki is a community-maintained, open documentation site that systematically teaches Capture The Flag (CTF) cybersecurity competition sk… | 77 | 9594 | active |
| toniblyx/my-arsenal-of-aws-security-tools A curated list of open-source security tools for AWS, organized into defensive, offensive, purple teaming, continuous auditing, DFIR, and d… | 73 | 9502 | active |
| zardus/ctf-tools A Nix flake that packages a large collection of security research and CTF (capture-the-flag) tools for easy deployment. It bundles tools li… | 86 | 9501 | active |
| meirwah/awesome-incident-response A curated awesome-list of tools and resources for security incident response and digital forensics (DFIR). It organizes links across catego… | 74 | 9353 | active |
| jivoi/awesome-ml-for-cybersecurity A curated awesome-list of tools, datasets, papers, books, talks, tutorials, and courses related to applying machine learning to cybersecuri… | 32 | 9325 | active |
| WebGoat/WebGoat OWASP WebGoat is a deliberately insecure web application designed to teach web application security lessons through hands-on exercises. It … | 79 | 9293 | active |
| Ignitetechnologies/Mindmap A collection of cybersecurity mind maps covering technologies, tools, methodologies, courses, and certifications, organized as visual tree … | 73 | 9224 | active |
| We5ter/Scanners-Box A curated awesome-list of 9,000+ open-source cybersecurity tools covering subdomain enumeration, SQL injection, red team/blue team tooling,… | 76 | 9024 | active |
| kiddin9/Kwrt Kwrt is a customized OpenWrt soft-router firmware distribution supporting a wide range of devices (x86-64, NanoPi, Raspberry Pi, Xiaomi/Red… | 77 | 8977 | active |
| mandiant/flare-vm FLARE-VM is a collection of PowerShell installation scripts that set up and maintain a reverse engineering and malware analysis environment… | 63 | 8965 | active |
| shellphish/how2heap An educational repository demonstrating a wide range of glibc heap exploitation techniques with annotated C examples. Each technique is ver… | 69 | 8796 | active |
| LOLBAS-Project/LOLBAS A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques… | 77 | 8771 | active |
| igareck/vpn-configs-for-russia A curated, auto-updated collection of free VPN configurations (VLESS, Trojan, Shadowsocks, Hysteria2, VMess, Tuic) tested to work in Russia… | 61 | 8287 | active |
| Orange-Cyberdefense/GOAD GOAD (Game Of Active Directory) is a pentest lab project that provisions intentionally vulnerable Active Directory environments using Vagra… | 64 | 8240 | active |
| linkedin/school-of-sre School of SRE is LinkedIn's open-source curriculum for training entry-level engineers into Site Reliability Engineering roles. It provides … | 59 | 8136 | active |
| trickest/cve An automatically updated repository collecting publicly available proof-of-concept exploits for CVEs, organized by year into markdown files… | 77 | 8026 | active |
| nomi-sec/PoC-in-GitHub An automatically curated dataset and web service that collects proof-of-concept (PoC) exploit repositories from GitHub as CVEs are publishe… | 77 | 8012 | active |
| guchangan1/All-Defense-Tool A curated, weekly auto-updated collection of open-source offensive and defensive security tools, covering information gathering, vulnerabil… | 77 | 7949 | active |
| jakejarvis/awesome-shodan-queries A curated awesome-list of interesting, funny, and alarming search queries (dorks) for Shodan, the internet-connected device search engine. … | 32 | 7674 | active |
| 0xInfection/Awesome-WAF A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, d… | 77 | 7592 | active |
| YoulianBoshi/vpn A curated list of links to cracked or 'free-ride' VPN clients, trial-reset tools, and shared VPN accounts, distributed via a Telegram chann… | 77 | 7486 | active |
| Mr-xn/Penetration_Testing_POC A curated collection of penetration testing resources including POCs, exploits, scripts, privilege escalation tools, and write-ups for web … | 77 | 7471 | active |
| 217heidai/adblockfilters A periodically updated (every 8 hours) merged ad-blocking filter rule set generated from multiple upstream sources, deduplicated and valida… | 85 | 7465 | active |
| Hackl0us/GeoIP2-CN A compact (~100 KB) GeoIP2 database containing only mainland China IP address ranges, built by merging ipip.net and CZ (纯真) data and update… | 77 | 7409 | active |
| infoslack/awesome-web-hacking A curated awesome-list of resources for learning web application security, including books, documentation, tools, cheat sheets, courses, la… | 76 | 7246 | active |
| fastfire/deepdarkCTI A curated collection of Cyber Threat Intelligence sources from the Deep and Dark Web, organized for CTI practitioners. It catalogs forums, … | 77 | 7195 | active |
| KathanP19/HowToHunt HowToHunt is a community-curated collection of practical guides, methodologies, and test cases for hunting web vulnerabilities, aimed at bu… | 45 | 7189 | active |
| hwanz/SSR-V2ray-Trojan-vpn A regularly updated curated list (awesome-list style repository) of free and trial VPN services, 'airport' (proxy subscription) providers, … | 77 | 7091 | active |
| sobolevn/awesome-cryptography A curated list of cryptography resources and links, covering theory, algorithms, tools, and libraries across many programming languages. It… | 74 | 7090 | active |
| paragonie/awesome-appsec A curated list of resources for learning about application security, including books, websites, blog posts, and self-assessment quizzes. It… | 36 | 7040 | active |
| I-Am-Jakoby/Flipper-Zero-BadUSB A collection of BadUSB payloads for the Flipper Zero device, formatted to be largely plug-and-play. Payloads are written mostly in PowerShe… | 32 | 7034 | active |
| limbopro/Paolujichang A community-maintained, continuously updated list (2020-2026) of proxy subscription providers ('airports') that have shut down, disappeared… | 76 | 6861 | active |
| sottlmarek/DevSecOps A curated awesome-list style library of open-source DevSecOps tools and methodologies covering cloud and SDLC security. It organizes tools … | 76 | 6855 | active |
| slowmist/Blockchain-dark-forest-selfguard-handbook A multilingual handbook by SlowMist teaching cryptocurrency users how to protect themselves in the 'blockchain dark forest', covering walle… | 53 | 6843 | active |
| microsoft/Security-101 An 8-lesson open curriculum from Microsoft that teaches cybersecurity fundamentals to beginners, covering topics like the CIA triad, identi… | 70 | 6834 | active |
| githubvpn007/v2rayNvpn A curated Chinese-language guide and resource list for circumventing internet censorship, covering VPN vs proxy concepts, client tools (V2R… | 67 | 6822 | active |
| SunWeb3Sec/DeFiHackLabs A curated collection of 859+ DeFi hack incidents reproduced as Foundry proof-of-concept tests in Solidity, for studying how real exploits w… | 77 | 6759 | active |
| ihebski/DefaultCreds-cheat-sheet A searchable dataset and CLI tool aggregating default usernames and passwords for thousands of products and vendors, sourced from projects … | 64 | 6725 | active |
page 1 / 12 next →