resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| FULLSHADE/WindowsExploitationResources A curated collection of links, books, papers, talks, and videos focused on Windows internals, kernel exploitation, and rootkit development.… | 32 | 1660 | maintenance |
| BlackFan/client-side-prototype-pollution A curated collection of JavaScript libraries vulnerable to client-side prototype pollution via document.location parsing, along with useful… | 32 | 1644 | maintenance |
| trimstray/linux-hardening-checklist A curated checklist for hardening GNU/Linux production systems, covering partitioning, bootloader, kernel, logging, users, filesystem, SELi… | 32 | 1642 | maintenance |
| NotSoSecure/password_cracking_rules A consolidated password cracking rules file for hashcat and John the Ripper, aggregating rules from sources like Hob0Rules, KoreLogic, NSAK… | 32 | 1629 | maintenance |
| MTK911/Attiny85 A collection of RubberDucky-style HID payloads for the DigiSpark Attiny85 microcontroller, written in C++ for the Arduino IDE. Payloads inc… | 32 | 1628 | maintenance |
| Wh0ale/SRC-experience A curated Chinese-language collection of links to bug bounty write-ups, cheatsheets, newsletters, and penetration testing resources. It agg… | 32 | 1626 | maintenance |
| ashutosh1206/Crypton An educational library collecting explanations and Python implementations of attacks on encryption systems, digital signatures, MACs, and a… | 10 | 1623 | maintenance |
| wirasecure/pentest-notes A curated collection of penetration testing study notes, cheat sheets, and useful scripts gathered from across the internet. It covers topi… | 32 | 1618 | maintenance |
| api0cradle/LOLBAS A curated knowledge base documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' attack technique… | 10 | 1613 | maintenance |
| cure53/XSSChallengeWiki A community-maintained wiki by Cure53 that catalogs XSS (cross-site scripting) challenges for security learners and researchers. It serves … | 10 | 1591 | maintenance |
| nsacyber/Windows-Secure-Host-Baseline NSA's Windows Secure Host Baseline provides configuration guidance and automation for deploying hardened Windows 10 and Windows Server 2016… | 10 | 1588 | maintenance |
| mubix/post-exploitation A curated collection of post-exploitation command lists, binaries, and scripts for Linux, Windows, macOS, and BSD systems. It aggregates of… | 32 | 1585 | maintenance |
| yeyintminthuhtut/Awesome-Advanced-Windows-Exploitation-References A curated awesome-list of advanced Windows exploitation references, including research papers, talks, and tutorials on browser exploits, mi… | 32 | 1569 | maintenance |
| corkami/pocs A collection of Proof of Concepts demonstrating unusual and edge-case constructs in file formats such as PE executables and PDF documents. … | 32 | 1556 | maintenance |
| wtsxDev/Machine-Learning-for-Cyber-Security A curated awesome-list of tools, datasets, papers, books, tutorials, and courses on applying machine learning to cyber security. It is a re… | 32 | 1534 | maintenance |
| praetorian-inc/Hob0Rules A collection of Hashcat password cracking rule files (hob064 and d3adhob0) built from password statistics and industry patterns, plus bundl… | 10 | 1533 | maintenance |
| lightswitch05/hosts A collection of regularly updated hosts files for blocking ads, trackers, Facebook services, AMP pages, and other unwanted domains. The lis… | 10 | 1527 | maintenance |
| sigp/solidity-security-blog A comprehensive reference documenting known Solidity smart contract attack vectors and common anti-patterns, hosted on GitHub as the basis … | 32 | 1522 | maintenance |
| JonasCz/How-To-Prevent-Scraping A comprehensive written guide on techniques for preventing or hindering website scraping, expanded from a Stack Overflow answer. It explain… | 32 | 1517 | maintenance |
| we1h0/redteam-tips A curated collection of links to red team and penetration testing learning materials, mostly in Chinese, covering domain penetration, intra… | 32 | 1513 | maintenance |
| BaizeSec/bylibrary BaizeSec's public vulnerability knowledge base (Baige Wenku) collecting POCs, EXPs, and security articles maintained by the BaizeSec securi… | 32 | 1503 | maintenance |
| danielmiessler/RobotsDisallowed A curated dataset of robots.txt disallowed directories harvested from the top 100K websites (Alexa/Majestic), useful for content discovery … | 32 | 1490 | maintenance |
| ibaiw/2023Hvv A curated Chinese-language intelligence feed aggregating vulnerability disclosures, POCs, and exploit write-ups collected during China's 20… | 28 | 1485 | maintenance |
| dineshshetty/Android-InsecureBankv2 A deliberately vulnerable Android banking application designed for security enthusiasts and developers to learn Android insecurities by tes… | 23 | 1470 | maintenance |
| MuddledBox/FlipperZeroSub-GHz A collection of Sub-GHz signal files (including deBruijn sequences) for the Flipper Zero multi-tool device. The files are meant to be copie… | 32 | 1459 | maintenance |
| aws/eks-distro Amazon EKS Distro (EKS-D) is a Kubernetes distribution containing the same upstream Kubernetes binaries, etcd, and networking/storage compo… | 94 | 1457 | maintenance |
| kennyn510/wpa2-wordlists A collection of password wordlists and dictionaries compiled from public breach data, intended for dictionary attacks against WPA2 and othe… | 78 | 1441 | maintenance |
| trailofbits/ctf The CTF Field Guide is a free online book by Trail of Bits that teaches how to win Capture The Flag security competitions. It covers vulner… | 32 | 1438 | maintenance |
| UmeLabs/node.umelabs.dev A daily-updated collection of free Shadowsocks (SS), ShadowsocksR (SSR), and V2Ray (vmess) proxy nodes published as subscription links, alo… | 68 | 1436 | maintenance |
| tcc0lin/Review_Reverse A collection of JavaScript reverse engineering case studies and tutorials covering how popular Chinese websites (Taobao, Zhihu, Toutiao, Ba… | 32 | 1429 | maintenance |
| Karanxa/Bug-Bounty-Wordlists A curated collection of wordlists commonly used during bug bounty hunting and web security testing, aggregated from public sources into one… | 23 | 1429 | maintenance |
| hmaverickadams/TCM-Security-Sample-Pentest-Report A sample penetration test report from TCM Security provided as a starter template for writing professional pentest reports. It contains a b… | 32 | 1428 | maintenance |
| pillarjs/understanding-csrf An educational guide by the Express/Pillar.js team explaining what CSRF attacks are and how CSRF tokens work, along with mitigation strateg… | 32 | 1423 | maintenance |
| felixgr/secure-ios-app-dev A curated guide collecting the most common vulnerabilities found in iOS applications, focused on application-level code issues rather than … | 32 | 1419 | maintenance |
| JoasASantos/Guide-CEH-Practical-Master A community study guide repository for the EC-Council Certified Ethical Hacker (Practical) exam, covering exam format, tips, tooling (Nmap,… | 32 | 1409 | maintenance |
| justinsteven/dostackbufferoverflowgood An intentionally vulnerable Win32 program plus a PDF tutorial teaching classic stack buffer overflow exploitation, created for CrikeyCon 20… | 32 | 1401 | maintenance |
| tennc/fuzzdb A curated dictionary collection of attack patterns, payloads, and brute-force wordlists for black-box application fault injection and resou… | 23 | 1399 | maintenance |
| threedr3am/JSP-WebShells A curated collection of JSP webshell samples demonstrating various implementation techniques such as class loading, bytecode manipulation, … | 32 | 1398 | maintenance |
| andrewjkerr/security-cheatsheets A collection of cheatsheets for infosec tools and common UNIX programs, designed to be used with the 'cheat' command-line tool. It helps pe… | 32 | 1395 | maintenance |
| RenwaX23/XSS-Payloads A curated collection of cross-site scripting (XSS) vectors and payloads gathered since 2015 from websites, tweets, and books. It includes a… | 60 | 1391 | maintenance |
| jdonsec/AllThingsSSRF A curated collection of writeups, cheatsheets, videos, and books about Server-Side Request Forgery (SSRF) gathered in one repository. It se… | 32 | 1388 | maintenance |
| guanzhi/GM-Standards A curated collection of texts for China's national cryptographic industry standards (GM/T), covering algorithms like SM2, SM3, SM4, and ZUC… | 32 | 1382 | maintenance |
| OWASP/www-project-top-10-for-large-language-model-applications The OWASP Top 10 for Large Language Model Applications, a community-driven guide to the most critical security risks facing LLM-powered app… | 74 | 1378 | maintenance |
| adon90/pentest_compilation A curated compilation of penetration testing commands, tips, and scripts covering enumeration, exploitation, privilege escalation, tunnelin… | 32 | 1362 | maintenance |
| eliotsykes/rails-security-checklist A community-driven security checklist for Ruby on Rails applications covering controller callbacks, routes, views, and secret token handlin… | 32 | 1362 | maintenance |
| Maktm/FLIRTDB A community-driven database of IDA Pro FLIRT signature files (.sig) used to identify and rename known library functions in symbol-stripped … | 32 | 1361 | maintenance |
| rosehgal/BinExp A consolidated tutorial series on Linux binary exploitation, covering memory layout, buffer overflows, shellcode injection, ret2libc, forma… | 32 | 1357 | maintenance |
| ptresearch/AttackDetection A collection of Suricata IDS rules, PoC exploits, and network traffic samples from Positive Technologies' Attack Detection Team. The rulese… | 10 | 1357 | maintenance |
| bit4woo/python_sec A curated collection of Chinese and English resources on Python security and code auditing, covering dangerous built-in functions, deserial… | 32 | 1352 | maintenance |
| JnuSimba/AndroidSecNotes A collection of learning notes on Android security written mostly in Chinese, covering Java/Android development basics, app security, rever… | 32 | 1350 | maintenance |
| sergey-pronin/Awesome-Vulnerability-Research A curated awesome-list of resources for vulnerability research, including books, articles, courses, tools, write-ups, and methodologies. It… | 32 | 1348 | maintenance |
| nocomp/Flipper_Zero_Badusb_hack5_payloads A collection of Hak5 BadUSB payloads adapted to run on the Flipper Zero device. The payloads are primarily PowerShell-based scripts used fo… | 32 | 1332 | maintenance |
| denji/golang-tls A curated collection of simple, copy-paste Go examples for HTTPS/TLS servers and clients, including OpenSSL commands for generating RSA/ECD… | 32 | 1330 | maintenance |
| tenable/poc A centralized collection of proof-of-concept code for vulnerabilities discovered by Tenable researchers, organized by vendor and product. I… | 32 | 1330 | maintenance |
| aleenzz/MYSQL_SQL_BYPASS_WIKI A community wiki of notes and techniques for bypassing WAFs and filters in MySQL SQL injection attacks. It documents payload tricks, filter… | 32 | 1329 | maintenance |
| vanhoefm/krackattacks The source code for the krackattacks.com website, which documents Mathy Vanhoef's KRACK (Key Reinstallation Attack) research against WPA2 W… | 32 | 1327 | maintenance |
| zxcvbn001/password_brute_dictionary A collection of Chinese-oriented password brute-force dictionaries derived from over 42 million leaked passwords across five platforms. It … | 32 | 1325 | maintenance |
| mikeroyal/Linux-Guide A curated guide (awesome-list style) covering Linux topics including desktop environments, window managers, distributions, hardware vendors… | 32 | 1311 | maintenance |
| Dor1s/libfuzzer-workshop Workshop materials for 'Modern fuzzing of C/C++ Projects', teaching coverage-guided fuzzing with libFuzzer through hands-on examples like f… | 32 | 1307 | maintenance |
| ansjdnakjdnajkd/iOS A curated cheatsheet of tools and resources for iOS and macOS penetration testing, covering static analysis, dynamic instrumentation, jailb… | 32 | 1307 | maintenance |
| WindowsExploits/Exploits A curated archive of compiled and tested public Windows exploits, written primarily in PowerShell. It serves as a reference collection for … | 32 | 1303 | maintenance |
| MichaelKoczwara/Awesome-CobaltStrike-Defence A curated awesome-list of defensive resources, tools, and detection techniques for countering Cobalt Strike, a commercial adversary simulat… | 32 | 1301 | maintenance |
| OTRF/OSSEM OSSEM is a community-led project that documents, standardizes, and models security event logs through data dictionaries, a common data mode… | 32 | 1300 | maintenance |
| RistBS/Awesome-RedTeam-Cheatsheet A curated cheatsheet repository of red team techniques, focused heavily on Active Directory attacks, PowerShell tricks, enumeration, privil… | 32 | 1295 | maintenance |
| DhavalKapil/heap-exploitation A free online book (with PDF/ePUB/Mobi editions) explaining glibc heap internals and heap exploitation attacks. It targets readers unfamili… | 23 | 1293 | maintenance |
| al0ne/suricata-rules A curated collection of high-quality Suricata IDS rules for detecting red-team tooling and malicious network behavior, including CobaltStri… | 32 | 1283 | maintenance |
| mykter/afl-training A hands-on workshop and set of exercises for learning how to fuzz C programs with American Fuzzy Lop (and afl++), including challenges base… | 32 | 1283 | maintenance |
| prism-break/prism-break PRISM Break is a curated directory of free and open-source software recommendations focused on privacy and security, published as a static … | 32 | 1281 | maintenance |
| CHYbeta/Software-Security-Learning A curated collection of links, tutorials, courses, and tools for learning software security, with a strong emphasis on binary security and … | 32 | 1279 | maintenance |
| research-virus/stuxnet A public repository containing decompiled, readable C source code reconstructed from the Stuxnet (MyRTUs) malware binaries, including its d… | 32 | 1279 | maintenance |
| kattgu7/Anti-996-License The Anti-996 License, an open source software license drafted by Katt Gu that prohibits use by companies violating labor laws regarding wor… | 32 | 1278 | maintenance |
| S3cur3Th1sSh1t/OffensiveVBA A curated collection of offensive VBA macro templates for code execution and antivirus evasion in Microsoft Office documents. It aggregates… | 32 | 1276 | maintenance |
| ChALkeR/notes A collection of public security research notes by ChALkeR, stored on GitHub in lieu of a blog. It covers vulnerability writeups on npm, Yar… | 32 | 1275 | maintenance |
| hegdepavankumar/VMware-Workstation-Pro-17-Licence-Keys A curated collection of license keys for VMware Workstation Pro 17 (and Fusion 13), organized by version. It is a list of keys rather than … | 28 | 1274 | maintenance |
| Jack-Liang/kalitools A community-driven translation project (KTTV) that localizes the Kali Linux tools documentation from tools.kali.org into Chinese. It is a c… | 32 | 1267 | maintenance |
| tadwhitaker/Security_Engineer_Interview_Questions A curated collection of security engineer interview questions scraped from Glassdoor.com, organized into logical topic groups. It serves as… | 32 | 1263 | maintenance |
| Ignitetechnologies/Vulnhub-CTF-Writeups A curated cheatsheet of links to Vulnhub CTF and boot-to-root lab writeups published on Hacking Articles. It helps CTF players and beginner… | 32 | 1255 | maintenance |
| blackhat-go/bhg Companion code samples for the No Starch Press book 'Black Hat Go: Go Programming for Hackers and Pentesters'. It contains example Go progr… | 32 | 1255 | maintenance |
| chriskaliX/AD-Pentest-Notes A set of Chinese-language study notes on internal network and Active Directory domain penetration testing, covering reconnaissance, SPN sca… | 32 | 1254 | maintenance |
| davinci1012/pinduoduo_backdoor_unpacker A collection of malicious backdoor and exploit samples extracted from the Pinduoduo Android app, along with Java-based unpacker scripts for… | 30 | 1242 | maintenance |
| Naunter/BT_BlockLists A curated blocklist dataset for the Transmission BitTorrent client, distributed as a gzipped dat file that blocks known bad peers. It is up… | 68 | 1228 | maintenance |
| Kyuu-Ji/Awesome-Azure-Pentest A curated awesome-list of tools, articles, labs, talks, and books for penetration testing and securing Microsoft Azure and Microsoft 365 en… | 32 | 1220 | maintenance |
| Stardustsky/SaiDict A curated collection of attack dictionaries for penetration testing, including weak passwords, common usernames, sensitive directory and fi… | 32 | 1219 | maintenance |
| struct/mms A collection of slides from a Black Hat training course on memory safety in C/C++, covering vulnerability discovery, exploitation, custom m… | 32 | 1219 | maintenance |
| veorq/cryptocoding A curated set of coding rules and best practices for implementing low-level cryptographic software, originally from the cryptocoding.net 'C… | 32 | 1218 | maintenance |
| shmilylty/awesome-hacking A curated awesome-list (Chinese version of awesome-hacking) collecting tutorials, tools, Docker images, and resources for hacking, penetrat… | 32 | 1205 | maintenance |
| liuyi01/kubernetes-starter A Chinese-language tutorial repository accompanying a MOOC course on Kubernetes, covering concepts, architecture, cluster setup, and authen… | 32 | 1203 | maintenance |
| saisathvik1/OSCP-Cheatsheet A community-maintained OSCP exam preparation cheatsheet covering penetration testing commands, privilege escalation paths, and important fi… | 27 | 1203 | maintenance |
| Ershu1/2021_Hvv A community-curated repository of resources related to China's HVV (HW, 'HuWang') offensive/defensive security exercise, collecting tools, … | 32 | 1200 | maintenance |
| SkyBlueEternal/thinkphp-RCE-POC-Collection A curated collection of proof-of-concept payloads for ThinkPHP 5.x remote code execution and SQL injection vulnerabilities. It documents ex… | 32 | 1193 | maintenance |
| mvelazc0/defcon27_csharp_workshop A Defcon 27 workshop repository with 8 hands-on labs teaching how to write custom backdoor payloads in C# targeting C2 frameworks like Meta… | 32 | 1190 | maintenance |
| RamadhanAmizudin/malware A collection of leaked malware source code samples (banking trojans, botnets, ransomware, RATs, exploit kits) uploaded to GitHub for resear… | 39 | 1188 | maintenance |
| vasanthk/web-security-basics A curated reference document reviewing fundamental web security concepts such as SSL/TLS, CORS, XSS, CSRF, and access/refresh tokens. It is… | 32 | 1187 | maintenance |
| THUYimingLi/backdoor-learning-resources A curated list of academic papers, toolboxes, and theses on backdoor learning (neural Trojan) attacks and defenses in machine learning, mai… | 32 | 1182 | maintenance |
| tutugreen/Huorong-Rules A community-maintained collection of custom rules for the Huorong (火绒) security software for Windows, contributed via pull requests. It inc… | 32 | 1181 | maintenance |
| XLsn0w/Cydiapps A collection of iOS jailbreak tweak development resources and Cydia repos by XLsn0w, focused on reverse engineering iOS apps using Logos, T… | 32 | 1179 | maintenance |
| lexburner/oauth2-demo A Java demo project and tutorial explaining how to implement OAuth2 with Spring Security OAuth2, including authorization code flow examples… | 32 | 1177 | maintenance |
| Tib3rius/Pentest-Cheatsheets A collection of penetration testing cheatsheets compiled into a Sphinx-based HTML documentation site. It serves as a quick reference guide … | 32 | 1176 | maintenance |
| ctf-wiki/ctf-tools A curated collection of tools, scripts, and security conference materials for CTF (Capture The Flag) competitions, organized by category (c… | 32 | 1176 | maintenance |
| elastic/ember EMBER is a benchmark dataset of features extracted from over 2 million PE (Portable Executable) files for training and evaluating malware c… | 10 | 1169 | maintenance |