Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
malrev/ABD
Course materials for Advanced Binary Deobfuscation taught by NTT Secure Platform Laboratories at GCC Tokyo 2020. It covers obfuscation prin…
321167maintenance
xtiankisutsa/awesome-mobile-CTF
A curated awesome-list of mobile-focused CTF challenges, write-ups, and intentionally vulnerable apps, mostly Android with some iOS coverag…
321164maintenance
nixawk/labs
A collection of vulnerability labs and proof-of-concept exploits for known CVEs, written primarily in Python. It serves as a security analy…
321162maintenance
RestCheatSheet/api-cheat-sheet
A community-maintained cheat sheet of REST API design guidelines and best practices, covering URL structure, HTTP methods, status codes, pa…
321161maintenance
masatokinugawa/filterbypass
A wiki-based cheat sheet cataloging techniques for bypassing browser XSS (cross-site scripting) filters. It serves as a reference for secur…
321159maintenance
CTFTraining/CTFTraining
A curated collection of Dockerized reproductions of classic CTF (Capture The Flag) competition challenges. Each challenge lives in its own …
321150maintenance
Dm2333/ATTCK-PenTester-Book
A ~400-page penetration testing handbook compiled by the DeadEye security team based on the MITRE ATT&CK knowledge base. It is organized by…
321150maintenance
TCM-Course-Resources/Open-Source-Intellingence-Resources
A curated compilation of links and tools from TCM Security's OSINT Fundamentals course, organized by category such as search engines, image…
321148maintenance
J0o1ey/BountyHunterInChina
A curated collection of Chinese-language bug bounty and penetration testing writeups documenting real-world vulnerability hunting cases (XS…
661145maintenance
pgaijin66/XSS-Payloads
A curated collection of advanced cross-site scripting (XSS) payloads intended for use in penetration testing. The payload lists can be load…
231141maintenance
payatu/diva-android
DIVA Android is an intentionally insecure Android application designed to teach developers, QA engineers, and security professionals about …
321140maintenance
S1ckB0y1337/Cobalt-Strike-CheatSheet
A community-maintained cheat sheet of notes, command examples, and OPSEC advice for the Cobalt Strike command-and-control framework. It cov…
321137maintenance
wallarm/jwt-secrets
A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used fo…
371136maintenance
JoasASantos/Cloud-Security-Attacks
A curated collection of links to cloud security attack writeups covering AWS, Azure, and GCP, including privilege escalation, RCE, and misc…
321133maintenance
ryh04x/CEH-Exam-Questions
A GitHub repository containing 125 practice questions and answers for the Certified Ethical Hacker (CEH) certification exam, organized by c…
301131maintenance
mozilla/server-side-tls
Mozilla's Server Side TLS repository, which historically hosted the wiki source for Mozilla's TLS configuration guidelines and the SSL/TLS …
101129maintenance
3gstudent/Pentest-and-Development-Tips
A curated collection of penetration testing and development tips, primarily focused on Windows post-exploitation techniques like port probi…
321126maintenance
Mochazz/ThinkPHP-Vuln
A curated collection of detailed vulnerability analyses for the ThinkPHP PHP framework, covering SQL injection, arbitrary file write, deser…
321123maintenance
cisagov/log4j-affected-db
A CISA-maintained, community-sourced list of software affected by the Log4j vulnerability (CVE-2021-44228, Log4Shell), along with official …
101123maintenance
jhaddix/pentest-bookmarks
A curated collection of penetration testing bookmarks assembled by Jason Haddix, organized into categories like OSINT sites, blogs, and for…
321120maintenance
mitre/advmlthreatmatrix
MITRE's Adversarial Threat Landscape for AI Systems (ATLAS), an ATT&CK-style knowledge base of adversarial machine learning attacks, case s…
321110maintenance
DawnFlame/POChouse
A curated collection of proof-of-concept (POC) and exploit (EXP) scripts for known N-day and 1-day vulnerabilities, oriented toward HVV red…
321108maintenance
ForbiddenProgrammer/conti-pentester-guide-leak
An archive of leaked technical training manuals originally distributed to affiliates of the Conti ransomware gang, covering attack techniqu…
321104maintenance
oskarsve/ms-teams-rce
A security research writeup documenting zero-click, wormable remote code execution vulnerabilities in Microsoft Teams, reported to MSRC in …
321104maintenance
HarmJ0y/CheatSheets
A collection of cheat sheets for offensive security tools maintained by HarmJ0y, including PowerView, PowerUp, Empire, PowerSploit, and Cob…
321102maintenance
lmy375/awesome-vmp
A curated collection of resources for analyzing virtualization-based software protection such as VMProtect. It catalogs analysis tools (mos…
101102maintenance
kaonashi-passwords/Kaonashi
Kaonashi is a collection of password wordlists, hashcat rules, and masks derived from large-scale analysis of billions of real leaked passw…
321099maintenance
Airboi/bypass-av-note
A Chinese-language knowledge base of antivirus evasion (bypass AV) techniques, covering signature-based, behavior-based, and cloud detectio…
321093maintenance
trigram-mrp/fractureiser
A documentation repository compiling information about the fractureiser malware, a virus found in Minecraft mods on CurseForge and BukkitDe…
291085maintenance
jiji262/wooyun_articles
A backup archive of the Wooyun Drops security articles (drops.wooyun.org), a well-known Chinese security knowledge base covering vulnerabil…
321082maintenance
edoardogerosa/sentinel-attack
A toolkit for rapidly deploying a threat hunting capability on Azure Sentinel using Sysmon telemetry mapped to the MITRE ATT&CK framework. …
231077maintenance
ankane/secure_rails
A curated guide of security best practices for Ruby on Rails applications, covering secrets management, SQL injection, host header injectio…
471066maintenance
EvilAnne/lzCloudSecurity
An open-source Chinese-language textbook, 'Cloud Security Attack and Defense Introduction' (《云安全攻防入门》), published via GitBook. It compiles …
271057maintenance
k8gege/PasswordDic
A collection of password dictionaries (wordlists) including top weak passwords from 2011-2019, SSH/VPS server passwords, admin panel passwo…
321053maintenance
h4x0r-dz/Leaked-Credentials
A tutorial repository teaching how to find leaked credentials (API keys, tokens, passwords) in web traffic using regex patterns with Chrome…
251051maintenance
EONRaider/violent-python3
A Python 3 conversion of the source code from the book 'Violent Python' by TJ O'Connor, refactored for PEP8 compliance and updated to remov…
761050maintenance
christophercalm/if-im-gone
A Markdown template cheat sheet for organizing personal affairs, accounts, and important documents so others can access them if you become …
321048maintenance
xapax/security
A collection of personal notes on IT security topics, hosted on GitHub Pages after being removed from Gitbook. It serves as a free referenc…
321043maintenance
alphaSeclab/awesome-burp-suite
A curated awesome-list of Burp Suite resources, cataloging 400+ open-source Burp plugins along with 400+ posts and videos. Content is organ…
321039maintenance
frostbits-security/MITM-cheatsheet
A curated cheat sheet compiling known Man-In-The-Middle attacks across network layers (L2, L3, L4+, wireless), along with protection method…
321039maintenance
LoseNine/Crack-JS-Spider
A curated collection of JavaScript reverse-engineering solutions for bypassing anti-scraping encryption parameters on popular Chinese websi…
321034maintenance
guardrailsio/awesome-php-security
A curated awesome-list of PHP security resources, including tools for static analysis, framework hardening, vulnerability advisories, and e…
321034maintenance
shadawck/awesome-anti-forensic
A curated awesome-list of tools and packages used for countering forensic activities, covering encryption, steganography, disk imaging, mem…
321034maintenance
3had0w/Fuzzing-Dicts
A curated collection of dictionaries and wordlists for web security testing, including payloads for fuzzing, directory brute-forcing, and v…
321028maintenance
KevinColemanInc/awesome-privacy
A curated awesome-list of tools, services, and guides for limiting personal data leaks on the internet. It covers categories like VPNs, Tor…
321028maintenance
I-am-R-E/Functional-Store-Hub
A curated collection of functional scripts, proxy agent nodes, and configuration files for iOS proxy tools such as Surge, QuantumultX, Loon…
321021maintenance
nnamon/linux-exploitation-course
A free, open course on intermediate-level Linux binary exploitation, covering techniques like ROP, ret2libc, ASLR bypass, GOT overwrite, an…
321015maintenance
ohmybahgosh/RockYou2021.txt
RockYou2021.txt is a massive compiled password wordlist of roughly 82 billion unique entries (6-20 ASCII characters), aggregated from multi…
321012maintenance
sundaysec/Android-Exploits
A curated collection of Android exploits, hacking tools, and guides organized by exploit type (DoS, local, remote, webapp), with references…
321012maintenance
hackerscrolls/SecurityTips
A curated collection of HackerScrolls security tips presented as images and mindmaps, covering Burp Suite usage, testing for 2FA/OAuth/SSRF…
321009maintenance
R3dy/capsulecorp-pentest
A Vagrant and Ansible managed virtual network of five VirtualBox VMs: an Xubuntu attacker machine with common pentest tools and four Window…
321006maintenance
correlatedsecurity/Awesome-SOAR
A curated awesome list of Security Orchestration, Automation and Response (SOAR) resources, including standards, playbooks, workflows, trai…
321002maintenance
sagishahar-zz/lpeworkshop
A free workshop covering local privilege escalation attack vectors on Windows and Linux, including slides, lab VMs, exercise walkthroughs, …
321001maintenance
osnr/horrifying-pdf-experiments
A collection of experiments demonstrating that PDF files can contain JavaScript and interactive behavior, most famously a playable Breakout…
321660experimental
tc39/proposal-shadowrealm
A TC39 ECMAScript language proposal (currently at Stage 2.7) for the ShadowRealm API, which provides distinct global environments with thei…
351583experimental
h2y/Shadowrocket-ADBlock-Rules
A collection of auto-generated proxy rule files for the Shadowrocket iOS app, defining which sites go through a proxy versus direct connect…
1016696abandoned
sundowndev/hacker-roadmap
A curated roadmap and collection of hacking tools, resources, and references for learning ethical hacking and penetration testing. It organ…
1015567abandoned
yeyintminthuhtut/Awesome-Red-Teaming
A curated awesome-list of red teaming resources organized by MITRE ATT&CK tactics such as initial access, persistence, privilege escalation…
328071abandoned
nirholas/fresh-start
A placeholder repository formerly known as nirholas/claude-code, which was a widely forked mirror of the Claude Code source leak before bei…
596246abandoned
clown-coding/vpn
A Chinese-language tutorial repository explaining how to rent a BandwagonHost VPS and set up a personal Shadowsocks VPN for circumventing i…
325796abandoned
dan1471/FREE-openai-api-keys
A repository claiming to provide a list of free OpenAI API keys for use in projects. The keys are clearly fabricated placeholder strings, s…
235434abandoned
clong/DetectionLab
DetectionLab is an automation project that builds a Windows domain lab environment pre-loaded with security tooling and logging best practi…
325010abandoned
ChenYilong/iOS9AdaptationTips
A Chinese-language tutorial series with demo code explaining how to adapt iOS apps to iOS 9 changes, most notably App Transport Security (A…
324443abandoned
iosre/iOSAppReverseEngineering
An open-source book (MIT licensed) teaching detailed iOS app reverse engineering skills, covering concepts, tools like class-dump, Theos, C…
324416abandoned
coreb1t/awesome-pentest-cheat-sheets
A curated awesome-list collection of cheat sheets useful for penetration testing, covering discovery, enumeration, exploitation, and genera…
104364abandoned
x0rz/EQGRP
A browsable, decrypted dump of the ShadowBrokers' eqgrp-auction-file.tar.xz archive containing alleged NSA Equation Group hacking tools, ex…
324202abandoned
PeiQi0/PeiQi-WIKI-Book
PeiQi文库 is a Chinese-language cybersecurity knowledge base covering vulnerability research, code auditing, CTF, and red/blue team operation…
324120abandoned
privacytools/privacytools.io
The archived source code of PrivacyTools, a community website recommending privacy-respecting tools, services, and encryption practices aga…
103145abandoned
openservicemesh/osm
Open Service Mesh (OSM) is a lightweight, extensible cloud native service mesh for Kubernetes that injects Envoy proxy sidecars next to app…
102551abandoned
Urinx/iOSAppHook
A Chinese-language tutorial and demo project on iOS app reverse engineering in non-jailbroken environments, covering app decryption checks,…
232487abandoned
notracking/hosts-blocklists
NoTracking is an automatically updated DNS-based blocklist for blocking ads, trackers, malware, phishing, and webminers. It ships optimized…
102303abandoned
pilcrowonpaper/copenhagen
The Copenhagen Book is a free, open-source guideline on implementing authentication in web applications, maintained as a documentation site…
102119abandoned
microsoft/Microsoft-365-Defender-Hunting-Queries
A collection of sample Kusto Query Language (KQL) hunting queries for Microsoft 365 Defender's Advanced Hunting feature, contributed by Mic…
102087abandoned
x0rz/EQGRP_Lost_in_Translation
A mirror of the decrypted Shadow Brokers leak containing Equation Group (NSA) Windows exploits, implants, payloads, banking attack operatio…
321999abandoned
abatchy17/WindowsExploits
A collection of mostly precompiled Windows exploits, largely forked from another privilege-escalation repository. It is no longer being upd…
321934abandoned
pirate/sites-using-cloudflare
An archived dataset listing domains that used Cloudflare DNS at the time of the CloudBleed HTTPS traffic leak announcement in February 2017…
101925abandoned
ffffffff0x/Dork-Admin
A curated list documenting data breach and supply chain pollution incidents across countries and industries from 2016 to 2021. It serves as…
101917abandoned
404notf0und/AI-for-Security-Learning
A curated Chinese-language learning resource collecting articles, papers, and industry practices on applying AI and machine learning to sec…
321772abandoned
mandatoryprogrammer/NorthKoreaDNSLeak
A snapshot of North Korea's .kp top-level domain DNS zone data, obtained via an accidental AXFR zone transfer from the ns2.kptc.kp nameserv…
321751abandoned
SpecterOps/at-ps
SpecterOps' free 'Adversary Tactics: PowerShell' course material covering offensive and defensive PowerShell tradecraft. It is no longer ma…
321609abandoned
tintinweb/smart-contract-sanctuary
A large git-based dataset of Etherscan-verified Solidity smart contracts, organized as an index repository with per-chain submodules (Ether…
661593abandoned
comeforu2012/truth
A GitHub repository whose content is a Chinese-language wiki collecting information and resources about internet censorship circumvention a…
321539abandoned
notthebee/infra
An Ansible playbook that provisions an Ubuntu-based home server with security hardening, auto-updates, and email notifications for S.M.A.R.…
101463abandoned
Vancir/365-days-get-xuanwulab-job
A 365-day self-study roadmap and daily notes repository created by a security researcher aiming to land a job at Tencent Xuanwu Lab. It cov…
101439abandoned
MorteNoir1/virtualbox_e1000_0day
A public proof-of-concept exploit for a guest-to-host escape vulnerability (0day) in VirtualBox's E1000 (Intel PRO/1000 MT) network device …
321426abandoned
adolfintel/Windows10-Privacy
A step-by-step guide for disabling telemetry and online data collection in Windows 10, last updated for version 1903. It is documentation r…
101409abandoned
ivolo/disposable-email-domains
A JSON dataset of disposable email domains (like mailinator.com) with exact and wildcard domain lists, published as an npm package. It is n…
281374abandoned
googlearchive/android-FingerprintDialog
An archived Android sample app from Google demonstrating fingerprint authentication using the FingerprintDialog API. It has been migrated t…
101357abandoned
lucyoa/kernel-exploits
A curated collection of Linux kernel privilege escalation exploits written in C, organized by exploit name with lists of vulnerable kernel …
321208abandoned
kpwn/iOSRE
A community-driven collection of tools, resources, and knowledge for iOS reverse engineering and exploitation. It aggregates user-contribut…
321180abandoned
smarthosts/smarthosts
SmartHosts is a community-maintained hosts file that maps blocked or slow foreign websites (e.g., Facebook, Google services) to their offic…
321150abandoned
letsencrypt/acme-spec
The original specification for the ACME (Automatic Certificate Management Environment) protocol used by Let's Encrypt to automate TLS certi…
321128abandoned
vysecurity/RedTips
A curated collection of red team tips originally posted by @vysecurity on Twitter, covering offensive security techniques like lateral move…
101119abandoned
Xyntax/1000php
A curated dataset of 1000 PHP code audit vulnerability cases extracted from publicly disclosed WooYun (乌云) vulnerabilities prior to July 20…
321106abandoned
RhinoSecurityLabs/Security-Research
A collection of security exploits and research code written by the Rhino Security Labs team. The repository is deprecated and no longer mai…
321101abandoned
edgelesssys/constellation
Constellation is a Kubernetes distribution that runs entire clusters inside Confidential VMs (AMD SEV / Intel TDX), encrypting runtime memo…
101096abandoned
zhengmin1989/iOS_ICE_AND_FIRE
A Chinese-language article series ('iOS Ice and Fire Song') covering iOS security research, from userland sandbox escapes to kernel exploit…
321082abandoned
neuroradiology/InsideReCaptcha
A Python-based research project reverse-engineering Google's 'no-captcha' ReCaptcha system, documenting its obfuscated JavaScript bytecode …
321049abandoned
certsocietegenerale/IRM-deprecated
A collection of operational incident response methodology cheat sheets from CERT Societe Generale, covering common security incident handli…
321014abandoned
GeQ1an/Rules
A collection of rule sets for Quantumult X, Loon, and Clash proxy clients, focused on 'back to CN' routing rules that direct Chinese traffi…
321005abandoned

← prev page 11 / 12 next →