resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet A curated cheat sheet of common enumeration and attack techniques for Windows Active Directory environments. It serves as a quick reference… | 70 | 6715 | active |
| MDX-Tom/gpt-5.6-instruct A versioned pack of jailbreak ('armor-breaking') system prompts and regression test sets targeting the gpt-5.6-sol model family in Codex, d… | 77 | 6618 | active |
| xairy/linux-kernel-exploitation A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic… | 76 | 6602 | active |
| fr0gger/Awesome-GPT-Agents A curated, community-driven list of GPT agents focused on cybersecurity, covering both offensive and defensive use cases. It catalogs links… | 27 | 6584 | active |
| ACL4SSR/ACL4SSR A collection of ACL rule lists for ShadowsocksR/SS and Clash, including GFWList-based rules and ad-blocking rules for routing traffic (dire… | 75 | 6579 | active |
| decalage2/awesome-security-hardening A curated awesome-list of security hardening guides, best practices, checklists, benchmarks, and tools covering Linux, Windows, macOS, netw… | 68 | 6526 | active |
| reddelexc/hackerone-reports A curated dataset of top disclosed HackerOne bug bounty reports, ranked by upvotes, bounties, bug type, and program, with raw data in data.… | 76 | 6481 | active |
| Aethersailor/Custom_OpenClash_Rules A community-maintained collection of OpenClash configuration resources for OpenWrt routers, including subscription conversion templates, YA… | 71 | 6403 | active |
| TG-Twilight/AWAvenue-Ads-Rule AWAvenue Ads Rule is a curated, lightweight ad-blocking filter list maintained as an open-source subscription. It blocks ad SDK traffic at … | 91 | 6399 | active |
| streaak/keyhacks KeyHacks is a curated reference repository listing commands and methods to validate leaked API keys found during bug bounty programs or pen… | 75 | 6322 | active |
| CarterPerez-dev/Cybersecurity-Projects A curated repository of 70 hands-on cybersecurity projects ranging from foundations to advanced, with full source code, certification roadm… | 61 | 6235 | active |
| vavkamil/awesome-bugbounty-tools A curated awesome-list of bug bounty and web security tools, organized by recon and exploitation categories. It catalogs tools for subdomai… | 76 | 6199 | active |
| ahmetb/kubernetes-network-policy-recipes A collection of copy-paste-ready YAML recipes and tutorials for Kubernetes Network Policies, covering common traffic restriction scenarios.… | 34 | 6159 | active |
| felixonmars/dnsmasq-china-list A maintained collection of Chinese-domain DNS configuration lists for dnsmasq, unbound, bind, and other DNS servers. It routes Chinese doma… | 77 | 6114 | active |
| OWASP/Top10 The official repository for the OWASP Top 10, a widely referenced document listing the most critical web application security risks. It hos… | 75 | 6018 | active |
| rmusser01/Infosec_Reference A large curated reference of information security tools, techniques, and learning resources covering offensive and defensive security topic… | 53 | 5986 | active |
| uBlockOrigin/uAssets uAssets is the official repository of filter lists and resources for uBlock Origin and uBlock Origin Lite. It serves as the issue tracker f… | 77 | 5971 | active |
| hak5/usbrubberducky-payloads The official community payload repository for the Hak5 USB Rubber Ducky, containing DuckyScript payloads, extensions, and language files fo… | 71 | 5953 | active |
| 0xZ0F/Z0FCourse_ReverseEngineering A free open-source course that teaches reverse engineering of x64 Windows binaries, taking learners from beginner to intermediate level. It… | 65 | 5906 | active |
| secfigo/Awesome-Fuzzing A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I… | 32 | 5904 | active |
| djadmin/awesome-bug-bounty A curated awesome-list of bug bounty and responsible disclosure programs, hunter write-ups, and getting-started resources. It serves as a r… | 64 | 5871 | active |
| matter-labs/awesome-zero-knowledge-proofs A curated awesome-list of resources for learning about zero-knowledge proofs, including courses, articles, videos, and proof system impleme… | 61 | 5806 | active |
| EdOverflow/can-i-take-over-xyz A community-maintained reference list of services vulnerable to subdomain takeover via dangling DNS records, with guidance on how to claim … | 34 | 5788 | active |
| madhuakula/kubernetes-goat Kubernetes Goat is an intentionally vulnerable-by-design Kubernetes cluster environment that serves as an interactive, hands-on playground … | 57 | 5756 | active |
| laylavish/uBlockOrigin-HUGE-AI-Blocklist A manually curated blocklist of 1000+ sites containing AI-generated imagery, distributed as filter lists for uBlock Origin and uBlacklist, … | 46 | 5755 | active |
| onlurking/awesome-infosec A curated awesome-style list of information security learning resources, including MOOCs, academic courses, labs, CTFs, books, and challeng… | 76 | 5726 | active |
| fmz200/wool_scripts A curated collection of configuration files and ad-blocking (去广告) rules for iOS proxy tools including Loon, Surge, QuantumultX, ShadowRocke… | 76 | 5591 | active |
| dsasmblr/game-hacking A curated list of tools, tutorials, books, and presentations for reverse engineering and hacking video games. It aggregates resources like … | 32 | 5567 | active |
| fabacab/awesome-cybersecurity-blueteam A curated awesome-list of free and open-source resources, tools, and references for cybersecurity blue teams focused on defensive security.… | 32 | 5541 | active |
| KingOfBugbounty/KingOfBugBountyTips A curated collection of bug bounty reconnaissance tips and one-liner commands shared by well-known bug hunters, with explanations to help n… | 73 | 5521 | active |
| LyleMi/Learn-Web-Hacking A comprehensive set of study notes on web security covering network protocols, information gathering, common vulnerabilities, intranet pene… | 76 | 5514 | active |
| devsecops/awesome-devsecops A curated awesome-list of free and open-source DevSecOps resources, including tools, guidelines, presentations, training labs, podcasts, an… | 32 | 5461 | active |
| disposable-email-domains/disposable-email-domains A community-maintained list of disposable and temporary email address domains, distributed as a plain-text blocklist and a PyPI package. It… | 77 | 5454 | active |
| 0xeb/TheBigPromptLibrary A curated library of system prompts, custom instructions, jailbreak prompts, and LLM instruction-protection examples from providers like Ch… | 70 | 5328 | active |
| GMOogway/shadowrocket-rules A daily auto-built collection of modular rule sets (DIRECT, PROXY, REJECT) for the Shadowrocket iOS proxy client, distributed as .module fi… | 76 | 5270 | active |
| StreisandEffect/streisand Streisand is an Ansible-based automation tool that provisions a cloud server running multiple censorship-resistant VPN and proxy services s… | 10 | 23462 | maintenance |
| Awesome-POC A curated knowledge base of 1k+ vulnerability Proof-of-Concept (PoC) writeups covering CVEs across CMSs, servers, and network devices. It i… | 68 | 5171 | active |
| cugu/awesome-forensics A curated list of free and open-source digital forensics (DFIR) tools and resources, organized by category such as memory forensics, networ… | 77 | 5166 | active |
| s0md3v/AwesomeXSS A curated awesome-list of cross-site scripting (XSS) resources including payloads, polyglots, cheatsheets, tools, challenges, and papers. I… | 32 | 5138 | active |
| niespodd/browser-fingerprinting An educational guide and analysis repository explaining how bot protection systems (PerimeterX, Akamai, Kasada, Arkose, reCAPTCHA, etc.) de… | 75 | 5125 | active |
| blocklistproject/Lists A collection of curated, community-maintained domain blocklists for network-level content filtering, covering ads, trackers, malware, phish… | 95 | 5054 | active |
| jassics/security-study-plan A curated, role-based study plan repository for becoming a cybersecurity engineer, covering paths like penetration testing, AppSec, cloud s… | 76 | 5048 | active |
| pirate/wireguard-docs An unofficial, comprehensive documentation and API reference for WireGuard, the open-source VPN, covering setup, configuration, usage, and … | 65 | 5044 | active |
| hahwul/WebHackersWeapons A curated awesome-list cataloging tools, bookmarklets, browser addons, and Burp/Caido/ZAP extensions used by web hackers for bug bounty and… | 68 | 5042 | active |
| google/google-ctf A repository of most challenges used in the Google CTF since 2017, along with infrastructure for hosting them. It serves as an archive of s… | 62 | 5012 | active |
| IAmStoxe/wirehole WireHole is a docker-compose project that combines WireGuard, Pi-hole, and Unbound into a single self-hosted VPN stack. It provides a perso… | 77 | 4968 | active |
| infosecn1nja/AD-Attack-Defense A curated knowledge base mapping the Active Directory attack kill chain to detection, mitigation, and prevention guidance. It catalogs atta… | 48 | 4858 | active |
| apple/password-manager-resources A collaborative dataset of website-specific 'quirks' for password managers, maintained by Apple and the community. It includes password rul… | 77 | 4794 | active |
| paulmillr/encrypted-dns A collection of DNS over HTTPS (DoH) and DNS over TLS (DoT) configuration profiles (.mobileconfig) for iOS and macOS, covering providers li… | 75 | 4772 | active |
| FallibleInc/security-guide-for-developers A practical open-source security guide and checklist for web developers covering authentication, authorization, encryption, sessions, heade… | 50 | 21094 | maintenance |
| Lin-arm/GKD_subscription A community-maintained fork of a third-party subscription ruleset for GKD, an Android automation tool that skips in-app ads. It provides JS… | 79 | 4729 | active |
| hiddendevj/Crawler_Illegal_Cases_In_China A curated collection of legal cases, news, and Chinese laws related to web crawler developers facing prosecution or violations in mainland … | 64 | 4717 | active |
| 0x4D31/awesome-threat-detection A curated awesome list of threat detection and threat hunting resources, including tools, detection rules, datasets, research papers, train… | 59 | 4710 | active |
| mantvydasb/RedTeaming-Tactics-and-Techniques ired.team is a publicly accessible collection of personal red teaming and offensive security notes documenting hands-on experiments with at… | 71 | 4679 | active |
| knownsec/KCon KCon is a well-known hacker conference organized by Knownsec Team, and this repository serves as its archive of presentation materials. It … | 32 | 4656 | active |
| forter/security-101-for-saas-startups A curated guide of security tips and best practices for SaaS startups, organized by company growth stage. It explains which security consid… | 61 | 4651 | active |
| OTRF/ThreatHunter-Playbook A community-driven open-source collection of threat hunting playbooks documenting adversary tradecraft, detection logic, and hunt hypothese… | 60 | 4643 | active |
| googlehosts/hosts A community-maintained, automatically generated hosts file that maps Google and related service domains to working IP addresses, helping us… | 32 | 20598 | maintenance |
| joe-shenouda/awesome-cyber-skills A curated list of hacking environments and platforms where users can legally and safely practice cybersecurity skills. It catalogs free tra… | 23 | 4639 | active |
| google/security-research A repository of security advisories and proof-of-concept exploits from Google security research affecting third-party (non-Google) software… | 77 | 4615 | active |
| slowmist/Knowledge-Base A curated knowledge base of blockchain security research published by the SlowMist security team, covering attack techniques like false dep… | 76 | 4592 | active |
| jaredthecoder/awesome-vehicle-security A curated awesome-list of resources for learning about vehicle security and car hacking, including articles, books, courses, podcasts, hard… | 70 | 4530 | active |
| bluscreenofjeff/Red-Team-Infrastructure-Wiki A community-maintained wiki collecting resources for building resilient, hardened Red Team penetration-testing infrastructure. It covers de… | 52 | 4520 | active |
| Orz-3/QuantumultX A beginner-friendly configuration file collection for the QuantumultX iOS proxy client, derived from the Shenji rules with custom policy gr… | 53 | 4510 | active |
| firmianay/CTF-All-In-One An open-source Chinese-language book series, 'CTF Competition Authoritative Guide', covering CTF security competition topics with a publish… | 32 | 4493 | active |
| AdguardTeam/AdguardFilters A repository of AdGuard's content-blocking filter lists — text-based rule sets used by AdGuard apps and other ad blockers like uBlock Origi… | 77 | 4481 | active |
| A-poc/BlueTeam-Tools A curated collection of 70+ tools and resources for blue teaming and incident response, organized as a wiki-style cheatsheet. It covers thr… | 76 | 4456 | active |
| bitnami/containers The Bitnami Containers Library provides hardened, security-optimized Docker container images for hundreds of popular open-source applicatio… | 77 | 4450 | active |
| riramar/Web-Attack-Cheat-Sheet A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and explo… | 76 | 4433 | active |
| morrownr/USB-WiFi A curated documentation repository with reviews, chipset information, and a plug-and-play list of USB WiFi adapters that work well with Lin… | 74 | 4424 | active |
| SukkaW/Surge A curated collection of rule snippets and rule sets for proxy clients including Surge, Mihomo (Clash.Meta), Clash Premium, sing-box, Surfbo… | 77 | 4413 | active |
| skerkour/black-hat-rust The companion repository for the book 'Black Hat Rust', teaching applied offensive security by building real-world attack tools in Rust. It… | 52 | 4391 | active |
| 0x90n/InfoSec-Black-Friday A annually updated curated list of Black Friday and Cyber Monday deals on InfoSec-related software, tools, and training. Deals are manually… | 57 | 4372 | active |
| r0ysue/AndroidSecurityStudy A curated Chinese-language study repository for Android application security, centered on Frida dynamic instrumentation and the FART unpack… | 32 | 4370 | active |
| Threekiii/Awesome-Redteam A curated knowledge base for red teaming and offensive security, collecting cheatsheets, scripts, tips, and links to open-source tools. It … | 71 | 4315 | active |
| Astrosp/Awesome-OSINT-List A curated awesome-list of OSINT (Open Source Intelligence) tools and websites covering reconnaissance, reverse searching, red team operatio… | 76 | 4306 | active |
| pedramamini/awesome-yara A curated awesome-list of YARA rules, tools, guides, services, and community resources for malware analysis and threat hunting. It aggregat… | 71 | 4262 | active |
| eunomia-bpf/bpf-developer-tutorial A step-by-step open-source eBPF developer tutorial based on CO-RE, with dozens of short, self-contained example tools built with libbpf, Ci… | 74 | 4254 | active |
| bikini/exploitarium A consolidated archive of public exploit proof-of-concept code and vulnerability research writeups, organized as self-contained folders per… | 55 | 4241 | active |
| 17mon/china_ip_list A quarterly-updated dataset of IP address ranges for mainland China, maintained by IPIP.NET from BGP/ASN and WHOIS data. It is distributed … | 36 | 4100 | active |
| CyberMonitor/APT_CyberCriminal_Campagin_Collections A curated collection of links and archived PDF reports about APT (Advanced Persistent Threat) and cybercriminal campaign disclosures, organ… | 32 | 4098 | active |
| ai-robots-txt/ai.robots.txt A community-maintained list of AI crawler user agents, distributed as robots.txt plus ready-made blocking configs for Apache, Nginx, Caddy,… | 92 | 4082 | active |
| 0xsyr0/Awesome-Cybersecurity-Handbooks A curated collection of cybersecurity handbooks compiled from the author's personal notes on CTFs and red teaming. It covers offensive and … | 76 | 4069 | active |
| 0xor0ne/awesome-list A curated awesome list of cybersecurity blog posts, write-ups, and papers organized by year, plus a companion list of security tools and re… | 77 | 4068 | active |
| W00t3k/Awesome-Cellular-Hacking A curated awesome-list of resources for 2G/3G/4G/5G cellular network security research, covering exploits, tools, papers, hardware setups, … | 65 | 3998 | active |
| Mr-xn/BurpSuite-collections A curated collection of Burp Suite plugins (mostly non-BApp Store), articles, and usage tips for web penetration testing. It aggregates lin… | 76 | 3964 | active |
| jekil/awesome-hacking A curated list of hacking and security tools for hackers, pentesters, and security researchers, organized by categories like CTF, forensics… | 69 | 3959 | active |
| KeiKinn/ShadowsocksBio A documentation project (in Chinese and English) chronicling the history of Shadowsocks and related censorship-circumvention tools, includi… | 55 | 3935 | active |
| carpedm20/awesome-hacking A curated awesome-list of hacking tutorials, tools, and resources covering system exploitation, reverse engineering, web security, forensic… | 32 | 16945 | maintenance |
| arkadiyt/bounty-targets-data A dataset repository containing hourly-updated dumps of bug bounty program scopes from platforms like HackerOne, Bugcrowd, Intigriti, YesWe… | 77 | 3915 | active |
| JoasASantos/OSCE3-Complete-Guide A curated study guide and resource collection for Offensive Security certifications OSCE3 (OSWE, OSEP, OSED) and OSEE. It aggregates refere… | 59 | 3888 | active |
| OneRedOak/claude-code-workflows A curated collection of workflows and configurations for Claude Code, including automated code review, security review, and design review p… | 37 | 3887 | active |
| Samsar4/Ethical-Hacking-Labs A collection of hands-on tutorials and labs for learning ethical hacking, aligned with CEH content. It guides beginners from core networkin… | 32 | 3887 | active |
| hackerschoice/thc-tips-tricks-hacks-cheat-sheet A curated cheat sheet of Linux command-line tips, tricks, and hacks from The Hacker's Choice, covering bash stealth techniques, SSH tunneli… | 73 | 3874 | active |
| arainho/awesome-api-security A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin… | 10 | 3862 | active |
| liuup/claude-code-analysis A repository of static analysis documents for the leaked TypeScript source code of Anthropic's Claude Code CLI agent, covering architecture… | 48 | 3853 | active |
| 0xsyr0/OSCP A comprehensive cheat sheet repository of commands and techniques for preparing for the OSCP (Offensive Security Certified Professional) pe… | 76 | 3831 | active |
| nakov/Practical-Cryptography-for-Developers-Book A free, open-source book by Svetlin Nakov teaching practical cryptography for developers, covering hashes, MACs, key derivation, key exchan… | 32 | 3824 | active |
| verazuo/jailbreak_llms A research dataset accompanying the ACM CCS 2024 paper 'Do Anything Now', containing 15,140 ChatGPT prompts collected from Reddit, Discord,… | 28 | 3791 | stable |
| sve1r/Rules-For-Quantumult-X A curated collection of rule lists and rewrite scripts for the Quantumult X proxy client on iOS, covering direct/accelerated routing, media… | 60 | 3784 | active |