resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| google/fuzzing A Google-hosted collection of tutorials, examples, documentation, and research proposals about fuzz testing, primarily aimed at C/C++ devel… | 10 | 3782 | active |
| husnainfareed/awesome-ethical-hacking-resources A curated awesome list of resources for learning ethical hacking and penetration testing, including books, courses, CTF platforms, vulnerab… | 67 | 3745 | active |
| Az0x7/vulnerability-Checklist A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40… | 30 | 3634 | active |
| Ignitetechnologies/Privilege-Escalation A curated cheat sheet and reference guide covering Linux and Windows privilege escalation techniques with worked examples from CTF and Vuln… | 65 | 3630 | active |
| Cats-Team/AdRules AdRules is a curated blocklist for blocking ads, trackers, malware, HTTPDNS, and PCDN traffic, focused on the Chinese region. It publishes … | 77 | 3614 | active |
| Acmesec/PromptJailbreakManual A Chinese-language manual (handbook) covering prompt engineering, prompt injection, prompt leaking, and LLM jailbreak techniques, with secu… | 12 | 3608 | active |
| OWASP/ASVS The OWASP Application Security Verification Standard (ASVS) is an open standard defining a comprehensive set of security requirements for d… | 87 | 3571 | active |
| awesome-windows11/windows11 A curated awesome-list of Windows 11 settings, tweaks, PowerShell scripts, and ISO resources for configuring Windows without third-party cl… | 67 | 3537 | active |
| yokoffing/filterlists A curated collection of adblock filter lists and recommendations for uBlock Origin, AdGuard, Brave, and similar content blockers. It guides… | 77 | 3528 | active |
| vaib25vicky/awesome-mobile-security A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes… | 32 | 3525 | active |
| V33RU/awesome-connected-things-sec A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin… | 76 | 3524 | active |
| dweinstein/awesome-frida A curated list of Frida resources, including libraries, projects, scripts, talks, and blog posts. Frida is a dynamic code instrumentation t… | 66 | 3516 | active |
| syncsynchalt/illustrated-tls12 An educational project that walks through a complete TLS 1.2 connection byte by byte, explaining every field of the handshake, published as… | 47 | 3514 | active |
| limbopro/Profiles4limbo A collection of ready-made 'lazy' configuration profiles for Quantumult X (and Surge) that bundle ad-blocking, traffic splitting, and rewri… | 74 | 3498 | active |
| sergiomarotco/Network-segmentation-cheat-sheet A curated collection of best-practice diagrams and guidance for segmenting corporate networks, organized into maturity levels. It includes … | 52 | 3493 | active |
| 0x4D31/awesome-oscp A curated awesome-list of resources for preparing for the OSCP (Offensive Security Certified Professional) certification. It collects guide… | 32 | 3466 | active |
| 2factorauth/twofactorauth A community-maintained dataset and API listing websites and services that support two-factor authentication, covering SMS, email, hardware,… | 67 | 3455 | active |
| snoopysecurity/awesome-burp-extensions A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and … | 76 | 3439 | active |
| gmh5225/awesome-game-security A curated awesome-list of resources on game security, covering anti-cheat systems, anti-debugging, kernel drivers, and game hacking techniq… | 77 | 3433 | active |
| matro7sh/BypassAV A curated mindmap (markdown rendered via Markmap) listing essential techniques for bypassing antivirus and EDR software. It serves as a ref… | 27 | 3433 | active |
| iDoka/awesome-canbus A curated awesome-list of CAN bus tools, hardware, and resources for reverse engineering and automotive security research. It collects soft… | 75 | 3432 | active |
| corkami/collisions A collection of hash collision tools, scripts, and examples by Ange Albertini and Marc Stevens, demonstrating MD5 and SHA1 collision attack… | 35 | 3397 | active |
| dongyubin/Free-AppleId-Serve A curated Chinese-language resource list and tutorial collection for circumventing internet censorship, centered on free shared US-region A… | 77 | 3377 | active |
| rshipp/awesome-malware-analysis A curated awesome-list of malware analysis tools and resources covering collection, threat intelligence, sandboxing, deobfuscation, debuggi… | 32 | 14158 | maintenance |
| Hamed233/Cybersecurity-Mastery-Roadmap A curated, step-by-step roadmap guiding learners from beginner to expert in cybersecurity, organized into phases covering foundations, tech… | 62 | 3367 | active |
| blaCCkHatHacEEkr/PENTESTING-BIBLE A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi… | 32 | 13939 | maintenance |
| jessfraz/dockerfiles A collection of Dockerfiles maintained by Jessie Frazelle for packaging command-line tools and desktop applications as Docker containers. I… | 32 | 13936 | maintenance |
| Bo0oM/fuzz.txt A curated wordlist of potentially dangerous and sensitive file paths for web fuzzing and directory brute-forcing. It is commonly used with … | 75 | 3321 | active |
| Goochbeater/Spiritual-Spell-Red-Teaming A curated collection of jailbreak prompts and red-teaming techniques targeting large language models, primarily Claude. It serves as an adv… | 59 | 3313 | active |
| brootware/awesome-cyber-security-university A curated awesome list of free cybersecurity educational resources organized into structured learning paths covering red team, blue team, C… | 48 | 3287 | active |
| lynkco01/jichangtuijian A curated, regularly updated list recommending paid proxy subscription services ('airports') for circumventing the Great Firewall of China,… | 74 | 3263 | active |
| h5bp/server-configs-apache A collection of Apache HTTP Server configuration snippets from the HTML5 Boilerplate project that improve website performance, security, an… | 64 | 3248 | active |
| coreruleset/coreruleset OWASP Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity, Coraza, or other compatible web application … | 99 | 3242 | stable |
| Tencent/secguide A set of secure coding guides from Tencent covering C/C++, JavaScript, Node, Go, Java, and Python, aimed at developers. It catalogs API-lev… | 32 | 13476 | maintenance |
| six2dez/OneListForAll A curated collection of wordlists for web fuzzing, aggregating ~36 source repositories into categorized short/long lists and combined 'onel… | 67 | 3231 | active |
| guyinatuxedo/nightmare Nightmare is an open-source introductory course on binary exploitation and reverse engineering built around CTF challenges, with over 90 do… | 62 | 3210 | stable |
| ytisf/theZoo theZoo is a curated repository of live malware samples made publicly accessible for educational malware analysis. It includes a Python cons… | 65 | 13328 | maintenance |
| dwisiswant0/awesome-oneliner-bugbounty A curated awesome-list collection of one-liner shell scripts for bug bounty hunting, covering tasks like LFI, open-redirect, XSS, prototype… | 32 | 3188 | active |
| neargle/re0-kubernetes-sec-archive A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap… | 55 | 3164 | active |
| yokoffing/NextDNS-Config A community-maintained setup guide with recommended configuration settings for NextDNS, a DNS-over-HTTPS filtering service. It covers secur… | 71 | 3127 | active |
| Loyalsoldier/surge-rules A continuously auto-updated collection of Surge rule sets (DOMAIN-SET and RULE-SET files) for Surge on iOS and Mac, built daily via GitHub … | 95 | 3122 | active |
| olafhartong/sysmon-modular A modular repository of Microsoft Sysmon configuration modules maintained in PowerShell, with scripts to generate custom sysmonconfig.xml f… | 75 | 3119 | active |
| easylist/easylist EasyList is a set of community-maintained adblock filter lists (EasyList, EasyPrivacy, EasyList Cookie, Fanboy's Social/Annoyance/Notificat… | 77 | 3108 | active |
| C2SP/wycheproof Project Wycheproof is a collection of JSON test vectors for testing cryptography libraries against known attacks, specification inconsisten… | 76 | 3104 | active |
| ljagiello/ctf-skills A collection of Agent Skills (SKILL.md files) that teach AI coding agents like Claude Code, Codex, and Gemini CLI how to solve Capture The … | 60 | 3104 | active |
| h5bp/server-configs A meta-repository from the HTML5 Boilerplate project that curates boilerplate configuration files for various web servers such as Apache an… | 32 | 3090 | active |
| blackorbird/APT_REPORT A curated collection of APT (Advanced Persistent Threat) reports, malware samples, and special IOCs gathered from security vendors and rese… | 77 | 3084 | active |
| hacksysteam/HackSysExtremeVulnerableDriver HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche… | 26 | 3083 | active |
| Psyhackological/AAA A curated list of the best free and open-source (FOSS) Android apps focused on privacy, freedom, and de-Googling, with 273+ vetted apps acr… | 66 | 3044 | active |
| lirantal/awesome-nodejs-security A curated awesome-list of Node.js security resources, including tools for framework hardening, static and dynamic analysis, vulnerability a… | 76 | 3027 | active |
| duffn/dumb-password-rules A crowdsourced compilation of websites with absurd or overly restrictive password rules, published as a browsable site at dumbpasswordrules… | 77 | 3024 | active |
| trickster0/OffensiveRust A collection of Rust examples and experiments for weaponizing the language in red team engagements, covering implant development techniques… | 32 | 3024 | active |
| awake1t/HackReport A curated Chinese-language collection of penetration testing report templates, security books, conference slides, and hands-on offensive/de… | 32 | 3014 | active |
| w181496/Web-CTF-Cheatsheet A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads … | 54 | 2982 | active |
| SnailSploit/Claude-Red A curated library of 58 offensive security skill files (SKILL.md) for the Claude skills system, covering attack surfaces from SQL injection… | 62 | 2976 | active |
| Flangvik/SharpCollection SharpCollection is a repository of nightly-built precompiled C# offensive security tool binaries (Rubeus, Certify, KrbRelay, etc.), automat… | 75 | 2969 | active |
| hak5/bashbunny-payloads The official community payload repository for the Hak5 Bash Bunny USB attack platform, containing payloads written in DuckyScript and Bash.… | 62 | 2947 | active |
| CVE List An official mirror/cache of the CVE List maintained by the CVE Program, published as CVE Records in JSON 5 format. It is updated continuous… | 95 | 2934 | active |
| frankwxu/digital-forensics-lab A free, grant-supported repository of hands-on digital forensics labs for students and faculty, built around Kali Linux with PowerPoint sli… | 75 | 2930 | active |
| publicsuffix/list The Public Suffix List is a community-maintained dataset of all known public internet domain suffixes such as com, co.uk, and pvt.k12.ma.us… | 76 | 2921 | active |
| Endermanch/MalwareDatabase A curated GitHub collection of malware samples (rogue/PUP, trojans, ransomware, joke programs) archived with passwords for safe storage. It… | 74 | 2903 | active |
| ivRodriguezCA/RE-iOS-Apps A free, open-source online course teaching reverse engineering of iOS applications across five modules, from environment setup to binary pa… | 32 | 2901 | active |
| kurogai/100-redteam-projects A curated list of 100 red team project ideas for security students and aspiring pentesters, organized from basic to advanced levels. It gui… | 66 | 2898 | active |
| maxiaof/github-hosts A daily-updated hosts file mapping GitHub domains to working IP addresses, helping users in China access GitHub when direct connections fai… | 77 | 2883 | active |
| dloss/python-pentest-tools A curated list of Python tools, libraries, and bindings useful for penetration testers, vulnerability researchers, and reverse engineers. I… | 74 | 2883 | active |
| orangetw/My-CTF-Web-Challenges A curated collection of CTF web challenges created by Orange Tsai, including source code, ideas, and write-ups from HITCON and other compet… | 50 | 2857 | active |
| slowmist/openclaw-security-practice-guide A security practice guide for OpenClaw, a high-privilege autonomous AI agent, built around an Agentic Zero-Trust Architecture rather than a… | 49 | 2857 | active |
| dafthack/CloudPentestCheatsheets A collection of cheatsheets for tools used in penetration testing of cloud provider environments, covering Azure/O365, AWS, and GCP. It foc… | 66 | 2836 | active |
| redhuntlabs/Awesome-Asset-Discovery A curated awesome-list of resources, tools, and services for asset discovery during security assessments, covering subdomains, IPs, emails,… | 33 | 2833 | active |
| EnergizedProtection/block Energized Protection - block is a collection of consolidated domain blocklists that merge reputable filters into protection packs for block… | 77 | 2821 | active |
| OverTheWallNode/SSV2RayTrojanSSRClash A curated list (in Chinese) recommending commercial VPN/proxy 'airport' providers for circumventing internet censorship, covering protocols… | 77 | 2817 | active |
| skills/secure-code-game An open source, gamified in-browser learning experience that teaches secure coding and AI security through interactive levels. It covers to… | 74 | 2813 | active |
| bugcrowd/bugcrowd_university Bugcrowd University is a free, open-source collection of educational modules for security researchers, including slides, videos, and hands-… | 77 | 2800 | active |
| gh0stkey/Web-Fuzzing-Box A curated collection of web fuzzing dictionaries and payloads covering brute force, directory enumeration, and common web vulnerabilities l… | 65 | 2792 | active |
| ComplianceAsCode/content A collection of machine-readable security policy content for platforms like RHEL, Fedora, Ubuntu, and products like Firefox, expressed in S… | 86 | 2791 | active |
| kjfx/QuantumultX A beginner's tutorial repository for Quantumult X, a paid iOS network proxy tool. It covers downloading the app, adding proxy nodes via sub… | 32 | 2762 | active |
| Integration-IT/Active-Directory-Exploitation-Cheat-Sheet A curated cheat sheet covering common enumeration and attack techniques for Windows Active Directory environments, organized as a kill-chai… | 46 | 2761 | active |
| Hacking-the-Cloud/hackingthe.cloud Hacking the Cloud is a community-maintained encyclopedia of offensive and defensive security techniques for cloud native technologies, cove… | 84 | 2746 | active |
| cipher387/Dorks-collections-list A curated awesome-list of GitHub repositories and articles collecting search engine dorks (Google, Shodan, Censys, GitHub, DuckDuckGo, and … | 39 | 2732 | active |
| imran-parray/Mind-Maps A curated collection of visual mind maps covering bug bounty hunting, penetration testing, and offensive/defensive security methodologies. … | 32 | 2725 | stable |
| Qihoo360/safe-rules A detailed C/C++ secure programming guideline collection (the '360 Safety Rules') authored by Qihoo 360's quality engineering department. I… | 23 | 2713 | active |
| gracenolan/Notes A curated set of interview study notes for Security Engineering roles, written by a Google security engineer. It covers networking, web app… | 62 | 2711 | active |
| denji/nginx-tuning A curated reference of NGINX configuration snippets and tuning guidance for maximizing web server performance, covering worker processes, c… | 60 | 2703 | active |
| elastic/detection-rules The official open-source repository of detection rules used by Elastic Security's Detection Engine, containing thousands of prebuilt threat… | 94 | 2693 | active |
| threedr3am/learnjavabug A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jac… | 32 | 2687 | active |
| trimstray/the-practical-linux-hardening-guide A practical guide for hardening GNU/Linux production systems, covering CIS, STIG, NIST, and PCI-DSS compliance with step-by-step instructio… | 32 | 10821 | maintenance |
| user1342/Awesome-Android-Reverse-Engineering A curated awesome-list of Android reverse engineering training courses, videos, books, tools, and CTF resources. It serves as a reference d… | 43 | 2679 | active |
| tennc/webshell A curated open-source collection of webshells written in PHP, JSP, ASP, ASPX, Perl, and Python, maintained as a reference repository for se… | 23 | 10774 | maintenance |
| JoyChou93/java-sec-code A Spring Boot-based Java web application containing intentionally vulnerable code examples for common vulnerability types like SQLi, SSRF, … | 23 | 2673 | active |
| SinaKarvandi/Hypervisor-From-Scratch Source code accompanying a multi-part tutorial series on building an Intel VT-x hypervisor from scratch. It covers VMX operation, VMCS setu… | 69 | 2658 | stable |
| netbiosX/Checklists A curated collection of penetration testing and red teaming checklists covering techniques like privilege escalation, persistence, credenti… | 47 | 2657 | active |
| Mr-xn/RedTeam_BlueTeam_HW A curated collection of red team and blue team tools, documents, and reference materials for Chinese HW (HVV) attack-defense exercises. It … | 76 | 2643 | active |
| pstadler/keybase-gpg-github A step-by-step tutorial for creating a GPG key via keybase.io, importing it into a local GPG setup, and configuring Git to sign commits ver… | 52 | 2642 | stable |
| zhaoweih/Shadowsocks-Tutorial A beginner-friendly tutorial repository (mostly in Chinese) for setting up a personal Shadowsocks proxy server on a VPS to bypass internet … | 74 | 2641 | active |
| j00ru/windows-syscalls A collection of Windows system call tables extracted from ntoskrnl.exe and win32k.sys across nearly every Windows release from NT 3.x throu… | 59 | 2631 | active |
| danieldurnea/FBI-tools A curated awesome-list of open-source OSINT (Open Source Intelligence) tools for information gathering, reconnaissance, and forensics. It c… | 37 | 2626 | active |
| wtsxDev/reverse-engineering A curated awesome-list of reverse engineering resources including books, courses, tools, and practice materials. It covers topics like disa… | 32 | 10392 | maintenance |
| Ignitetechnologies/BurpSuite-For-Pentester A curated cheat sheet and learning guide for using Burp Suite in web application penetration testing and bug bounty hunting. It links struc… | 65 | 2588 | active |
| Nickyie/Cybersecurity-Resources A curated library of cybersecurity resources covering various infosec topics. It serves as a reference collection for learners and practiti… | 32 | 2586 | active |
| veeral-patel/how-to-secure-anything A curated educational repository documenting security engineering principles and processes for securing systems of any kind, from castles t… | 32 | 10227 | maintenance |