Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
google/fuzzing
A Google-hosted collection of tutorials, examples, documentation, and research proposals about fuzz testing, primarily aimed at C/C++ devel…
103782active
husnainfareed/awesome-ethical-hacking-resources
A curated awesome list of resources for learning ethical hacking and penetration testing, including books, courses, CTF platforms, vulnerab…
673745active
Az0x7/vulnerability-Checklist
A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40…
303634active
Ignitetechnologies/Privilege-Escalation
A curated cheat sheet and reference guide covering Linux and Windows privilege escalation techniques with worked examples from CTF and Vuln…
653630active
Cats-Team/AdRules
AdRules is a curated blocklist for blocking ads, trackers, malware, HTTPDNS, and PCDN traffic, focused on the Chinese region. It publishes …
773614active
Acmesec/PromptJailbreakManual
A Chinese-language manual (handbook) covering prompt engineering, prompt injection, prompt leaking, and LLM jailbreak techniques, with secu…
123608active
OWASP/ASVS
The OWASP Application Security Verification Standard (ASVS) is an open standard defining a comprehensive set of security requirements for d…
873571active
awesome-windows11/windows11
A curated awesome-list of Windows 11 settings, tweaks, PowerShell scripts, and ISO resources for configuring Windows without third-party cl…
673537active
yokoffing/filterlists
A curated collection of adblock filter lists and recommendations for uBlock Origin, AdGuard, Brave, and similar content blockers. It guides…
773528active
vaib25vicky/awesome-mobile-security
A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes…
323525active
V33RU/awesome-connected-things-sec
A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin…
763524active
dweinstein/awesome-frida
A curated list of Frida resources, including libraries, projects, scripts, talks, and blog posts. Frida is a dynamic code instrumentation t…
663516active
syncsynchalt/illustrated-tls12
An educational project that walks through a complete TLS 1.2 connection byte by byte, explaining every field of the handshake, published as…
473514active
limbopro/Profiles4limbo
A collection of ready-made 'lazy' configuration profiles for Quantumult X (and Surge) that bundle ad-blocking, traffic splitting, and rewri…
743498active
sergiomarotco/Network-segmentation-cheat-sheet
A curated collection of best-practice diagrams and guidance for segmenting corporate networks, organized into maturity levels. It includes …
523493active
0x4D31/awesome-oscp
A curated awesome-list of resources for preparing for the OSCP (Offensive Security Certified Professional) certification. It collects guide…
323466active
2factorauth/twofactorauth
A community-maintained dataset and API listing websites and services that support two-factor authentication, covering SMS, email, hardware,…
673455active
snoopysecurity/awesome-burp-extensions
A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and …
763439active
gmh5225/awesome-game-security
A curated awesome-list of resources on game security, covering anti-cheat systems, anti-debugging, kernel drivers, and game hacking techniq…
773433active
matro7sh/BypassAV
A curated mindmap (markdown rendered via Markmap) listing essential techniques for bypassing antivirus and EDR software. It serves as a ref…
273433active
iDoka/awesome-canbus
A curated awesome-list of CAN bus tools, hardware, and resources for reverse engineering and automotive security research. It collects soft…
753432active
corkami/collisions
A collection of hash collision tools, scripts, and examples by Ange Albertini and Marc Stevens, demonstrating MD5 and SHA1 collision attack…
353397active
dongyubin/Free-AppleId-Serve
A curated Chinese-language resource list and tutorial collection for circumventing internet censorship, centered on free shared US-region A…
773377active
rshipp/awesome-malware-analysis
A curated awesome-list of malware analysis tools and resources covering collection, threat intelligence, sandboxing, deobfuscation, debuggi…
3214158maintenance
Hamed233/Cybersecurity-Mastery-Roadmap
A curated, step-by-step roadmap guiding learners from beginner to expert in cybersecurity, organized into phases covering foundations, tech…
623367active
blaCCkHatHacEEkr/PENTESTING-BIBLE
A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi…
3213939maintenance
jessfraz/dockerfiles
A collection of Dockerfiles maintained by Jessie Frazelle for packaging command-line tools and desktop applications as Docker containers. I…
3213936maintenance
Bo0oM/fuzz.txt
A curated wordlist of potentially dangerous and sensitive file paths for web fuzzing and directory brute-forcing. It is commonly used with …
753321active
Goochbeater/Spiritual-Spell-Red-Teaming
A curated collection of jailbreak prompts and red-teaming techniques targeting large language models, primarily Claude. It serves as an adv…
593313active
brootware/awesome-cyber-security-university
A curated awesome list of free cybersecurity educational resources organized into structured learning paths covering red team, blue team, C…
483287active
lynkco01/jichangtuijian
A curated, regularly updated list recommending paid proxy subscription services ('airports') for circumventing the Great Firewall of China,…
743263active
h5bp/server-configs-apache
A collection of Apache HTTP Server configuration snippets from the HTML5 Boilerplate project that improve website performance, security, an…
643248active
coreruleset/coreruleset
OWASP Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity, Coraza, or other compatible web application …
993242stable
Tencent/secguide
A set of secure coding guides from Tencent covering C/C++, JavaScript, Node, Go, Java, and Python, aimed at developers. It catalogs API-lev…
3213476maintenance
six2dez/OneListForAll
A curated collection of wordlists for web fuzzing, aggregating ~36 source repositories into categorized short/long lists and combined 'onel…
673231active
guyinatuxedo/nightmare
Nightmare is an open-source introductory course on binary exploitation and reverse engineering built around CTF challenges, with over 90 do…
623210stable
ytisf/theZoo
theZoo is a curated repository of live malware samples made publicly accessible for educational malware analysis. It includes a Python cons…
6513328maintenance
dwisiswant0/awesome-oneliner-bugbounty
A curated awesome-list collection of one-liner shell scripts for bug bounty hunting, covering tasks like LFI, open-redirect, XSS, prototype…
323188active
neargle/re0-kubernetes-sec-archive
A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap…
553164active
yokoffing/NextDNS-Config
A community-maintained setup guide with recommended configuration settings for NextDNS, a DNS-over-HTTPS filtering service. It covers secur…
713127active
Loyalsoldier/surge-rules
A continuously auto-updated collection of Surge rule sets (DOMAIN-SET and RULE-SET files) for Surge on iOS and Mac, built daily via GitHub …
953122active
olafhartong/sysmon-modular
A modular repository of Microsoft Sysmon configuration modules maintained in PowerShell, with scripts to generate custom sysmonconfig.xml f…
753119active
easylist/easylist
EasyList is a set of community-maintained adblock filter lists (EasyList, EasyPrivacy, EasyList Cookie, Fanboy's Social/Annoyance/Notificat…
773108active
C2SP/wycheproof
Project Wycheproof is a collection of JSON test vectors for testing cryptography libraries against known attacks, specification inconsisten…
763104active
ljagiello/ctf-skills
A collection of Agent Skills (SKILL.md files) that teach AI coding agents like Claude Code, Codex, and Gemini CLI how to solve Capture The …
603104active
h5bp/server-configs
A meta-repository from the HTML5 Boilerplate project that curates boilerplate configuration files for various web servers such as Apache an…
323090active
blackorbird/APT_REPORT
A curated collection of APT (Advanced Persistent Threat) reports, malware samples, and special IOCs gathered from security vendors and rese…
773084active
hacksysteam/HackSysExtremeVulnerableDriver
HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche…
263083active
Psyhackological/AAA
A curated list of the best free and open-source (FOSS) Android apps focused on privacy, freedom, and de-Googling, with 273+ vetted apps acr…
663044active
lirantal/awesome-nodejs-security
A curated awesome-list of Node.js security resources, including tools for framework hardening, static and dynamic analysis, vulnerability a…
763027active
duffn/dumb-password-rules
A crowdsourced compilation of websites with absurd or overly restrictive password rules, published as a browsable site at dumbpasswordrules…
773024active
trickster0/OffensiveRust
A collection of Rust examples and experiments for weaponizing the language in red team engagements, covering implant development techniques…
323024active
awake1t/HackReport
A curated Chinese-language collection of penetration testing report templates, security books, conference slides, and hands-on offensive/de…
323014active
w181496/Web-CTF-Cheatsheet
A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads …
542982active
SnailSploit/Claude-Red
A curated library of 58 offensive security skill files (SKILL.md) for the Claude skills system, covering attack surfaces from SQL injection…
622976active
Flangvik/SharpCollection
SharpCollection is a repository of nightly-built precompiled C# offensive security tool binaries (Rubeus, Certify, KrbRelay, etc.), automat…
752969active
hak5/bashbunny-payloads
The official community payload repository for the Hak5 Bash Bunny USB attack platform, containing payloads written in DuckyScript and Bash.…
622947active
CVE List
An official mirror/cache of the CVE List maintained by the CVE Program, published as CVE Records in JSON 5 format. It is updated continuous…
952934active
frankwxu/digital-forensics-lab
A free, grant-supported repository of hands-on digital forensics labs for students and faculty, built around Kali Linux with PowerPoint sli…
752930active
publicsuffix/list
The Public Suffix List is a community-maintained dataset of all known public internet domain suffixes such as com, co.uk, and pvt.k12.ma.us…
762921active
Endermanch/MalwareDatabase
A curated GitHub collection of malware samples (rogue/PUP, trojans, ransomware, joke programs) archived with passwords for safe storage. It…
742903active
ivRodriguezCA/RE-iOS-Apps
A free, open-source online course teaching reverse engineering of iOS applications across five modules, from environment setup to binary pa…
322901active
kurogai/100-redteam-projects
A curated list of 100 red team project ideas for security students and aspiring pentesters, organized from basic to advanced levels. It gui…
662898active
maxiaof/github-hosts
A daily-updated hosts file mapping GitHub domains to working IP addresses, helping users in China access GitHub when direct connections fai…
772883active
dloss/python-pentest-tools
A curated list of Python tools, libraries, and bindings useful for penetration testers, vulnerability researchers, and reverse engineers. I…
742883active
orangetw/My-CTF-Web-Challenges
A curated collection of CTF web challenges created by Orange Tsai, including source code, ideas, and write-ups from HITCON and other compet…
502857active
slowmist/openclaw-security-practice-guide
A security practice guide for OpenClaw, a high-privilege autonomous AI agent, built around an Agentic Zero-Trust Architecture rather than a…
492857active
dafthack/CloudPentestCheatsheets
A collection of cheatsheets for tools used in penetration testing of cloud provider environments, covering Azure/O365, AWS, and GCP. It foc…
662836active
redhuntlabs/Awesome-Asset-Discovery
A curated awesome-list of resources, tools, and services for asset discovery during security assessments, covering subdomains, IPs, emails,…
332833active
EnergizedProtection/block
Energized Protection - block is a collection of consolidated domain blocklists that merge reputable filters into protection packs for block…
772821active
OverTheWallNode/SSV2RayTrojanSSRClash
A curated list (in Chinese) recommending commercial VPN/proxy 'airport' providers for circumventing internet censorship, covering protocols…
772817active
skills/secure-code-game
An open source, gamified in-browser learning experience that teaches secure coding and AI security through interactive levels. It covers to…
742813active
bugcrowd/bugcrowd_university
Bugcrowd University is a free, open-source collection of educational modules for security researchers, including slides, videos, and hands-…
772800active
gh0stkey/Web-Fuzzing-Box
A curated collection of web fuzzing dictionaries and payloads covering brute force, directory enumeration, and common web vulnerabilities l…
652792active
ComplianceAsCode/content
A collection of machine-readable security policy content for platforms like RHEL, Fedora, Ubuntu, and products like Firefox, expressed in S…
862791active
kjfx/QuantumultX
A beginner's tutorial repository for Quantumult X, a paid iOS network proxy tool. It covers downloading the app, adding proxy nodes via sub…
322762active
Integration-IT/Active-Directory-Exploitation-Cheat-Sheet
A curated cheat sheet covering common enumeration and attack techniques for Windows Active Directory environments, organized as a kill-chai…
462761active
Hacking-the-Cloud/hackingthe.cloud
Hacking the Cloud is a community-maintained encyclopedia of offensive and defensive security techniques for cloud native technologies, cove…
842746active
cipher387/Dorks-collections-list
A curated awesome-list of GitHub repositories and articles collecting search engine dorks (Google, Shodan, Censys, GitHub, DuckDuckGo, and …
392732active
imran-parray/Mind-Maps
A curated collection of visual mind maps covering bug bounty hunting, penetration testing, and offensive/defensive security methodologies. …
322725stable
Qihoo360/safe-rules
A detailed C/C++ secure programming guideline collection (the '360 Safety Rules') authored by Qihoo 360's quality engineering department. I…
232713active
gracenolan/Notes
A curated set of interview study notes for Security Engineering roles, written by a Google security engineer. It covers networking, web app…
622711active
denji/nginx-tuning
A curated reference of NGINX configuration snippets and tuning guidance for maximizing web server performance, covering worker processes, c…
602703active
elastic/detection-rules
The official open-source repository of detection rules used by Elastic Security's Detection Engine, containing thousands of prebuilt threat…
942693active
threedr3am/learnjavabug
A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jac…
322687active
trimstray/the-practical-linux-hardening-guide
A practical guide for hardening GNU/Linux production systems, covering CIS, STIG, NIST, and PCI-DSS compliance with step-by-step instructio…
3210821maintenance
user1342/Awesome-Android-Reverse-Engineering
A curated awesome-list of Android reverse engineering training courses, videos, books, tools, and CTF resources. It serves as a reference d…
432679active
tennc/webshell
A curated open-source collection of webshells written in PHP, JSP, ASP, ASPX, Perl, and Python, maintained as a reference repository for se…
2310774maintenance
JoyChou93/java-sec-code
A Spring Boot-based Java web application containing intentionally vulnerable code examples for common vulnerability types like SQLi, SSRF, …
232673active
SinaKarvandi/Hypervisor-From-Scratch
Source code accompanying a multi-part tutorial series on building an Intel VT-x hypervisor from scratch. It covers VMX operation, VMCS setu…
692658stable
netbiosX/Checklists
A curated collection of penetration testing and red teaming checklists covering techniques like privilege escalation, persistence, credenti…
472657active
Mr-xn/RedTeam_BlueTeam_HW
A curated collection of red team and blue team tools, documents, and reference materials for Chinese HW (HVV) attack-defense exercises. It …
762643active
pstadler/keybase-gpg-github
A step-by-step tutorial for creating a GPG key via keybase.io, importing it into a local GPG setup, and configuring Git to sign commits ver…
522642stable
zhaoweih/Shadowsocks-Tutorial
A beginner-friendly tutorial repository (mostly in Chinese) for setting up a personal Shadowsocks proxy server on a VPS to bypass internet …
742641active
j00ru/windows-syscalls
A collection of Windows system call tables extracted from ntoskrnl.exe and win32k.sys across nearly every Windows release from NT 3.x throu…
592631active
danieldurnea/FBI-tools
A curated awesome-list of open-source OSINT (Open Source Intelligence) tools for information gathering, reconnaissance, and forensics. It c…
372626active
wtsxDev/reverse-engineering
A curated awesome-list of reverse engineering resources including books, courses, tools, and practice materials. It covers topics like disa…
3210392maintenance
Ignitetechnologies/BurpSuite-For-Pentester
A curated cheat sheet and learning guide for using Burp Suite in web application penetration testing and bug bounty hunting. It links struc…
652588active
Nickyie/Cybersecurity-Resources
A curated library of cybersecurity resources covering various infosec topics. It serves as a reference collection for learners and practiti…
322586active
veeral-patel/how-to-secure-anything
A curated educational repository documenting security engineering principles and processes for securing systems of any kind, from castles t…
3210227maintenance

← prev page 3 / 12 next →