Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
mullvad/dns-blocklists
A repository of DNS blocklists and Ansible configuration used by Mullvad to generate DNS-based blocking files for its encrypted DNS and VPN…
771951active
Cyfrin/security-and-auditing-full-course-s23
A comprehensive open-source course repository by Cyfrin Updraft and The Red Guild covering smart contract auditing, security, assembly, and…
691948active
ReAbout/web-sec
A continuously updated Chinese-language web security handbook (red team skill stack) organized as a curated knowledge base covering vulnera…
741943active
ihebski/A-Red-Teamer-diaries
A public collection of red team and penetration testing notes, cheatsheets, and command snippets tested on controlled lab infrastructures. …
541932active
fabionoth/awesome-cyber-security
A curated awesome-list collecting cybersecurity software, libraries, documents, books, certifications, CTF resources, and tools. It organiz…
761930active
KaWaIDeSuNe/dijiajichang
A curated Chinese-language list recommending low-cost proxy subscription services ('airports') for circumventing internet censorship, with …
691924active
slsa-framework/slsa
SLSA (Supply-chain Levels for Software Artifacts) is an OpenSSF security framework and specification defining graduated levels of software …
751915active
evilc0deooo/PentesterSpecialDict
A curated collection of fuzzing and penetration-testing dictionaries covering payloads, usernames, passwords, file paths, DNS subnames, and…
441909active
Neo23x0/auditd
A best-practice auditd ruleset for Linux that provides a broad, portable baseline of security-relevant audit telemetry. It is designed to l…
841899active
TheGP/untidetect-tools
A curated list of anti-detect browsers, humanizing tools, captcha solvers, and SMS activation services, maintained as a reference for brows…
681899active
RoseSecurity/Red-Teaming-TTPs
A curated collection of cheatsheets, guides, and scripts covering red teaming tactics, techniques, and procedures across Windows, Linux, ma…
761897active
mthcht/awesome-lists
A curated collection of security detection lists and resources for SOC, CERT, and CTI teams, including suspicious TLDs, ASNs, named pipes, …
671892active
TakSec/google-dorks-bug-bounty
A curated list of Google Dorks (advanced search queries) for bug bounty hunting, web application security, and penetration testing, with a …
501891active
yaklang/hack-skills
A curated knowledge base of 101 installable 'SKILL.md' security skills for AI agents, organized into a master entry, six category entries, …
531879active
trailofbits/publications
A curated repository of Trail of Bits' published work, including academic papers, white papers, conference presentations, security review r…
761878active
wangdoc/ssh-tutorial
An open-source Chinese-language tutorial on SSH (mainly OpenSSH), covering its concepts and basic usage, usable as a reference manual. Part…
631867active
8680/GOODBYEADS
A curated collection of ad-blocking filter rules for AdGuard, AdGuard Home, Quantumult X, and SmartDNS. It merges high-quality upstream rul…
771864active
OffcierCia/Crypto-OpSec-SelfGuard-RoadMap
A curated knowledge base and roadmap collecting the best operational security (OpSec) research, tools, and practices for DeFi, blockchain, …
671861active
Semporia/Clash
A personal collection of Clash proxy client configurations, including node subscription setups, traffic-splitting rules, and reference conf…
751860active
safe6Sec/Fastjson
A curated collection of Fastjson exploitation techniques, payloads, and fingerprinting tricks for Java JSON deserialization vulnerabilities…
321860active
FeeiCN/security-engineering
A curated Chinese-language knowledge base on cybersecurity engineering, structured as a digital garden covering attack techniques, historic…
741847active
lutfumertceylan/top25-parameter
OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XS…
231847stable
xalgord/Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
A curated collection of notes, tutorials, and resources for learning web application penetration testing and bug bounty hunting. It covers …
511845active
AabyssZG/WebShell-Bypass-Guide
A Chinese-language open-source manual for learning WebShell antivirus-evasion (bypass) techniques from scratch, primarily covering PHP with…
311837active
Ignitetechnologies/HackTheBox-CTF-Writeups
A curated collection of Hack The Box machine write-ups and CTF walkthroughs from Hacking Articles, organized by operating system and diffic…
651831active
aleff-github/my-flipper-shits
A curated collection of free and open-source BadUSB payloads written in DuckyScript for the Flipper Zero device, covering Windows, GNU/Linu…
721824active
ZhangZhuoSJTU/Web3Bugs
A curated dataset of exploitable bugs in Solidity smart contracts, extracted from code4rena audit contests and classified by bug nature (ou…
431819active
daffainfo/AllAboutBugBounty
A curated collection of bug bounty notes covering web vulnerabilities, bypass techniques, and payloads gathered from various sources. It is…
326835maintenance
rootkit-io/awesome-malware-development
A curated awesome-list of resources for malware development, rootkits, EDR evasion, and red-team tooling, intended for educational and defe…
661816active
cyb3rxp/awesome-soc
A curated awesome-list knowledge base and operational handbook for building, running, and maturing a Security Operations Center (SOC) and C…
771805active
OTRF/Security-Datasets
An open-source collection of malicious and benign security event datasets from different platforms, maintained by the Open Threat Research …
231805active
lizrice/learning-ebpf
Companion repository for the O'Reilly book 'Learning eBPF' by Liz Rice, containing example eBPF programs in C and BCC for each book chapter…
651804active
coinspect/learn-evm-attacks
A collection of Foundry tests reproducing real-world smart contract exploits, bug bounty reports, and theoretical vulnerabilities across EV…
531802active
jeanphorn/wordlist
A curated collection of password wordlists, username lists, and default credentials (SSH, RDP, FTP, databases, IoT, IP cameras) for authori…
681801active
hysnsec/awesome-threat-modelling
A curated awesome-list of threat modeling resources including books, free and paid courses, videos, tutorials, tools, and practice workshop…
321801active
eastmountyxz/NetworkSecuritySelf-study
A curated series of self-study notes and tutorials on network security, covering tools like Burp Suite, Nmap, Wireshark, Sqlmap, IDA Pro, a…
321794active
trickest/wordlists
A regularly updated collection of real-world infosec wordlists maintained by Trickest, including technology-specific path lists (WordPress,…
771791active
mikeroyal/Windows-11-Guide
A curated guide repository covering Windows 10/11 setup, security hardening, privacy tools, gaming, virtualization, and WSL 2. It is a docu…
451781active
rootsecdev/Azure-Red-Team
A curated collection of notes, links, and resources for Microsoft Azure and Microsoft 365 red teaming and penetration testing. It covers en…
631773active
ignaciocastro/a-dove-is-dumb
A continuously updated blocklist of Adobe telemetry-checking domains distributed in multiple hosts-file formats. It is consumed via hosts f…
721771active
Purp1eW0lf/Blue-Team-Notes
A curated collection of one-liners, small scripts, and tips for blue team / DFIR work covering Windows, Linux, and macOS investigation comm…
751770active
threatexpress/malleable-c2
A design and reference guide for Cobalt Strike Malleable C2 profiles, including example profiles updated for recent Cobalt Strike versions …
321766active
arch3rPro/PentestTools
A curated awesome-list cataloging open-source penetration testing tools, organized by category and modeled on the Kali Tools listing. It se…
671763active
magicsword-io/LOLDrivers
LOLDrivers is a community-maintained curated dataset of vulnerable and malicious Windows drivers abused by adversaries (BYOVD attacks), wit…
651763active
tmylla/Awesome-LLM4Cybersecurity
A curated awesome-list and systematic literature review tracking 861+ papers on large language models applied to cybersecurity, organized i…
701761active
wall-flipping/SSV2RayTrojanClashSSR
A curated Chinese-language list recommending commercial VPN/proxy subscription services ('airports') for circumventing the Great Firewall, …
771760active
EdOverflow/bugbounty-cheatsheet
A curated cheat sheet of payloads, tips, and tricks for bug bounty hunters, covering vulnerabilities like XSS, SQLi, SSRF, XXE, and RCE. It…
326536maintenance
protectai/ai-exploits
A collection of real-world AI/ML exploits and scanning templates for responsibly disclosed vulnerabilities in machine learning tools and in…
271746active
SecWiki/sec-chart
A curated collection of security-related mind maps, flow charts, and diagrams covering topics like penetration testing, web security, APT a…
326498maintenance
hintjen/selfhosted-gateway
A self-hosted, Docker-native tunneling solution that exposes local Docker Compose services to the public Internet via WireGuard tunnels wit…
381734active
Bert-JanP/Hunting-Queries-Detection-Rules
A curated collection of KQL queries for Microsoft Defender for Endpoint and Azure Sentinel, covering advanced hunting, custom detections, a…
751732active
ashishb/osx-and-ios-security-awesome
A curated awesome-list of macOS and iOS security tools covering forensics, binary analysis, jailbreaks, and hardening. It is a reference ca…
761728active
yeahhub/Hacking-Security-Ebooks
A curated collection of roughly 100 free PDF e-books on hacking, penetration testing, and information security, with links to each title. I…
326439maintenance
duyet/bruteforce-database
A curated collection of wordlists (11+ million entries) for password cracking, username enumeration, subdomain discovery, and web path brut…
741726active
assetnote/wordlists
A collection of automatically and manually curated wordlists for content and subdomain discovery during security testing, generated monthly…
631722active
spring-guides/tut-spring-security-and-angular-js
A tutorial series from the Spring guides repository showing how to secure an Angular single page application with Spring Security and Sprin…
751721active
duckduckgo/tracker-radar
A dataset from DuckDuckGo cataloging the most common third-party web domains with rich metadata such as parent entity, prevalence, fingerpr…
981718active
jakob-pennington/awesome-devsecops
A curated awesome-list of DevSecOps resources and tooling, including articles, books, conferences, training, and categorized security tools…
321718active
WADComs/WADComs.github.io
WADComs is an interactive cheat sheet website hosting a curated list of offensive security tools and their commands for attacking Windows a…
761713active
reZach/secure-electron-template
A secure Electron application template combining React, Redux, Webpack, and i18next with Electron security best practices built in. It prov…
631711active
hmaverickadams/Beginner-Network-Pentesting
A collection of course notes for a free Beginner Network Pentesting course taught by The Cyber Mentor, covering ethical hacking fundamental…
326348maintenance
itdoginfo/allow-domains
A curated, regularly updated collection of domain and IP lists (blocked, geo-blocked, and country-specific resources) published in many rou…
911707active
d-xo/weird-erc20
A collection of minimal Solidity implementations of ERC20 tokens with unusual or non-standard behavior, based on real tokens that have been…
431707active
B3nac/Android-Reports-and-Resources
A curated list of disclosed HackerOne bug bounty reports and security resources focused on Android application vulnerabilities. It organize…
511706active
wgpsec/AboutSecurity
A large structured penetration testing knowledge base containing 200+ skill methodologies covering recon, exploitation, lateral movement, a…
651702active
ctf-wiki/ctf-challenges
A curated collection of CTF (Capture The Flag) challenges organized by category, including source files, writeups, and related materials. I…
411697active
AmnestyTech/investigations
A repository of indicators of compromise (IOCs) extracted from Amnesty International's technical investigations into targeted spyware attac…
321696active
RPiList/specials
A curated collection of DNS blocklists for Pi-hole that protect against fake shops, advertising, tracking, and other internet threats. It a…
771692active
Azure/azure-policy
The official repository of Azure Policy built-in policy definitions and samples, maintained by Microsoft. It serves as the source of truth …
761692active
Bambu-Research-Group/RFID-Tag-Guide
A community research guide documenting how to decrypt, read, and clone the NFC/RFID tags Bambu Lab uses on its 3D printer filament spools, …
511690active
satoshilabs/slips
A repository of SatoshiLabs Improvement Proposals (SLIPs), technical specification documents extending the Bitcoin Improvement Proposal (BI…
771689active
fwwdn/sensitive-stop-words
A curated collection of Chinese sensitive-word and stopword lists for content moderation, text filtering, and NLP tokenization. It ships pl…
641687active
corca-ai/awesome-llm-security
A curated awesome-list of tools, papers, benchmarks, and articles focused on LLM security, covering attacks like jailbreaks and prompt inje…
451686active
Da2dalus/The-MALWARE-Repo
A curated collection of malware samples including ransomware, worms, trojans, spyware, and remote access trojans. It serves as a reference …
321685active
randorisec/MobileHackingCheatSheet
A cheat sheet summarizing commands, tools, and techniques for assessing the security of Android and iOS mobile applications. It is availabl…
561683active
metowolf/iplist
A regularly updated dataset of IP CIDR lists categorized by country (ISO 3166-1), Chinese province and city (administrative division codes)…
771680active
luestr/ShuntRules
A collection of consolidated traffic-splitting (shunt) rule files for the Loon and Clash proxy clients, merged from the blackmatrix7/ios_ru…
661679active
splunk/security_content
A repository of Splunk security detections, Analytic Stories, and SOAR playbooks maintained by the Splunk Threat Research Team, mapped to M…
981676active
jstrosch/malware-samples
A curated collection of password-protected malware samples, malicious documents, and training PCAPs for malware analysis practice. It also …
321671active
DeepSpaceHarbor/Awesome-AI-Security
A curated awesome-list of AI security resources covering adversarial examples, evasion attacks, poisoning attacks, and related research. It…
641664active
LandGrey/SpringBootVulExploit
A curated collection of Spring Boot vulnerability learning materials, exploitation methods, and a black-box security assessment checklist. …
326144maintenance
Baeldung/spring-security-registration
A companion example project for Baeldung's Learn Spring Security course demonstrating login and registration flows with Spring Security in …
331658active
xdavidhu/awesome-google-vrp-writeups
A curated list of bug bounty writeups from Google's Vulnerability Reward Program (VRP), maintained as a CSV-backed awesome list with automa…
691654active
TCM-Course-Resources/Practical-Ethical-Hacking-Resources
A curated compilation of links, tools, and references accompanying TCM Security's Practical Ethical Hacking Udemy course. It organizes reso…
326113maintenance
devanshbatham/Awesome-Bugbounty-Writeups
A curated list of bug bounty writeups organized by vulnerability type, covering XSS, SSRF, IDOR, SQL injection, and more. It serves as a le…
326102maintenance
reprise99/Sentinel-Queries
A curated collection of KQL (Kusto Query Language) queries, tips, and tutorials for Microsoft Sentinel. It teaches how to write queries for…
611645active
RPISEC/MBE
Course materials for RPISEC's Modern Binary Exploitation, a university course teaching binary exploitation, reverse engineering, and vulner…
236033maintenance
blockthreat/blocksec-ctfs
A curated list of blockchain security wargames, challenges, and Capture the Flag (CTF) competitions along with solution writeups. It serves…
321632active
github/securitylab
The main repository of GitHub Security Lab, containing security research documentation, CodeQL query examples, and proof-of-concept exploit…
621626active
phishdestroy/destroylist
A continuously updated phishing and scam domain blocklist with 208k+ curated threats, distributed in multiple formats (hosts, AdBlock, Dnsm…
721624active
The-XSS-Rat/SecurityTesting
A Python-based repository by The XSS Rat focused on security testing, likely containing scripts, labs, or educational material for web appl…
641623active
pcaversaccio/reentrancy-attacks
A curated, chronological list of reentrancy attacks on Ethereum smart contracts, maintained as a GitHub repository. It documents each attac…
741622active
vokins/yhosts
yhosts is a curated hosts file project that blocks ads, trackers, and unwanted domains via DNS-level entries. It is maintained as a regular…
851620active
mytechnotalent/Hacking-Windows
A free self-study course and book teaching Windows C development with the Win32 API, with each step reverse engineered and hacked using IDA…
771620active
Anugrahsr/Awesome-web3-Security
A curated awesome-list of web3 security materials and resources aimed at pentesters and bug hunters. It collects vulnerable CTF platforms, …
641620active
krol3/container-security-checklist
A curated checklist and guide covering container security practices from image build to workload runtime, including supply chain, registry,…
511620active
psiinon/open-source-web-scanners
A curated list of open source web security scanners hosted on GitHub and GitLab, ordered by stars. It serves as a discovery resource coveri…
411615active
packing-box/awesome-executable-packing
A curated awesome-list of resources on executable packing, covering literature, datasets, packers, and detection/unpacking tools for format…
701614active
mazen160/secrets-patterns-db
Secrets Patterns DB is the largest open-source database of over 1600 tested regular expressions for detecting secrets, API keys, passwords,…
471609active
grbnb/xp_module
A curated Chinese-language collection (backup of resources shared by Coolapk user 午夜神) of download links for Android rooting and Xposed-fra…
461606active

← prev page 5 / 12 next →