resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| mullvad/dns-blocklists A repository of DNS blocklists and Ansible configuration used by Mullvad to generate DNS-based blocking files for its encrypted DNS and VPN… | 77 | 1951 | active |
| Cyfrin/security-and-auditing-full-course-s23 A comprehensive open-source course repository by Cyfrin Updraft and The Red Guild covering smart contract auditing, security, assembly, and… | 69 | 1948 | active |
| ReAbout/web-sec A continuously updated Chinese-language web security handbook (red team skill stack) organized as a curated knowledge base covering vulnera… | 74 | 1943 | active |
| ihebski/A-Red-Teamer-diaries A public collection of red team and penetration testing notes, cheatsheets, and command snippets tested on controlled lab infrastructures. … | 54 | 1932 | active |
| fabionoth/awesome-cyber-security A curated awesome-list collecting cybersecurity software, libraries, documents, books, certifications, CTF resources, and tools. It organiz… | 76 | 1930 | active |
| KaWaIDeSuNe/dijiajichang A curated Chinese-language list recommending low-cost proxy subscription services ('airports') for circumventing internet censorship, with … | 69 | 1924 | active |
| slsa-framework/slsa SLSA (Supply-chain Levels for Software Artifacts) is an OpenSSF security framework and specification defining graduated levels of software … | 75 | 1915 | active |
| evilc0deooo/PentesterSpecialDict A curated collection of fuzzing and penetration-testing dictionaries covering payloads, usernames, passwords, file paths, DNS subnames, and… | 44 | 1909 | active |
| Neo23x0/auditd A best-practice auditd ruleset for Linux that provides a broad, portable baseline of security-relevant audit telemetry. It is designed to l… | 84 | 1899 | active |
| TheGP/untidetect-tools A curated list of anti-detect browsers, humanizing tools, captcha solvers, and SMS activation services, maintained as a reference for brows… | 68 | 1899 | active |
| RoseSecurity/Red-Teaming-TTPs A curated collection of cheatsheets, guides, and scripts covering red teaming tactics, techniques, and procedures across Windows, Linux, ma… | 76 | 1897 | active |
| mthcht/awesome-lists A curated collection of security detection lists and resources for SOC, CERT, and CTI teams, including suspicious TLDs, ASNs, named pipes, … | 67 | 1892 | active |
| TakSec/google-dorks-bug-bounty A curated list of Google Dorks (advanced search queries) for bug bounty hunting, web application security, and penetration testing, with a … | 50 | 1891 | active |
| yaklang/hack-skills A curated knowledge base of 101 installable 'SKILL.md' security skills for AI agents, organized into a master entry, six category entries, … | 53 | 1879 | active |
| trailofbits/publications A curated repository of Trail of Bits' published work, including academic papers, white papers, conference presentations, security review r… | 76 | 1878 | active |
| wangdoc/ssh-tutorial An open-source Chinese-language tutorial on SSH (mainly OpenSSH), covering its concepts and basic usage, usable as a reference manual. Part… | 63 | 1867 | active |
| 8680/GOODBYEADS A curated collection of ad-blocking filter rules for AdGuard, AdGuard Home, Quantumult X, and SmartDNS. It merges high-quality upstream rul… | 77 | 1864 | active |
| OffcierCia/Crypto-OpSec-SelfGuard-RoadMap A curated knowledge base and roadmap collecting the best operational security (OpSec) research, tools, and practices for DeFi, blockchain, … | 67 | 1861 | active |
| Semporia/Clash A personal collection of Clash proxy client configurations, including node subscription setups, traffic-splitting rules, and reference conf… | 75 | 1860 | active |
| safe6Sec/Fastjson A curated collection of Fastjson exploitation techniques, payloads, and fingerprinting tricks for Java JSON deserialization vulnerabilities… | 32 | 1860 | active |
| FeeiCN/security-engineering A curated Chinese-language knowledge base on cybersecurity engineering, structured as a digital garden covering attack techniques, historic… | 74 | 1847 | active |
| lutfumertceylan/top25-parameter OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XS… | 23 | 1847 | stable |
| xalgord/Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes A curated collection of notes, tutorials, and resources for learning web application penetration testing and bug bounty hunting. It covers … | 51 | 1845 | active |
| AabyssZG/WebShell-Bypass-Guide A Chinese-language open-source manual for learning WebShell antivirus-evasion (bypass) techniques from scratch, primarily covering PHP with… | 31 | 1837 | active |
| Ignitetechnologies/HackTheBox-CTF-Writeups A curated collection of Hack The Box machine write-ups and CTF walkthroughs from Hacking Articles, organized by operating system and diffic… | 65 | 1831 | active |
| aleff-github/my-flipper-shits A curated collection of free and open-source BadUSB payloads written in DuckyScript for the Flipper Zero device, covering Windows, GNU/Linu… | 72 | 1824 | active |
| ZhangZhuoSJTU/Web3Bugs A curated dataset of exploitable bugs in Solidity smart contracts, extracted from code4rena audit contests and classified by bug nature (ou… | 43 | 1819 | active |
| daffainfo/AllAboutBugBounty A curated collection of bug bounty notes covering web vulnerabilities, bypass techniques, and payloads gathered from various sources. It is… | 32 | 6835 | maintenance |
| rootkit-io/awesome-malware-development A curated awesome-list of resources for malware development, rootkits, EDR evasion, and red-team tooling, intended for educational and defe… | 66 | 1816 | active |
| cyb3rxp/awesome-soc A curated awesome-list knowledge base and operational handbook for building, running, and maturing a Security Operations Center (SOC) and C… | 77 | 1805 | active |
| OTRF/Security-Datasets An open-source collection of malicious and benign security event datasets from different platforms, maintained by the Open Threat Research … | 23 | 1805 | active |
| lizrice/learning-ebpf Companion repository for the O'Reilly book 'Learning eBPF' by Liz Rice, containing example eBPF programs in C and BCC for each book chapter… | 65 | 1804 | active |
| coinspect/learn-evm-attacks A collection of Foundry tests reproducing real-world smart contract exploits, bug bounty reports, and theoretical vulnerabilities across EV… | 53 | 1802 | active |
| jeanphorn/wordlist A curated collection of password wordlists, username lists, and default credentials (SSH, RDP, FTP, databases, IoT, IP cameras) for authori… | 68 | 1801 | active |
| hysnsec/awesome-threat-modelling A curated awesome-list of threat modeling resources including books, free and paid courses, videos, tutorials, tools, and practice workshop… | 32 | 1801 | active |
| eastmountyxz/NetworkSecuritySelf-study A curated series of self-study notes and tutorials on network security, covering tools like Burp Suite, Nmap, Wireshark, Sqlmap, IDA Pro, a… | 32 | 1794 | active |
| trickest/wordlists A regularly updated collection of real-world infosec wordlists maintained by Trickest, including technology-specific path lists (WordPress,… | 77 | 1791 | active |
| mikeroyal/Windows-11-Guide A curated guide repository covering Windows 10/11 setup, security hardening, privacy tools, gaming, virtualization, and WSL 2. It is a docu… | 45 | 1781 | active |
| rootsecdev/Azure-Red-Team A curated collection of notes, links, and resources for Microsoft Azure and Microsoft 365 red teaming and penetration testing. It covers en… | 63 | 1773 | active |
| ignaciocastro/a-dove-is-dumb A continuously updated blocklist of Adobe telemetry-checking domains distributed in multiple hosts-file formats. It is consumed via hosts f… | 72 | 1771 | active |
| Purp1eW0lf/Blue-Team-Notes A curated collection of one-liners, small scripts, and tips for blue team / DFIR work covering Windows, Linux, and macOS investigation comm… | 75 | 1770 | active |
| threatexpress/malleable-c2 A design and reference guide for Cobalt Strike Malleable C2 profiles, including example profiles updated for recent Cobalt Strike versions … | 32 | 1766 | active |
| arch3rPro/PentestTools A curated awesome-list cataloging open-source penetration testing tools, organized by category and modeled on the Kali Tools listing. It se… | 67 | 1763 | active |
| magicsword-io/LOLDrivers LOLDrivers is a community-maintained curated dataset of vulnerable and malicious Windows drivers abused by adversaries (BYOVD attacks), wit… | 65 | 1763 | active |
| tmylla/Awesome-LLM4Cybersecurity A curated awesome-list and systematic literature review tracking 861+ papers on large language models applied to cybersecurity, organized i… | 70 | 1761 | active |
| wall-flipping/SSV2RayTrojanClashSSR A curated Chinese-language list recommending commercial VPN/proxy subscription services ('airports') for circumventing the Great Firewall, … | 77 | 1760 | active |
| EdOverflow/bugbounty-cheatsheet A curated cheat sheet of payloads, tips, and tricks for bug bounty hunters, covering vulnerabilities like XSS, SQLi, SSRF, XXE, and RCE. It… | 32 | 6536 | maintenance |
| protectai/ai-exploits A collection of real-world AI/ML exploits and scanning templates for responsibly disclosed vulnerabilities in machine learning tools and in… | 27 | 1746 | active |
| SecWiki/sec-chart A curated collection of security-related mind maps, flow charts, and diagrams covering topics like penetration testing, web security, APT a… | 32 | 6498 | maintenance |
| hintjen/selfhosted-gateway A self-hosted, Docker-native tunneling solution that exposes local Docker Compose services to the public Internet via WireGuard tunnels wit… | 38 | 1734 | active |
| Bert-JanP/Hunting-Queries-Detection-Rules A curated collection of KQL queries for Microsoft Defender for Endpoint and Azure Sentinel, covering advanced hunting, custom detections, a… | 75 | 1732 | active |
| ashishb/osx-and-ios-security-awesome A curated awesome-list of macOS and iOS security tools covering forensics, binary analysis, jailbreaks, and hardening. It is a reference ca… | 76 | 1728 | active |
| yeahhub/Hacking-Security-Ebooks A curated collection of roughly 100 free PDF e-books on hacking, penetration testing, and information security, with links to each title. I… | 32 | 6439 | maintenance |
| duyet/bruteforce-database A curated collection of wordlists (11+ million entries) for password cracking, username enumeration, subdomain discovery, and web path brut… | 74 | 1726 | active |
| assetnote/wordlists A collection of automatically and manually curated wordlists for content and subdomain discovery during security testing, generated monthly… | 63 | 1722 | active |
| spring-guides/tut-spring-security-and-angular-js A tutorial series from the Spring guides repository showing how to secure an Angular single page application with Spring Security and Sprin… | 75 | 1721 | active |
| duckduckgo/tracker-radar A dataset from DuckDuckGo cataloging the most common third-party web domains with rich metadata such as parent entity, prevalence, fingerpr… | 98 | 1718 | active |
| jakob-pennington/awesome-devsecops A curated awesome-list of DevSecOps resources and tooling, including articles, books, conferences, training, and categorized security tools… | 32 | 1718 | active |
| WADComs/WADComs.github.io WADComs is an interactive cheat sheet website hosting a curated list of offensive security tools and their commands for attacking Windows a… | 76 | 1713 | active |
| reZach/secure-electron-template A secure Electron application template combining React, Redux, Webpack, and i18next with Electron security best practices built in. It prov… | 63 | 1711 | active |
| hmaverickadams/Beginner-Network-Pentesting A collection of course notes for a free Beginner Network Pentesting course taught by The Cyber Mentor, covering ethical hacking fundamental… | 32 | 6348 | maintenance |
| itdoginfo/allow-domains A curated, regularly updated collection of domain and IP lists (blocked, geo-blocked, and country-specific resources) published in many rou… | 91 | 1707 | active |
| d-xo/weird-erc20 A collection of minimal Solidity implementations of ERC20 tokens with unusual or non-standard behavior, based on real tokens that have been… | 43 | 1707 | active |
| B3nac/Android-Reports-and-Resources A curated list of disclosed HackerOne bug bounty reports and security resources focused on Android application vulnerabilities. It organize… | 51 | 1706 | active |
| wgpsec/AboutSecurity A large structured penetration testing knowledge base containing 200+ skill methodologies covering recon, exploitation, lateral movement, a… | 65 | 1702 | active |
| ctf-wiki/ctf-challenges A curated collection of CTF (Capture The Flag) challenges organized by category, including source files, writeups, and related materials. I… | 41 | 1697 | active |
| AmnestyTech/investigations A repository of indicators of compromise (IOCs) extracted from Amnesty International's technical investigations into targeted spyware attac… | 32 | 1696 | active |
| RPiList/specials A curated collection of DNS blocklists for Pi-hole that protect against fake shops, advertising, tracking, and other internet threats. It a… | 77 | 1692 | active |
| Azure/azure-policy The official repository of Azure Policy built-in policy definitions and samples, maintained by Microsoft. It serves as the source of truth … | 76 | 1692 | active |
| Bambu-Research-Group/RFID-Tag-Guide A community research guide documenting how to decrypt, read, and clone the NFC/RFID tags Bambu Lab uses on its 3D printer filament spools, … | 51 | 1690 | active |
| satoshilabs/slips A repository of SatoshiLabs Improvement Proposals (SLIPs), technical specification documents extending the Bitcoin Improvement Proposal (BI… | 77 | 1689 | active |
| fwwdn/sensitive-stop-words A curated collection of Chinese sensitive-word and stopword lists for content moderation, text filtering, and NLP tokenization. It ships pl… | 64 | 1687 | active |
| corca-ai/awesome-llm-security A curated awesome-list of tools, papers, benchmarks, and articles focused on LLM security, covering attacks like jailbreaks and prompt inje… | 45 | 1686 | active |
| Da2dalus/The-MALWARE-Repo A curated collection of malware samples including ransomware, worms, trojans, spyware, and remote access trojans. It serves as a reference … | 32 | 1685 | active |
| randorisec/MobileHackingCheatSheet A cheat sheet summarizing commands, tools, and techniques for assessing the security of Android and iOS mobile applications. It is availabl… | 56 | 1683 | active |
| metowolf/iplist A regularly updated dataset of IP CIDR lists categorized by country (ISO 3166-1), Chinese province and city (administrative division codes)… | 77 | 1680 | active |
| luestr/ShuntRules A collection of consolidated traffic-splitting (shunt) rule files for the Loon and Clash proxy clients, merged from the blackmatrix7/ios_ru… | 66 | 1679 | active |
| splunk/security_content A repository of Splunk security detections, Analytic Stories, and SOAR playbooks maintained by the Splunk Threat Research Team, mapped to M… | 98 | 1676 | active |
| jstrosch/malware-samples A curated collection of password-protected malware samples, malicious documents, and training PCAPs for malware analysis practice. It also … | 32 | 1671 | active |
| DeepSpaceHarbor/Awesome-AI-Security A curated awesome-list of AI security resources covering adversarial examples, evasion attacks, poisoning attacks, and related research. It… | 64 | 1664 | active |
| LandGrey/SpringBootVulExploit A curated collection of Spring Boot vulnerability learning materials, exploitation methods, and a black-box security assessment checklist. … | 32 | 6144 | maintenance |
| Baeldung/spring-security-registration A companion example project for Baeldung's Learn Spring Security course demonstrating login and registration flows with Spring Security in … | 33 | 1658 | active |
| xdavidhu/awesome-google-vrp-writeups A curated list of bug bounty writeups from Google's Vulnerability Reward Program (VRP), maintained as a CSV-backed awesome list with automa… | 69 | 1654 | active |
| TCM-Course-Resources/Practical-Ethical-Hacking-Resources A curated compilation of links, tools, and references accompanying TCM Security's Practical Ethical Hacking Udemy course. It organizes reso… | 32 | 6113 | maintenance |
| devanshbatham/Awesome-Bugbounty-Writeups A curated list of bug bounty writeups organized by vulnerability type, covering XSS, SSRF, IDOR, SQL injection, and more. It serves as a le… | 32 | 6102 | maintenance |
| reprise99/Sentinel-Queries A curated collection of KQL (Kusto Query Language) queries, tips, and tutorials for Microsoft Sentinel. It teaches how to write queries for… | 61 | 1645 | active |
| RPISEC/MBE Course materials for RPISEC's Modern Binary Exploitation, a university course teaching binary exploitation, reverse engineering, and vulner… | 23 | 6033 | maintenance |
| blockthreat/blocksec-ctfs A curated list of blockchain security wargames, challenges, and Capture the Flag (CTF) competitions along with solution writeups. It serves… | 32 | 1632 | active |
| github/securitylab The main repository of GitHub Security Lab, containing security research documentation, CodeQL query examples, and proof-of-concept exploit… | 62 | 1626 | active |
| phishdestroy/destroylist A continuously updated phishing and scam domain blocklist with 208k+ curated threats, distributed in multiple formats (hosts, AdBlock, Dnsm… | 72 | 1624 | active |
| The-XSS-Rat/SecurityTesting A Python-based repository by The XSS Rat focused on security testing, likely containing scripts, labs, or educational material for web appl… | 64 | 1623 | active |
| pcaversaccio/reentrancy-attacks A curated, chronological list of reentrancy attacks on Ethereum smart contracts, maintained as a GitHub repository. It documents each attac… | 74 | 1622 | active |
| vokins/yhosts yhosts is a curated hosts file project that blocks ads, trackers, and unwanted domains via DNS-level entries. It is maintained as a regular… | 85 | 1620 | active |
| mytechnotalent/Hacking-Windows A free self-study course and book teaching Windows C development with the Win32 API, with each step reverse engineered and hacked using IDA… | 77 | 1620 | active |
| Anugrahsr/Awesome-web3-Security A curated awesome-list of web3 security materials and resources aimed at pentesters and bug hunters. It collects vulnerable CTF platforms, … | 64 | 1620 | active |
| krol3/container-security-checklist A curated checklist and guide covering container security practices from image build to workload runtime, including supply chain, registry,… | 51 | 1620 | active |
| psiinon/open-source-web-scanners A curated list of open source web security scanners hosted on GitHub and GitLab, ordered by stars. It serves as a discovery resource coveri… | 41 | 1615 | active |
| packing-box/awesome-executable-packing A curated awesome-list of resources on executable packing, covering literature, datasets, packers, and detection/unpacking tools for format… | 70 | 1614 | active |
| mazen160/secrets-patterns-db Secrets Patterns DB is the largest open-source database of over 1600 tested regular expressions for detecting secrets, API keys, passwords,… | 47 | 1609 | active |
| grbnb/xp_module A curated Chinese-language collection (backup of resources shared by Coolapk user 午夜神) of download links for Android rooting and Xposed-fra… | 46 | 1606 | active |