Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
Ultimate-Hosts-Blacklist/Ultimate.Hosts.Blacklist
A large, daily-updated unified hosts file aggregating hundreds of thousands of malicious and unwanted domains, plus hosts.deny and superhos…
771605active
Phishing-Database/Phishing.Database
A continuously updated open-source database of phishing domains, URLs, and threats, validated with the PyFunceble testing tool and publishe…
771602active
wishihab/Android-RATList
A curated list of known Android Remote Access Trojans (RATs) with their features and required permissions, intended for documentation and r…
741602active
yueliu1999/Awesome-Jailbreak-on-LLMs
A curated awesome-list collecting state-of-the-art jailbreak methods on large language models, including papers, code, datasets, evaluation…
671602active
trickest/inventory
A continuously updated asset inventory of over 800 public bug bounty programs, including DNS and web server data, maintained by Trickest. I…
351602active
m0nad/awesome-privilege-escalation
A curated awesome-list of resources for privilege escalation on Linux, Windows, Docker, and cloud platforms. It aggregates guides, papers, …
651595active
austinsonger/Incident-Playbook
A community-driven catalog of incident response playbooks mapped to MITRE ATT&CK tactics and techniques, along with checklists, exercise sc…
321591active
trimstray/iptables-essentials
A curated reference guide of common iptables firewall rules, commands, and kernel (sysctl) settings for Linux. It serves as a practical che…
321590stable
Audi-1/sqli-labs
SQLI-LABS is a self-hosted PHP web application of deliberately vulnerable SQL injection labs for learning and practicing SQL injection tech…
325833maintenance
ViktorUJ/cks
An open-source learning platform for Kubernetes and AWS EKS, built with Terraform, that provides hands-on lab environments and practice que…
761586active
fr0gger/awesome-ida-x64-olly-plugin
A curated awesome-style list of plugins for reverse-engineering tools including IDA Pro, Ghidra, x64DBG, GDB, and OllyDBG. It catalogs plug…
631586active
jassics/awesome-aws-security
A curated awesome-list of AWS security resources including whitepapers, books, videos, tutorials, courses, tools, CTFs, and hacking practic…
661585active
tkmru/awesome-edr-bypass
A curated awesome-list of resources, proof-of-concept code, and tools for bypassing Endpoint Detection and Response (EDR) software, aimed a…
591585active
xairy/kernel-exploits
A collection of proof-of-concept exploits for Linux kernel vulnerabilities written in C, covering CVEs from 2016 to 2025. Each exploit demo…
511582active
nickspaargaren/no-google
A maintained blocklist of Google and Google-related domains, distributed in formats for Pi-hole, AdGuard, and hosts files. It categorizes d…
761581active
SexyBeast233/SecDictionary
A curated collection of wordlists and dictionaries for security testing, built from real-world penetration testing experience. It includes …
751581active
Berkanktk/CyberSecurity
A curated collection of foundational cybersecurity knowledge organized into topics like security models, threat intelligence, penetration t…
631581active
0xJs/RedTeaming_CheatSheet
A community-maintained pentesting and red teaming cheatsheet collecting commands and techniques across infrastructure, Windows Active Direc…
561576active
thunlp/TAADpapers
A curated, categorized list of must-read research papers on textual adversarial attack and defense in NLP. It organizes over 150 papers by …
441575active
otobtc/ADhosts
A curated collection of ad-blocking hosts files and filter rules for PC and Android, aggregating sources like yhosts, StevenBlack, AdAway, …
361574active
ffffffff0x/1earn
A security knowledge framework maintained by the ffffffff0x team, organized as a large collection of Markdown notes covering web security, …
325708maintenance
sajjadium/ctf-archives
A curated archive of Capture The Flag (CTF) competition challenges organized by event and year, with links to writeups and CTFtime event pa…
771559active
RocketGod-git/Flipper_Zero
A dump of RocketGod's Flipper Zero SD card contents, largely derived from the UberGuidoZ Flipper repository, containing files, assets, and …
611558active
maddiestone/AndroidAppRE
An introductory workshop on reverse engineering Android applications, covering both DEX bytecode and native code analysis. It is hosted as …
321557stable
DNSCrypt/dnscrypt-resolvers
A curated, actively maintained dataset of public DNSCrypt, DNS-over-HTTPS (DoH), and Oblivious DoH servers, plus anonymized DNS relays. It …
771554active
rapid7/metasploitable3
Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit developme…
355681maintenance
Xacone/BestEdrOfTheMarket
An open-source lab implementing EDR-style detection capabilities in a Windows kernel driver, covering kernel callbacks, system call interce…
561552active
SecWiki/linux-kernel-exploits
A curated collection of Linux kernel privilege escalation exploits organized by CVE, with descriptions and affected kernel versions. It ser…
325650maintenance
mikesiko/PracticalMalwareAnalysis-Labs
A collection of malicious lab binaries accompanying the book 'Practical Malware Analysis'. The samples are designed as hands-on reverse-eng…
321545stable
terraform-google-modules/terraform-example-foundation
A Terraform example repository demonstrating how to compose Cloud Foundation Toolkit (CFT) modules into a secure Google Cloud enterprise fo…
861544active
SwiftOnSecurity/sysmon-config
A heavily commented Microsoft Sysmon configuration file template providing high-quality default event tracing for Windows systems. It serve…
325630maintenance
OlivierLaflamme/Cheatsheet-God
A curated collection of penetration testing cheatsheets, scripts, and how-to guides compiled for OSCP/PTP/PTX exam preparation and general …
325622maintenance
euphrat1ca/Security-List
A curated Chinese-language security knowledge index (awesome-style list) covering the full red team attack lifecycle, from reconnaissance a…
321529active
Bypass007/Emergency-Response-Notes
A Chinese-language GitBook-style collection of security incident response notes covering intrusion investigation, log analysis, persistence…
325562maintenance
hoshsadiq/adblock-nocoin-list
A maintained block list that prevents browser-based JavaScript cryptocurrency mining (cryptojacking). It is distributed in Adblock filter f…
701523active
I-Am-Jakoby/PowerShell-for-Hackers
A curated collection of PowerShell functions useful for hackers and payload developers, contributed by the top Hak5 payload creator. Each f…
321523active
Nanos
Nanos is a unikernel written in C that runs exactly one application in a virtualized environment, with no users, ssh, or multi-process supp…
821512active
diegolnasc/kubernetes-best-practices
A community-maintained cookbook of best practices for working with Kubernetes, covering cluster setup, security, RBAC, networking, secrets …
681504active
davinci1010/pinduoduo_backdoor
A security research repository documenting analysis of privilege-escalation code embedded in the Pinduoduo Android APK, including a VMP-pac…
305448maintenance
ksluckow/awesome-symbolic-execution
A curated awesome-list of symbolic execution resources, including foundational research papers, university lecture slides, videos, and tool…
651496active
cedrickchee/awesome-wireguard
A curated awesome-list of WireGuard tools, projects, tutorials, and resources. It organizes links by category (tools, mesh networking, depl…
321493active
xairy/vmware-exploitation
A curated collection of links to research, write-ups, slides, and videos about VMware escape exploits and vulnerability research. It serves…
321493active
NotPrab/.NET-Obfuscator
A curated list of .NET obfuscators, protectors, and packers, categorized as open source, free, freemium, and paid. It helps developers find…
341492active
crytic/awesome-ethereum-security
A curated list of Ethereum security references, guidance, tools, blogs, and capture-the-flag resources maintained by Trail of Bits. It serv…
321486active
elastic/protections-artifacts
Elastic's open repository of endpoint detection content, including EQL-based behavior rules, YARA malware rules, and ransomware protection …
761482active
x0uid/SpotifyAdBlock
A maintained hosts-file blocklist that redirects Spotify's ad and analytics/tracking domains to localhost, blocking ads and telemetry on Li…
321479active
vavkamil/awesome-vulnerable-apps
A curated awesome-list of intentionally vulnerable applications, VMs, and CTF platforms for practicing security skills. It covers web explo…
711471active
hfiref0x/SyscallTables
A collection of combined Windows NT syscall tables covering ntoskrnl and win32k service tables across Windows versions from XP x64 through …
631465active
skyw4tch3r/RootKits-List-Download
A curated list of links to rootkit projects and resources found on GitHub and other sites, covering Linux, Windows, BSD, and Android rootki…
501465active
chvancooten/OSEP-Code-Snippets
A collection of code snippets and boilerplate tools for Offensive Security's PEN-300 (OSEP) course, covering Windows privilege escalation, …
471464active
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
A curated collection of study notes covering over 110 PortSwigger Web Security Academy labs used to pass the Burp Suite Certified Practitio…
751461active
OWASP/Go-SCP
An OWASP guide book covering secure coding practices for web applications written in Go, adapted from the OWASP Secure Coding Practices Qui…
325285maintenance
rootphantomer/Blasting_dictionary
A collection of dictionaries (wordlists) for brute-force attacks, commonly used with tools like Hydra, Burp Suite, and other password-crust…
325284maintenance
BehiSecc/First-Bounty
A beginner-friendly bug bounty roadmap repository that guides readers from zero knowledge in web application security to earning their firs…
361459active
tanprathan/MobileApp-Pentest-Cheatsheet
A curated cheat sheet and checklist of high-value tools and techniques for mobile application penetration testing, mapped to the OWASP Mobi…
325257maintenance
SkipToTheEndpoint/OpenIntuneBaseline
A community-driven security baseline of configuration profiles and settings for Windows devices managed by Microsoft Intune. It provides a …
771453active
jerryn70/GoodbyeAds
GoodbyeAds is a curated adblock filter list that blocks ads, trackers, and malware domains across browsers, Android apps, and DNS-based blo…
341453active
WebBluetoothCG/web-bluetooth
The W3C Web Bluetooth Community Group's repository hosting the Web Bluetooth specification, which defines JavaScript APIs for websites to s…
701446active
1ndianl33t/Gf-Patterns
A collection of JSON pattern files for the tomnomnom/gf grep wrapper, used to match URLs and parameters vulnerable to SSRF, RCE, LFI, SQLi,…
321446active
Cyber-Guy1/API-SecurityEmpire
A curated collection of mindmaps, tips, and resources for API security and API penetration testing, based on the OWASP API Top 10. It cover…
321445active
kuasar-io/kuasar
Kuasar is a multi-sandbox container runtime written in Rust that provides a unified sandbox abstraction on top of containerd's Sandbox API.…
781443active
vpnfast/vpnfast.github.io
A Chinese-language informational website (GitHub Pages) reviewing and ranking VPN services and censorship-circumvention tools that work beh…
771443active
gh0stkey/Binary-Learning
A collection of Chinese-language study notes on binary security and reverse engineering, primarily covering the Dishui (滴水) reverse enginee…
321441active
initstring/passphrase-wordlist
A large wordlist of over 20 million passphrase phrases paired with two hashcat rule files that generate 1,000+ permutations per phrase for …
371440active
disposable/disposable
A regularly updated dataset of disposable/temporary email address domains (like 10MinuteMail and GuerrillaMail), provided as plain text lis…
751438active
0x727/FingerprintHub
FingerprintHub is a community-maintained YAML fingerprint rule library for the ObserverWard web technology detection tool. Rules use nuclei…
671437active
pushsecurity/browser-identity-attacks-matrix
A curated knowledge base of browser and identity attack techniques covering SaaS applications, identity providers, phishing, and browser-ba…
641436active
w3c/webauthn
The W3C Web Authentication (WebAuthn) specification repository, defining a browser API for creating and using scoped, attested public key c…
671435active
BushidoUK/Ransomware-Tool-Matrix
A curated knowledge base mapping the tools used by ransomware and extortion gangs, organized by category (RMM, exfiltration, credential the…
651434active
trustedsec/SysmonCommunityGuide
A community-maintained guide by TrustedSec covering Microsoft Sysinternals Sysmon on Windows and Linux, including installation, configurati…
711431active
msanft/CVE-2025-55182
A Python proof-of-concept and technical writeup for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (as use…
411431active
ottosulin/awesome-ai-security
A curated awesome list of AI security resources including frameworks, standards, learning materials, and open-source tools. It covers topic…
741427active
random-robbie/bruteforce-lists
A collection of wordlist files for brute-forcing various targets, useful in bug bounty and penetration testing workflows. It is a data repo…
681427active
bollwarm/SecToolSet
A curated collection of GitHub security-related tools and projects, organized into categories like scanners, penetration testing, CTF pract…
671423active
cjh0613/tencent-sensitive-words
An offline dataset of sensitive words extracted from Tencent's software, published as a wordlist repository. It is intended for content mod…
101423active
BypassAntiVirus
A Chinese-language knowledge base and tool collection on antivirus evasion (bypassing AV) for remote access payloads, summarizing dozens of…
325120maintenance
TributePaulWalker/Profiles
A curated collection of Surge 5 proxy configuration rules, scripts, and modules aggregated from popular community rule projects like Conner…
731420active
ZYSzys/awesome-captcha
A curated awesome-list of CAPTCHA libraries, generation tools, and captcha cracking/solving resources across many languages. It serves as a…
671420active
DebOps
DebOps is a collection of general-purpose Ansible roles and playbooks for managing Debian- and Ubuntu-based hosts, from single servers to m…
901418active
jiep/offensive-ai-compilation
A curated list of resources covering Offensive AI, including adversarial machine learning attacks (extraction, inversion, poisoning, evasio…
741418active
tnballo/high-assurance-rust
A free online book, 'High Assurance Rust', teaching secure and robust systems software development in Rust through a project-based approach…
461413active
agent-network-protocol/AgentNetworkProtocol
AgentNetworkProtocol (ANP) is an open-source protocol specification suite defining how AI agents identify, discover, and communicate with e…
771407active
WICG/webusb
The WebUSB API specification, a W3C Community Group draft that defines a JavaScript API for securely accessing USB devices directly from we…
711407active
carlospolop/Auto_Wordlists
A repository of automatically generated security wordlists for web fuzzing, reconnaissance, and payload testing, refreshed on a schedule (D…
761403active
ClashConnectRules/Self-Configuration
A curated collection of ready-to-use proxy client configuration files, primarily a Clash/Clash Meta YAML config with rule-based routing, re…
531402active
alphaSeclab/awesome-reverse-engineering
A curated awesome-list of reverse engineering resources covering 3500+ open source tools and 2300+ articles and videos across Windows, Linu…
235035maintenance
OWASP/www-community
The OWASP Community Pages repository, which hosts community-contributed application security content published at owasp.org/www-community. …
771401active
monperrus/crawler-user-agents
A curated JSON dataset of regular-expression patterns matching HTTP user-agents used by bots, crawlers, spiders, and scrapers. It is distri…
751400active
microsoft/MSRC-Security-Research
A repository hosting security research published by the Microsoft Security Response Center (MSRC). It contains research papers, tools, and …
321392active
Drun1baby/JavaSecurityLearning
A curated learning roadmap and notes repository for Java security, covering Java deserialization vulnerabilities, Commons Collections gadge…
451388active
Hack-with-Github/Free-Security-eBooks
A curated list of links to free security, hacking, and penetration-testing eBooks available on the internet, organized by topic such as net…
104974maintenance
stong/how-to-exploit-a-double-free
A long-form tutorial repository teaching modern binary exploitation through a real CTF challenge from pbctf. It walks through exploiting an…
341387stable
insidetrust/statistically-likely-usernames
A collection of wordlists for generating statistically likely usernames for use in password attacks, username enumeration, and authorized s…
621386stable
ckane/CS7038-Malware-Analysis
A public course repository for the University of Cincinnati's Malware Analysis class (CS6038/CS5138), containing lecture content, topics, a…
321383active
kaiiyer/awesome-vulnerable
A curated awesome-list of intentionally vulnerable applications and systems for practicing penetration testing. It catalogs vulnerable web …
721381active
taielab/awesome-hacking-lists
An auto-generated awesome list curating thousands of GitHub repositories (via the starred tool), with an emphasis on penetration testing to…
571381active
socfortress/Wazuh-Rules
A community-maintained collection of advanced Wazuh detection rulesets that improve on Wazuh's default rules for more accurate threat detec…
551381active
ffffffff0x/Digital-Privacy
A curated collection of resources on digital privacy protection and OSINT (open-source intelligence), covering sensitive information discov…
104944maintenance
KaWaIDeSuNe/xingjiabijichang
A curated Chinese-language list recommending paid VPN proxy services ('airports') compatible with Clash, Shadowsocks, and V2Ray clients, wi…
661376active
mmotti/pihole-regex
A curated regex filter list for Pi-hole v4+ (FTLDNS) that blocks broad patterns of ad, tracking, and malicious domains. It ships with a Pyt…
321373active

← prev page 6 / 12 next →