resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| harisqazi1/Cybersecurity A curated educational document compiling resources for people pursuing entry-level cybersecurity jobs and learning hacking skills. It cover… | 10 | 1370 | active |
| nickvourd/Windows-Local-Privilege-Escalation-Cookbook A curated cookbook of Windows local privilege escalation techniques covering misconfiguration vulnerabilities, with sections for descriptio… | 60 | 1368 | active |
| lfit/itpol A collection of generalized IT policies from the Linux Foundation's internal IT staff, shared as checklists and best-practice documents. It… | 32 | 4886 | maintenance |
| 0xMarcio/cve A continuously updated hub aggregating the latest CVEs alongside links to their public Proof-of-Concept exploit repositories, with a web in… | 69 | 1365 | active |
| Yara-Rules/rules A community-maintained repository of YARA rules for malware and threat detection, organized into categories like anti-debug/anti-VM, CVEs, … | 32 | 4879 | maintenance |
| 0xricksanchez/paper_collection A curated, continuously updated collection of academic papers on fuzzing, binary analysis, IoT/firmware security, and exploit development, … | 35 | 1362 | active |
| neodevpro/neodevhost A regularly updated ad and tracking blocking dataset distributed as hosts files, adblocker filter lists, dnsmasq/smartdns configs, and Clas… | 77 | 1358 | active |
| Proviesec/google-dorks A curated collection of Google Dork queries (advanced search operators) for web security testing and bug bounty hunting. It documents searc… | 75 | 1355 | active |
| AdguardTeam/AdGuardSDNSFilter A consolidated DNS-level ad-blocking filter list maintained by AdGuard, composed of several upstream filters (AdGuard Base, Social media, T… | 77 | 1351 | active |
| cyberfascinate/ISC2-CC-Study-Material A collection of study material for the ISC2 Certified in Cybersecurity (CC) entry-level certification, based on the official self-paced cou… | 32 | 1348 | stable |
| NiREvil/windows-activation An open-source documentation guide and script collection for activating Windows 10/11 and Microsoft Office using methods like HWID, KMS, KM… | 45 | 1347 | active |
| projectdiscovery/public-bugbounty-programs A community-curated dataset of public bug bounty and responsible disclosure programs, maintained as YAML with a JSON schema and distributed… | 76 | 1341 | active |
| harishsg993010/damn-vulnerable-MCP-server Damn Vulnerable MCP Server (DVMCP) is a deliberately vulnerable implementation of the Model Context Protocol built as an educational securi… | 45 | 1339 | active |
| zhangkaitao/shiro-example A collection of example code accompanying the Chinese tutorial series 'Learn Shiro with Me' (跟我学Shiro), covering Apache Shiro authenticatio… | 32 | 4769 | maintenance |
| may215/awesome-termux-hacking A curated awesome list of the best hacking and penetration testing tools that run in Termux on Android. It catalogs links to tools for OSIN… | 32 | 4767 | maintenance |
| Acmesec/theAIMythbook A Chinese-language guidebook ('AI Myth Book') covering large language model fundamentals, prompt design, AI applications in security work, … | 17 | 1331 | active |
| infosecB/awesome-detection-engineering A curated awesome-list of resources for detection engineering, the cybersecurity discipline of designing and operating detective controls. … | 75 | 1330 | active |
| carlcastanas/Cybersecurity-Roadmap A free, structured cybersecurity learning roadmap for beginners, career switchers, and IT professionals, covering networking and OS fundame… | 69 | 1323 | active |
| luzhisheng/js_reverse A curated collection of study notes and tool links for learning web scraping reverse engineering, covering JavaScript deobfuscation, app re… | 76 | 1319 | active |
| eallion/uBlacklist-subscription-compilation A curated compilation of uBlacklist subscription blocklists that merges blocklists from around the web into a single subscription URL. It p… | 67 | 1319 | active |
| DERE-ad2001/Frida-Labs A series of hands-on Android challenges designed to teach Frida dynamic instrumentation from basics to intermediate usage. Each challenge s… | 57 | 1315 | active |
| Hacking-Notes/Hacker-Roadmap A curated roadmap repository guiding learners toward hacking and penetration testing proficiency through multiple pathways, including hobby… | 31 | 1315 | active |
| pashov/audits A public repository collecting smart contract security audit reports published by the Pashov Audit Group, organized by protocol category (l… | 76 | 1314 | active |
| crifan/android_app_security_crack An open-source ebook (built with HonKit) covering Android app security and reverse engineering, from APK packaging and Dalvik/ART internals… | 32 | 1313 | active |
| cloudflare/sslconfig Cloudflare's public-facing SSL/TLS cipher configuration for its NGINX web servers, tracked as a single configuration fragment. It also incl… | 67 | 1312 | active |
| Ruddernation-Designs/Adobe-URL-Block-List A curated hosts-file blocklist of Adobe URLs and IPs, with apply/revert scripts for Windows, macOS, and Linux plus dnsmasq and Pi-hole form… | 71 | 1310 | active |
| SexyBeast233/SecBooks A curated collection of Chinese-language cybersecurity articles and vulnerability write-ups aggregated from various security blogs and WeCh… | 48 | 1308 | active |
| bridgecrewio/terragoat TerraGoat is Bridgecrew's 'Vulnerable by Design' Terraform repository containing intentionally misconfigured cloud infrastructure for AWS, … | 37 | 1305 | active |
| beerisgood/Windows11_Hardening A curated collection of documentation, links, and recommendations for hardening Windows 11, covering Microsoft Defender, Credential Guard, … | 36 | 1305 | active |
| ahegazy0/linux-basics-for-hackers-notes A structured, open-source course of study notes based on the book 'Linux Basics for Hackers' by OccupyTheWeb, organized into 18 modules cov… | 52 | 1302 | active |
| 1andrevich/Re-filter-lists A regularly updated dataset of domains and IP addresses blocked in Russia, plus community-maintained lists of services restricting Russian … | 88 | 1301 | active |
| phith0n/Mind-Map A curated collection of security-related mind maps covering topics like penetration testing, web application security, code auditing, XSS, … | 32 | 4600 | maintenance |
| anudeepND/blacklist A curated, regularly updated hosts file containing domains that serve ads, tracking scripts, malware, and cryptomining scripts. It is desig… | 59 | 1297 | active |
| bsauce/kernel-exploit-factory A curated collection of Linux kernel CVE exploits paired with preconfigured QEMU debug environments and analysis writeups. It lets research… | 70 | 1296 | active |
| projectacrn/acrn-hypervisor Project ACRN is an open-source Type 1 (bare-metal) embedded hypervisor reference stack for running multiple software subsystems securely on… | 57 | 1293 | active |
| jmdugan/blocklists A curated collection of categorized domain blocklists intended for use with hosts files, Pi-hole, Dnsmasq, or Privoxy. The lists focus on b… | 32 | 4566 | maintenance |
| nickboucher/trojan-source The reference repository for the Trojan Source attack (CVE-2021-42574), which uses Unicode bidirectional control characters to make source … | 32 | 1285 | stable |
| wolfi-dev/os The main package repository for Wolfi, a minimal, security-focused GNU/Linux distribution designed for containerized environments and built… | 77 | 1283 | active |
| huhusmang/Awesome-LLMs-for-Vulnerability-Detection A curated, continuously-updated awesome-list indexing research papers, projects, datasets, and benchmarks on using large language models fo… | 67 | 1283 | active |
| zardus/wargame-nexus A curated, regularly tested list of security wargame and CTF practice sites, maintained as a simple HTML page. It categorizes sites by diff… | 76 | 1281 | active |
| signalapp/Signal-TLS-Proxy An official Signal project providing a Docker-based TLS proxy that lets users relay Signal traffic when direct connections are blocked. It … | 74 | 1279 | active |
| kleo/evilportals A collection of captive portal templates for the Hak5 WiFi Pineapple's Evil Portal module, used to conduct phishing attacks against WiFi cl… | 68 | 1279 | active |
| topscoder/nuclei-wordfence-cve A collection of 80,000+ Nuclei vulnerability-scanning templates for WordPress core, plugins, and themes, generated daily from Wordfence thr… | 78 | 1278 | active |
| gmelodie/awesome-wordlists A curated awesome-list of wordlists for brute-forcing and fuzzing, covering enumeration, passwords, usernames, emails, and vulnerabilities.… | 73 | 1276 | active |
| hahwul/MobileHackersWeapons A curated awesome-list of tools used by mobile hackers for Android and iOS security testing and bug bounty hunting. It catalogs tools by ty… | 63 | 1273 | active |
| osirislab/Hack-Night Hack Night is the open-source curriculum for NYU Tandon OSIRIS Lab's weekly thirteen-week offensive security training course. It provides l… | 32 | 1273 | active |
| ForensicArtifacts/artifacts A community-sourced, machine-readable knowledge base of digital forensic artifact definitions stored as YAML files. It provides standardize… | 78 | 1268 | active |
| beigeworm/BadUSB-Files-For-FlipperZero A collection of over 60 Ducky Script payloads curated for the FlipperZero BadUSB/BadKB feature, ranging from pranks to red team tools, most… | 71 | 1266 | active |
| rng70/TryHackMe-Roadmap A curated list of 350+ free TryHackMe rooms organized by cybersecurity topic, from Linux and Windows fundamentals to CTFs, forensics, and A… | 53 | 1266 | active |
| ax1sX/SecurityList A curated collection of web security and code audit resources, focused on Chinese enterprise software (OA systems), common Java components,… | 32 | 1262 | active |
| wddadk/Offensive-OSINT-Tools A curated awesome-list of offensive OSINT tools and links for penetration testers and red teamers. It organizes tools by reconnaissance cat… | 75 | 1261 | active |
| zer0yu/Awesome-CobaltStrike A curated awesome-list of Cobalt Strike resources including articles, videos, C2 profiles, BOFs, Aggressor scripts, and related tools. It h… | 32 | 4436 | maintenance |
| jonaschn/awesome-he A curated awesome-list of homomorphic encryption libraries, toolkits, applications, databases, and learning resources. It serves as a disco… | 38 | 1257 | active |
| ybdt/exp-hub A curated collection of proof-of-concept (PoC) and exploit (Exp) scripts for reproducing known vulnerabilities, written primarily in HTML/J… | 76 | 1253 | active |
| jhaddix/tbhm A curated collection of tips, tricks, tools, and notes for web application security assessments and bug bounty hunting, maintained by Jason… | 32 | 4396 | maintenance |
| lirantal/npm-security-best-practices A curated awesome-list of npm package manager security best practices, covering safe-by-default CLI options, supply chain attack hardening,… | 55 | 1248 | active |
| anudeepND/whitelist A curated collection of commonly whitelisted domains for Pi-Hole, bundled with a script that adds them to a Pi-Hole setup. It helps prevent… | 23 | 4376 | maintenance |
| nicanorflavier/spf-dkim-dmarc-simplified A plain-language guide explaining SPF, DKIM, and DMARC email authentication standards and how they protect domains from spoofing and phishi… | 24 | 1243 | stable |
| thehappydinoa/awesome-censys-queries A curated awesome-list of Censys Search queries (dorks) for discovering exposed industrial control systems, IoT devices, databases, dashboa… | 74 | 1240 | active |
| nascentxyz/simple-security-toolkit A collection of practical security-focused guides and checklists for smart contract development, maintained by the Nascent team. It covers … | 32 | 1233 | stable |
| CHYbeta/Web-Security-Learning A curated collection of links and learning materials on web security, covering SQL injection, XSS, CSRF, SSRF, XXE, file upload vulnerabili… | 32 | 4299 | maintenance |
| emadshanab/Nuclei-Templates-Collection A curated collection of links to community Nuclei template repositories, aggregating vulnerability detection templates for the Nuclei scann… | 58 | 1225 | active |
| ashishb/android-malware A curated collection of over 300 live Android malware samples gathered from multiple sources and mailing lists. It serves as a research dat… | 59 | 1222 | active |
| blackarrowsec/redteam-research A collection of proof-of-concept code and offensive security techniques published by the BlackArrow Red Team. It serves as a research repos… | 67 | 1219 | active |
| ngalongc/bug-bounty-reference A curated list of publicly disclosed bug bounty write-ups organized by vulnerability type such as XSS, SQLi, SSRF, and IDOR. It serves as a… | 32 | 4256 | maintenance |
| sayan011/Immunefi-bug-bounty-writeups-list A curated list of Immunefi bug bounty writeups, organized by bounty amount and severity, covering mostly web3 and smart contract vulnerabil… | 64 | 1214 | active |
| giuliacassara/awesome-social-engineering A curated awesome-list of social engineering resources including online courses, books, CTF events, tools, and OSINT links. It is aimed at … | 32 | 4244 | maintenance |
| FroggMaster/FlipperZero A curated collection of notes, scripts, applications, frequencies, and other resources for the Flipper Zero multi-tool device. It indexes p… | 52 | 1207 | active |
| tandasat/Hypervisor-101-in-Rust Course materials for 'Hypervisor 101 in Rust', a one-day class on hardware-assisted virtualization and its use for high-performance fuzzing… | 51 | 1207 | active |
| t3l3machus/PowerShell-Obfuscation-Bible A curated educational reference of manual PowerShell script obfuscation techniques for bypassing signature-based antivirus detection, with … | 30 | 1204 | active |
| luguanxing/Cheating-Plugin-Program A step-by-step educational C++ tutorial series studying the design principles of game cheats, covering memory editing, base address reading… | 32 | 1203 | active |
| nozaq/terraform-aws-secure-baseline A Terraform module that applies a secure baseline configuration to AWS accounts based on CIS Foundations and AWS Foundational Security Best… | 64 | 1200 | active |
| c0ny1/upload-labs A PHP-based deliberately vulnerable training range (CTF-style lab) that collects 20 levels of file upload vulnerabilities found in penetrat… | 23 | 4190 | maintenance |
| uphiago/recon-skills A curated pack of Markdown skill files documenting reconnaissance and penetration-testing procedures for web apps, APIs, authentication, cl… | 58 | 1199 | active |
| httpvoid/writeups A collection of application security research writeups by the HTTPVoid team, covering their own CVEs and technical analyses of public n-day… | 32 | 1199 | active |
| ShadowHackrs/Jailbreaks-GPT-Gemini-deepseek- A curated collection of jailbreak prompts targeting GPT, Sora, Claude, Gemini, and DeepSeek, claimed to bypass model safety restrictions. I… | 63 | 1197 | active |
| jefferywmoore/CISSP-Study-Resources A curated collection of study guides, reference materials, practice tests, and personal notes for preparing for the (ISC)² CISSP security c… | 72 | 1196 | active |
| dwyl/learn-json-web-tokens A tutorial repository teaching how to use JSON Web Tokens (JWT) for authentication in web and mobile applications, with working examples an… | 76 | 4173 | maintenance |
| ayoubfathi/leaky-paths A curated wordlist of special web paths linked to sensitive APIs, devops internals, framework configs, and known misconfigurations. It is d… | 66 | 1193 | active |
| wh1te4ever/super-tart-vphone-writeup A technical writeup explaining how to build a virtual iPhone using the vphone600ap components found in Apple's Private Cloud Compute (PCC) … | 46 | 1192 | active |
| tide-emergency/yingji A curated Chinese-language knowledge base and script collection for cybersecurity emergency response (应急响应), covering handling of server in… | 32 | 1191 | active |
| jacobdjwilson/awesome-annual-security-reports A curated awesome-list of annual cybersecurity reports from research firms, industry groups, non-profits, and government agencies. It centr… | 77 | 1190 | active |
| birdhan/SecurityProduct A curated awesome-list collecting open-source security products and projects, including IDS, IPS, WAF, honeypots, threat intelligence, vuln… | 62 | 1190 | active |
| wesbos/burner-email-providers A community-maintained list of disposable (burner) email provider domains, useful for filtering throwaway addresses from signup forms and m… | 74 | 1189 | active |
| xiaoy-sec/Pentest_Note A Chinese-language penetration testing handbook (Pentest Handbook) organized as a GitBook wiki covering reconnaissance, initial access, pri… | 32 | 4132 | maintenance |
| twelvesec/PwnPad PwnPad is an open-source, affordable (under $20) hardware hacking learning platform with a series of hands-on challenges covering PCB desig… | 43 | 1185 | active |
| findneo/Newbie-Security-List A curated list of cybersecurity learning resources for beginners, covering CTF platforms, web security, vulnerability databases, and knowle… | 70 | 1184 | active |
| tib36/PhishingBook A curated Chinese-language resource collection (memo/awesome list) of phishing simulation and red-blue team exercise materials, covering Of… | 30 | 1183 | active |
| alvin-tosh/Malware-Exhibit A curated collection of real-world malware samples compiled and analyzed by researchers for studying malware threats, analysis techniques, … | 32 | 1181 | active |
| mdisec/mdisec-twitch-yayinlari A companion repository for the MDISEC Twitch channel's live cybersecurity training streams, containing code written during each episode. It… | 71 | 1178 | active |
| wandou911/ssr A curated repository of free and paid Shadowsocks/ShadowsocksR proxy nodes plus one-click installation scripts and tutorials for self-hosti… | 49 | 1178 | active |
| PaPerseller/chn-iplist A regularly updated dataset of China IP routes (chnroutes) for IPv4 and IPv6, packaged as subscription rules for proxy clients like Shadowr… | 76 | 1177 | active |
| yeswehack/vulnerable-code-snippets A collection of intentionally vulnerable code snippets (mostly PHP) published weekly by YesWeHack for practicing secure code analysis. Each… | 62 | 1176 | active |
| lord-alfred/ipranges A continuously updated dataset of IP address ranges (IPv4/IPv6 CIDR lists) for major cloud providers and services like Google, AWS, Microso… | 77 | 1174 | active |
| Abao130/jichangtizi-tuijian A curated Chinese-language guide and recommendation list of commercial proxy/VPN subscription services ('airports') for circumventing inter… | 64 | 1174 | active |
| hexops-graveyard/dockerfile A curated Dockerfile template and guide documenting best practices for building production-worthy Docker images, covering non-root users, s… | 32 | 4080 | maintenance |
| OverTheWireOrg/OverTheWire-website The source for the OverTheWire website, which hosts security wargames that teach security concepts through fun, game-based challenges. The … | 70 | 1171 | active |
| undergroundwires/CEH-in-bullet-points A comprehensive set of study notes for the Certified Ethical Hacker (CEH) exam, written in bullet points and organized by exam topic. It su… | 32 | 1170 | stable |
| pe3zx/my-infosec-awesome A curated awesome-list of links, resources, and tools covering information security topics such as adversary simulation, application securi… | 74 | 1169 | active |
| jphall663/awesome-machine-learning-interpretability A curated awesome-list of resources on machine learning interpretability and responsible AI, including fairness, explainability, transparen… | 70 | 4060 | maintenance |