Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
harisqazi1/Cybersecurity
A curated educational document compiling resources for people pursuing entry-level cybersecurity jobs and learning hacking skills. It cover…
101370active
nickvourd/Windows-Local-Privilege-Escalation-Cookbook
A curated cookbook of Windows local privilege escalation techniques covering misconfiguration vulnerabilities, with sections for descriptio…
601368active
lfit/itpol
A collection of generalized IT policies from the Linux Foundation's internal IT staff, shared as checklists and best-practice documents. It…
324886maintenance
0xMarcio/cve
A continuously updated hub aggregating the latest CVEs alongside links to their public Proof-of-Concept exploit repositories, with a web in…
691365active
Yara-Rules/rules
A community-maintained repository of YARA rules for malware and threat detection, organized into categories like anti-debug/anti-VM, CVEs, …
324879maintenance
0xricksanchez/paper_collection
A curated, continuously updated collection of academic papers on fuzzing, binary analysis, IoT/firmware security, and exploit development, …
351362active
neodevpro/neodevhost
A regularly updated ad and tracking blocking dataset distributed as hosts files, adblocker filter lists, dnsmasq/smartdns configs, and Clas…
771358active
Proviesec/google-dorks
A curated collection of Google Dork queries (advanced search operators) for web security testing and bug bounty hunting. It documents searc…
751355active
AdguardTeam/AdGuardSDNSFilter
A consolidated DNS-level ad-blocking filter list maintained by AdGuard, composed of several upstream filters (AdGuard Base, Social media, T…
771351active
cyberfascinate/ISC2-CC-Study-Material
A collection of study material for the ISC2 Certified in Cybersecurity (CC) entry-level certification, based on the official self-paced cou…
321348stable
NiREvil/windows-activation
An open-source documentation guide and script collection for activating Windows 10/11 and Microsoft Office using methods like HWID, KMS, KM…
451347active
projectdiscovery/public-bugbounty-programs
A community-curated dataset of public bug bounty and responsible disclosure programs, maintained as YAML with a JSON schema and distributed…
761341active
harishsg993010/damn-vulnerable-MCP-server
Damn Vulnerable MCP Server (DVMCP) is a deliberately vulnerable implementation of the Model Context Protocol built as an educational securi…
451339active
zhangkaitao/shiro-example
A collection of example code accompanying the Chinese tutorial series 'Learn Shiro with Me' (跟我学Shiro), covering Apache Shiro authenticatio…
324769maintenance
may215/awesome-termux-hacking
A curated awesome list of the best hacking and penetration testing tools that run in Termux on Android. It catalogs links to tools for OSIN…
324767maintenance
Acmesec/theAIMythbook
A Chinese-language guidebook ('AI Myth Book') covering large language model fundamentals, prompt design, AI applications in security work, …
171331active
infosecB/awesome-detection-engineering
A curated awesome-list of resources for detection engineering, the cybersecurity discipline of designing and operating detective controls. …
751330active
carlcastanas/Cybersecurity-Roadmap
A free, structured cybersecurity learning roadmap for beginners, career switchers, and IT professionals, covering networking and OS fundame…
691323active
luzhisheng/js_reverse
A curated collection of study notes and tool links for learning web scraping reverse engineering, covering JavaScript deobfuscation, app re…
761319active
eallion/uBlacklist-subscription-compilation
A curated compilation of uBlacklist subscription blocklists that merges blocklists from around the web into a single subscription URL. It p…
671319active
DERE-ad2001/Frida-Labs
A series of hands-on Android challenges designed to teach Frida dynamic instrumentation from basics to intermediate usage. Each challenge s…
571315active
Hacking-Notes/Hacker-Roadmap
A curated roadmap repository guiding learners toward hacking and penetration testing proficiency through multiple pathways, including hobby…
311315active
pashov/audits
A public repository collecting smart contract security audit reports published by the Pashov Audit Group, organized by protocol category (l…
761314active
crifan/android_app_security_crack
An open-source ebook (built with HonKit) covering Android app security and reverse engineering, from APK packaging and Dalvik/ART internals…
321313active
cloudflare/sslconfig
Cloudflare's public-facing SSL/TLS cipher configuration for its NGINX web servers, tracked as a single configuration fragment. It also incl…
671312active
Ruddernation-Designs/Adobe-URL-Block-List
A curated hosts-file blocklist of Adobe URLs and IPs, with apply/revert scripts for Windows, macOS, and Linux plus dnsmasq and Pi-hole form…
711310active
SexyBeast233/SecBooks
A curated collection of Chinese-language cybersecurity articles and vulnerability write-ups aggregated from various security blogs and WeCh…
481308active
bridgecrewio/terragoat
TerraGoat is Bridgecrew's 'Vulnerable by Design' Terraform repository containing intentionally misconfigured cloud infrastructure for AWS, …
371305active
beerisgood/Windows11_Hardening
A curated collection of documentation, links, and recommendations for hardening Windows 11, covering Microsoft Defender, Credential Guard, …
361305active
ahegazy0/linux-basics-for-hackers-notes
A structured, open-source course of study notes based on the book 'Linux Basics for Hackers' by OccupyTheWeb, organized into 18 modules cov…
521302active
1andrevich/Re-filter-lists
A regularly updated dataset of domains and IP addresses blocked in Russia, plus community-maintained lists of services restricting Russian …
881301active
phith0n/Mind-Map
A curated collection of security-related mind maps covering topics like penetration testing, web application security, code auditing, XSS, …
324600maintenance
anudeepND/blacklist
A curated, regularly updated hosts file containing domains that serve ads, tracking scripts, malware, and cryptomining scripts. It is desig…
591297active
bsauce/kernel-exploit-factory
A curated collection of Linux kernel CVE exploits paired with preconfigured QEMU debug environments and analysis writeups. It lets research…
701296active
projectacrn/acrn-hypervisor
Project ACRN is an open-source Type 1 (bare-metal) embedded hypervisor reference stack for running multiple software subsystems securely on…
571293active
jmdugan/blocklists
A curated collection of categorized domain blocklists intended for use with hosts files, Pi-hole, Dnsmasq, or Privoxy. The lists focus on b…
324566maintenance
nickboucher/trojan-source
The reference repository for the Trojan Source attack (CVE-2021-42574), which uses Unicode bidirectional control characters to make source …
321285stable
wolfi-dev/os
The main package repository for Wolfi, a minimal, security-focused GNU/Linux distribution designed for containerized environments and built…
771283active
huhusmang/Awesome-LLMs-for-Vulnerability-Detection
A curated, continuously-updated awesome-list indexing research papers, projects, datasets, and benchmarks on using large language models fo…
671283active
zardus/wargame-nexus
A curated, regularly tested list of security wargame and CTF practice sites, maintained as a simple HTML page. It categorizes sites by diff…
761281active
signalapp/Signal-TLS-Proxy
An official Signal project providing a Docker-based TLS proxy that lets users relay Signal traffic when direct connections are blocked. It …
741279active
kleo/evilportals
A collection of captive portal templates for the Hak5 WiFi Pineapple's Evil Portal module, used to conduct phishing attacks against WiFi cl…
681279active
topscoder/nuclei-wordfence-cve
A collection of 80,000+ Nuclei vulnerability-scanning templates for WordPress core, plugins, and themes, generated daily from Wordfence thr…
781278active
gmelodie/awesome-wordlists
A curated awesome-list of wordlists for brute-forcing and fuzzing, covering enumeration, passwords, usernames, emails, and vulnerabilities.…
731276active
hahwul/MobileHackersWeapons
A curated awesome-list of tools used by mobile hackers for Android and iOS security testing and bug bounty hunting. It catalogs tools by ty…
631273active
osirislab/Hack-Night
Hack Night is the open-source curriculum for NYU Tandon OSIRIS Lab's weekly thirteen-week offensive security training course. It provides l…
321273active
ForensicArtifacts/artifacts
A community-sourced, machine-readable knowledge base of digital forensic artifact definitions stored as YAML files. It provides standardize…
781268active
beigeworm/BadUSB-Files-For-FlipperZero
A collection of over 60 Ducky Script payloads curated for the FlipperZero BadUSB/BadKB feature, ranging from pranks to red team tools, most…
711266active
rng70/TryHackMe-Roadmap
A curated list of 350+ free TryHackMe rooms organized by cybersecurity topic, from Linux and Windows fundamentals to CTFs, forensics, and A…
531266active
ax1sX/SecurityList
A curated collection of web security and code audit resources, focused on Chinese enterprise software (OA systems), common Java components,…
321262active
wddadk/Offensive-OSINT-Tools
A curated awesome-list of offensive OSINT tools and links for penetration testers and red teamers. It organizes tools by reconnaissance cat…
751261active
zer0yu/Awesome-CobaltStrike
A curated awesome-list of Cobalt Strike resources including articles, videos, C2 profiles, BOFs, Aggressor scripts, and related tools. It h…
324436maintenance
jonaschn/awesome-he
A curated awesome-list of homomorphic encryption libraries, toolkits, applications, databases, and learning resources. It serves as a disco…
381257active
ybdt/exp-hub
A curated collection of proof-of-concept (PoC) and exploit (Exp) scripts for reproducing known vulnerabilities, written primarily in HTML/J…
761253active
jhaddix/tbhm
A curated collection of tips, tricks, tools, and notes for web application security assessments and bug bounty hunting, maintained by Jason…
324396maintenance
lirantal/npm-security-best-practices
A curated awesome-list of npm package manager security best practices, covering safe-by-default CLI options, supply chain attack hardening,…
551248active
anudeepND/whitelist
A curated collection of commonly whitelisted domains for Pi-Hole, bundled with a script that adds them to a Pi-Hole setup. It helps prevent…
234376maintenance
nicanorflavier/spf-dkim-dmarc-simplified
A plain-language guide explaining SPF, DKIM, and DMARC email authentication standards and how they protect domains from spoofing and phishi…
241243stable
thehappydinoa/awesome-censys-queries
A curated awesome-list of Censys Search queries (dorks) for discovering exposed industrial control systems, IoT devices, databases, dashboa…
741240active
nascentxyz/simple-security-toolkit
A collection of practical security-focused guides and checklists for smart contract development, maintained by the Nascent team. It covers …
321233stable
CHYbeta/Web-Security-Learning
A curated collection of links and learning materials on web security, covering SQL injection, XSS, CSRF, SSRF, XXE, file upload vulnerabili…
324299maintenance
emadshanab/Nuclei-Templates-Collection
A curated collection of links to community Nuclei template repositories, aggregating vulnerability detection templates for the Nuclei scann…
581225active
ashishb/android-malware
A curated collection of over 300 live Android malware samples gathered from multiple sources and mailing lists. It serves as a research dat…
591222active
blackarrowsec/redteam-research
A collection of proof-of-concept code and offensive security techniques published by the BlackArrow Red Team. It serves as a research repos…
671219active
ngalongc/bug-bounty-reference
A curated list of publicly disclosed bug bounty write-ups organized by vulnerability type such as XSS, SQLi, SSRF, and IDOR. It serves as a…
324256maintenance
sayan011/Immunefi-bug-bounty-writeups-list
A curated list of Immunefi bug bounty writeups, organized by bounty amount and severity, covering mostly web3 and smart contract vulnerabil…
641214active
giuliacassara/awesome-social-engineering
A curated awesome-list of social engineering resources including online courses, books, CTF events, tools, and OSINT links. It is aimed at …
324244maintenance
FroggMaster/FlipperZero
A curated collection of notes, scripts, applications, frequencies, and other resources for the Flipper Zero multi-tool device. It indexes p…
521207active
tandasat/Hypervisor-101-in-Rust
Course materials for 'Hypervisor 101 in Rust', a one-day class on hardware-assisted virtualization and its use for high-performance fuzzing…
511207active
t3l3machus/PowerShell-Obfuscation-Bible
A curated educational reference of manual PowerShell script obfuscation techniques for bypassing signature-based antivirus detection, with …
301204active
luguanxing/Cheating-Plugin-Program
A step-by-step educational C++ tutorial series studying the design principles of game cheats, covering memory editing, base address reading…
321203active
nozaq/terraform-aws-secure-baseline
A Terraform module that applies a secure baseline configuration to AWS accounts based on CIS Foundations and AWS Foundational Security Best…
641200active
c0ny1/upload-labs
A PHP-based deliberately vulnerable training range (CTF-style lab) that collects 20 levels of file upload vulnerabilities found in penetrat…
234190maintenance
uphiago/recon-skills
A curated pack of Markdown skill files documenting reconnaissance and penetration-testing procedures for web apps, APIs, authentication, cl…
581199active
httpvoid/writeups
A collection of application security research writeups by the HTTPVoid team, covering their own CVEs and technical analyses of public n-day…
321199active
ShadowHackrs/Jailbreaks-GPT-Gemini-deepseek-
A curated collection of jailbreak prompts targeting GPT, Sora, Claude, Gemini, and DeepSeek, claimed to bypass model safety restrictions. I…
631197active
jefferywmoore/CISSP-Study-Resources
A curated collection of study guides, reference materials, practice tests, and personal notes for preparing for the (ISC)² CISSP security c…
721196active
dwyl/learn-json-web-tokens
A tutorial repository teaching how to use JSON Web Tokens (JWT) for authentication in web and mobile applications, with working examples an…
764173maintenance
ayoubfathi/leaky-paths
A curated wordlist of special web paths linked to sensitive APIs, devops internals, framework configs, and known misconfigurations. It is d…
661193active
wh1te4ever/super-tart-vphone-writeup
A technical writeup explaining how to build a virtual iPhone using the vphone600ap components found in Apple's Private Cloud Compute (PCC) …
461192active
tide-emergency/yingji
A curated Chinese-language knowledge base and script collection for cybersecurity emergency response (应急响应), covering handling of server in…
321191active
jacobdjwilson/awesome-annual-security-reports
A curated awesome-list of annual cybersecurity reports from research firms, industry groups, non-profits, and government agencies. It centr…
771190active
birdhan/SecurityProduct
A curated awesome-list collecting open-source security products and projects, including IDS, IPS, WAF, honeypots, threat intelligence, vuln…
621190active
wesbos/burner-email-providers
A community-maintained list of disposable (burner) email provider domains, useful for filtering throwaway addresses from signup forms and m…
741189active
xiaoy-sec/Pentest_Note
A Chinese-language penetration testing handbook (Pentest Handbook) organized as a GitBook wiki covering reconnaissance, initial access, pri…
324132maintenance
twelvesec/PwnPad
PwnPad is an open-source, affordable (under $20) hardware hacking learning platform with a series of hands-on challenges covering PCB desig…
431185active
findneo/Newbie-Security-List
A curated list of cybersecurity learning resources for beginners, covering CTF platforms, web security, vulnerability databases, and knowle…
701184active
tib36/PhishingBook
A curated Chinese-language resource collection (memo/awesome list) of phishing simulation and red-blue team exercise materials, covering Of…
301183active
alvin-tosh/Malware-Exhibit
A curated collection of real-world malware samples compiled and analyzed by researchers for studying malware threats, analysis techniques, …
321181active
mdisec/mdisec-twitch-yayinlari
A companion repository for the MDISEC Twitch channel's live cybersecurity training streams, containing code written during each episode. It…
711178active
wandou911/ssr
A curated repository of free and paid Shadowsocks/ShadowsocksR proxy nodes plus one-click installation scripts and tutorials for self-hosti…
491178active
PaPerseller/chn-iplist
A regularly updated dataset of China IP routes (chnroutes) for IPv4 and IPv6, packaged as subscription rules for proxy clients like Shadowr…
761177active
yeswehack/vulnerable-code-snippets
A collection of intentionally vulnerable code snippets (mostly PHP) published weekly by YesWeHack for practicing secure code analysis. Each…
621176active
lord-alfred/ipranges
A continuously updated dataset of IP address ranges (IPv4/IPv6 CIDR lists) for major cloud providers and services like Google, AWS, Microso…
771174active
Abao130/jichangtizi-tuijian
A curated Chinese-language guide and recommendation list of commercial proxy/VPN subscription services ('airports') for circumventing inter…
641174active
hexops-graveyard/dockerfile
A curated Dockerfile template and guide documenting best practices for building production-worthy Docker images, covering non-root users, s…
324080maintenance
OverTheWireOrg/OverTheWire-website
The source for the OverTheWire website, which hosts security wargames that teach security concepts through fun, game-based challenges. The …
701171active
undergroundwires/CEH-in-bullet-points
A comprehensive set of study notes for the Certified Ethical Hacker (CEH) exam, written in bullet points and organized by exam topic. It su…
321170stable
pe3zx/my-infosec-awesome
A curated awesome-list of links, resources, and tools covering information security topics such as adversary simulation, application securi…
741169active
jphall663/awesome-machine-learning-interpretability
A curated awesome-list of resources on machine learning interpretability and responsible AI, including fairness, explainability, transparen…
704060maintenance

← prev page 7 / 12 next →