resource: security
1184 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| RPISEC/Malware Course materials for RPISEC's university-level Malware Analysis course (CSCI 4976), built around the Practical Malware Analysis book. It in… | 23 | 4059 | maintenance |
| subat0mik/Misconfiguration-Manager A central knowledge base documenting known Microsoft Configuration Manager (SCCM/ConfigMgr) attack tradecraft along with defensive and hard… | 71 | 1167 | active |
| Zeyad-Azima/Offensive-Resources A large curated collection of learning resources and labs for offensive security, covering topics like infrastructure, web, mobile, API, cl… | 48 | 1167 | active |
| aws-samples/aws-security-reference-architecture-examples A code library of example solutions from AWS that demonstrates how to deploy security services across a multi-account AWS Organizations env… | 66 | 1149 | active |
| foospidy/payloads A curated collection of web attack payloads (XSS, SQLi, CRLF, open redirect, password lists, and more) aggregated from many well-known secu… | 32 | 3979 | maintenance |
| HuskyHacks/PMAT-labs A collection of lab exercises and live malware samples accompanying the Practical Malware Analysis & Triage (PMAT) course. The repository i… | 64 | 1147 | active |
| 1N3/IntruderPayloads A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodol… | 32 | 3970 | maintenance |
| certsocietegenerale/IRM A collection of operational incident response cheat sheets (IRM-2022) published by CERT Societe Generale with CERT aDvens. Each methodology… | 39 | 1140 | active |
| sbwml/halflife-list A collection of Adblock/uBlock Origin filter lists that merge popular rulesets like Easylist, EasylistChina, EasyPrivacy, and CJX's Annoyan… | 77 | 1139 | active |
| learnk8s/kubernetes-production-best-practices A free, open checklist of Kubernetes best practices for releasing applications to production, covering application behavior, manifests, sec… | 69 | 1136 | active |
| ethereum/devp2p The official specifications for Ethereum's peer-to-peer networking protocols, including node discovery (v4/v5), DNS node lists, Ethereum No… | 76 | 1127 | active |
| Repcz/Tool A curated repository of proxy rule-sets (Netflix, Telegram, AI services, China domains/IPs, etc.) and configuration profiles for proxy clie… | 72 | 1126 | active |
| S3N4T0R-0X0/APTs-Adversary-Simulation A curated collection of simulated APT campaigns modeled on real-world state-sponsored threat groups from Russia, China, Iran, and North Kor… | 68 | 1123 | active |
| jakespringer/angr_ctf A collection of capture-the-flag style challenges designed to teach binary analysis and symbolic execution with the angr framework. It incl… | 32 | 1123 | active |
| The-Hacker-Recipes/The-Hacker-Recipes The Hacker Recipes is a free and open-source collection of technical guides on hacking topics, with a focus on Active Directory and web ser… | 74 | 1118 | active |
| kinopeee/cursorrules A collection of custom instructions and workflow commands optimized for the Cursor AI code editor, provided in both Japanese and English. I… | 55 | 1116 | active |
| bkerler/exploit_me A deliberately vulnerable ARM/ARM64 C++ application offering 29 CTF-style exploitation levels covering techniques like stack overflow, form… | 80 | 1106 | active |
| mikeroyal/Open-Source-Security-Guide A curated open-source guide to security covering standards (FIPS, CIS, FedRAMP, FISMA), frameworks, threat models, encryption, benchmarks, … | 45 | 1106 | active |
| indianajson/can-i-take-over-dns A curated reference list of DNS providers and whether domains pointing to their nameservers are vulnerable to DNS (zone) takeover, with fin… | 76 | 1103 | active |
| digitalknk/openclaw-runbook An unofficial, opinionated runbook (built as an Astro documentation site) for operating OpenClaw AI agents day to day with a focus on cost … | 53 | 1103 | active |
| conwnet/wpa-dictionary A WPA/WPA2 password dictionary (wordlist) dataset intended for Wi-Fi password cracking, paired with a tutorial on using aircrack-ng on Linu… | 32 | 3794 | maintenance |
| mdecrevoisier/Microsoft-eventlog-mindmap A collection of mindmaps (PDF/PNG/SVG) detailing the auditing capacities and event logs of Microsoft products including Windows, Windows Se… | 55 | 1102 | active |
| disclose/bug-bounty-platforms A community-maintained, CC0-licensed catalog of every known bug bounty platform, vulnerability disclosure platform, and crowdsourced securi… | 76 | 1101 | active |
| rodolfomarianocy/OSCP-Tricks A curated OSCP preparation guide collecting tricks, tutorials, exercises, and machine recommendations for penetration testing. It organizes… | 63 | 1101 | active |
| lovelyyoshino/Halcon_licenses A collection of Halcon (MVTec machine vision software) license .dat files with installation instructions for placing them in the Halcon lic… | 75 | 1100 | active |
| Medicean/VulApps VulApps is a collection of Dockerized vulnerability environments (CVE-based, e.g. Struts2, Spring, Tomcat, Drupal) plus security tool envir… | 10 | 3783 | maintenance |
| aws-samples/aws-incident-response-playbooks A collection of sample incident response playbooks for AWS environments, aligned to NIST SP 800-61r3 and CSF 2.0. It provides templates and… | 66 | 1099 | active |
| SourByte05/Vulnerability-Wiki-PoC A continuously updated archive of 1-day/N-day vulnerability PoCs and reproduction write-ups focused on high-value enterprise assets such as… | 61 | 1099 | active |
| OWASP/DevSecOpsGuideline An OWASP project providing a guideline for embedding security into DevOps/CI-CD pipelines, covering practices like SAST, DAST, SCA, IaC sca… | 74 | 1098 | active |
| LINCnil/Guide-RGPD-du-developpeur An open-source GDPR compliance guide for developers published by the French data protection authority (CNIL). It consists of 18 thematic fa… | 23 | 1097 | stable |
| scadastrangelove/awesome-ai-security-tools A curated awesome-list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. It catalogs tools ac… | 59 | 1095 | active |
| crypto101/book Crypto 101 is a free, open-source introductory book on cryptography aimed at programmers, covering ciphers, hash functions, MACs, public-ke… | 23 | 3765 | maintenance |
| microsoft/shell-intune-samples A Microsoft-maintained collection of sample shell scripts for managing macOS and Linux devices through Microsoft Intune. It provides educat… | 68 | 1092 | active |
| minaminao/ctf-blockchain A curated collection of 200+ blockchain CTF challenges and wargames with categorized writeups and solutions, focused on Ethereum, Solidity,… | 53 | 1092 | active |
| hak5/omg-payloads The official community payload library for Hak5's O.MG line of covert USB attack devices (Cable, Adapter, Plug, Unblocker). It contains Duc… | 57 | 1090 | active |
| Kim-Hammar/awesome-rl-for-cybersecurity A curated awesome-list of resources for applying reinforcement learning to cyber security, including RL environments, papers, books, blog p… | 74 | 1085 | active |
| platomav/CPUMicrocodes A curated repository of the latest production CPU microcode binaries for Intel, AMD, VIA, and Freescale processors, collected from official… | 71 | 1084 | active |
| javaweb-sec/javaweb-sec An open-source knowledge base and training project summarizing Java Web security topics, published as a GitBook at javasec.org. It explains… | 70 | 1083 | active |
| BC-SECURITY/Beginners-Guide-to-Obfuscation A hands-on workshop and course material from BC Security teaching malware obfuscation and defense evasion techniques on Windows. It covers … | 32 | 1080 | active |
| disclose/diodb An open, CC0-licensed dataset of vulnerability disclosure programs (VDPs) and bug bounty programs, including their safe-harbor status, poli… | 76 | 1079 | active |
| max-baz/dotfiles A personal dotfiles repository managing NixOS system and user configurations declaratively with Nix flakes and home-manager. It configures … | 76 | 1079 | active |
| GRC-Engineer/awesome-security-GRC A curated list of resources for security Governance, Risk Management, Compliance, and Audit (GRC) professionals. It collects frameworks, bo… | 50 | 1077 | active |
| kbandla/APTnotes A curated repository of links to publicly available reports, whitepapers, and articles about Advanced Persistent Threat (APT) campaigns, so… | 32 | 3668 | maintenance |
| rubysec/ruby-advisory-db A community-maintained database of security vulnerability advisories for Ruby gems and Ruby implementations, stored as YAML files identifie… | 77 | 1070 | active |
| ossf/wg-best-practices-os-developers An OpenSSF working group repository curating security best practices, guides, and educational resources for open source developers. It host… | 77 | 1064 | active |
| n0kovo/awesome-password-cracking A curated awesome-list of tools, research papers, and projects related to password cracking and password security. It serves as a reference… | 74 | 1064 | active |
| system76/firmware-open System76's open source firmware distribution built on coreboot and EDK2 for their laptops and desktops. It provides build tooling, board de… | 77 | 1057 | active |
| FeeiCN/Security-PPT A curated collection of ~8,800 security conference slide decks, whitepapers, research reports, and free security books gathered from the in… | 10 | 3604 | maintenance |
| R00tS3c/DDOS-RootSec A curated archive of DDoS-related source code and tools, including Mirai and QBot botnet variants, scanners, exploits, Layer 4/7 attack met… | 32 | 1053 | active |
| teamssix/twiki T Wiki is a Chinese-language knowledge base focused on cloud security and cloud-native security, built with VuePress and deployable via Doc… | 32 | 1052 | active |
| MicrosoftLearning/AZ500-AzureSecurityTechnologies Official Microsoft Learning lab materials for the AZ-500 Azure Security Technologies certification course, containing hands-on lab instruct… | 77 | 1049 | active |
| trickest/resolvers A continuously updated, validated list of reliable public DNS resolver IP addresses maintained by Trickest. It ships three files: a main re… | 77 | 1048 | active |
| Silverr12/DMA-CFW-Guide A detailed guide for creating custom/modified DMA attack firmware based on pcileech-fpga for FPGA-based PCIe DMA cards. It walks through do… | 53 | 1041 | active |
| googleprojectzero/0days-in-the-wild A Google Project Zero maintained reference of 0-day vulnerabilities detected as exploited in-the-wild, including root cause analyses and a … | 76 | 1039 | active |
| enovella/TEE-reversing A curated list of public resources for learning about Trusted Execution Environments (TEE) and ARM TrustZone, including papers, blog posts,… | 60 | 1036 | active |
| qazbnm456/awesome-cve-poc A curated awesome-list collecting proof-of-concept exploits for known CVEs, organized by CVE identifier. It serves as a reference index lin… | 32 | 3527 | maintenance |
| bootmortis/iran-hosted-domains A continuously updated dataset of Iranian domains and services hosted inside Iran, packaged in formats for proxy clients like Clash, sing-b… | 94 | 1033 | active |
| safe6Sec/PentestDB A curated Chinese-language knowledge base collecting database exploitation techniques for penetration testing, covering MySQL, MSSQL, Oracl… | 32 | 1032 | active |
| android/security-samples An official Google repository of Android sample apps demonstrating security best practices, including the Play Integrity API, biometric log… | 75 | 1029 | active |
| fazgal0/free-sms-receivers A curated list of 16 free and paid SMS verification (temporary/virtual phone number) platforms for receiving OTP codes without exposing a p… | 38 | 1028 | active |
| safe6Sec/command A curated cheatsheet of commands commonly used in penetration testing and red team operations, covering command execution, file writing, an… | 65 | 1023 | active |
| mitre-attack/car The MITRE Cyber Analytics Repository (CAR) is a knowledge base of detection analytics based on the MITRE ATT&CK adversary model. Each analy… | 42 | 1022 | active |
| dirtycow/dirtycow.github.io The official documentation site and FAQ for Dirty COW (CVE-2016-5195), a privilege escalation vulnerability in the Linux kernel's copy-on-w… | 32 | 3467 | maintenance |
| chanakaudaya/solution-architecture-patterns A curated collection of reusable solution architecture patterns for enterprise software systems, covering vendor-neutral, industry-specific… | 23 | 3465 | maintenance |
| spawnmason/randar-explanation An explanation and writeup of 'Randar', a Minecraft exploit that uses LLL lattice reduction to crack the internal state of a reused java.ut… | 72 | 1020 | active |
| diafygi/webrtc-ips A demo and code snippet showing how WebRTC STUN requests in Firefox and Chrome expose a user's local and public IP addresses to JavaScript.… | 32 | 3453 | maintenance |
| W01fh4cker/LearnJavaMemshellFromZero A ~30,000-word Chinese-language tutorial that teaches Java memory webshell (memshell) techniques from absolute zero, covering Servlet, Filt… | 36 | 1015 | stable |
| cleverca22/not-os not-os is an operating system generator based on NixOS that, given a configuration, produces a small (~47 MB) read-only squashfs image with… | 73 | 1009 | active |
| maestron/botnets A curated collection of botnet source code samples gathered for educational and malware research purposes. It aggregates many historical bo… | 32 | 3335 | maintenance |
| fravoll/solidity-patterns A curated collection of design, security, upgradeability, and economic patterns for the Solidity smart contract language, each with code sa… | 32 | 3323 | maintenance |
| Xyl2k/TSA-Travel-Sentry-master-keys A collection of 3D-printable model files reproducing TSA Travel Sentry and Safe Skies master luggage keys, based on leaked key images and r… | 70 | 3302 | maintenance |
| ignis-sec/Pwdb-Public A curated dataset of password statistics and wordlists extracted from over one billion leaked credentials, including filtered lists like a … | 32 | 3286 | maintenance |
| kleiton0x00/Advanced-SQL-Injection-Cheatsheet A curated cheat sheet of advanced SQL injection queries and methodologies covering MySQL, PostgreSQL, Oracle, and MSSQL. It documents error… | 32 | 3248 | maintenance |
| wmnnd/nginx-certbot A boilerplate configuration combining nginx and certbot in a docker-compose setup, with an init script that fetches and renews Let's Encryp… | 32 | 3225 | maintenance |
| Ascotbe/Kernelhub A curated collection of kernel privilege escalation vulnerabilities for Windows, Linux, and macOS, including exploit code, compilation envi… | 23 | 3196 | maintenance |
| GrrrDog/Java-Deserialization-Cheat-Sheet A curated cheat sheet for pentesters and security researchers covering deserialization vulnerabilities across Java/JVM serialization librar… | 32 | 3182 | maintenance |
| breakwa11/gfw_whitelist A maintained whitelist-based PAC (Proxy Auto-Config) list for circumventing the Great Firewall, where all traffic goes through a proxy exce… | 32 | 3149 | maintenance |
| hookmaster/frida-all-in-one A Chinese-language handbook (《FRIDA操作手册》) collecting tutorials, scripts, and case studies for the Frida dynamic instrumentation toolkit. It… | 32 | 3148 | maintenance |
| szerhusenBC/jwt-spring-security-demo A demo application showing how to implement JWT-based authentication with Spring Security and Spring Boot 2, based on a minimal extraction … | 23 | 3106 | maintenance |
| mikeroyal/Digital-Forensics-Guide A curated guide to Digital Forensics covering tools, libraries, frameworks, books, tutorials, and certifications across computer, mobile, n… | 32 | 3104 | maintenance |
| google/eddystone Eddystone is Google's open protocol specification for Bluetooth Low Energy (BLE) proximity beacon message formats, including frame types li… | 10 | 3089 | maintenance |
| byt3bl33d3r/OffensiveNim A collection of experiments and examples demonstrating how to weaponize the Nim programming language for offensive security operations and … | 32 | 3087 | maintenance |
| l3m0n/pentest_study A Chinese-language study guide and tutorial repository for learning internal network (intranet) penetration testing from scratch, covering … | 32 | 3034 | maintenance |
| kylemcdonald/FreeWifi A tutorial repository explaining techniques for gaining internet access on public wireless networks, including MAC address randomization vi… | 32 | 3005 | maintenance |
| NoorQureshi/kali-linux-cheatsheet A community-maintained cheat sheet of Kali Linux commands and techniques for penetration testers, covering recon, enumeration, password cra… | 32 | 2988 | maintenance |
| cure53/H5SC A curated collection of HTML5-related XSS attack vectors, test files, and hidden testing features, browsable at html5sec.org. It serves as … | 32 | 2938 | maintenance |
| Kitsun3Sec/Pentest-Cheat-Sheets A curated collection of penetration testing cheat sheets containing command snippets for reconnaissance, exploitation, and post-exploitatio… | 32 | 2931 | maintenance |
| HackJava/HackJava A curated Chinese-language collection of Java security learning resources covering vulnerability analysis, code auditing, security tools, a… | 32 | 2893 | maintenance |
| s0md3v/be-a-hacker A curated guide and roadmap for becoming a self-taught hacker, covering hacking history, principles, and a learning path from computer scie… | 32 | 2886 | maintenance |
| opsdisk/the_cyber_plumbers_handbook A free PDF book, The Cyber Plumber's Handbook, teaching SSH tunneling, port redirection, and SOCKS proxying with practical penetration test… | 32 | 2881 | maintenance |
| ExpLangcn/NucleiTP A continuously updated aggregation of Nuclei vulnerability POC templates collected from across the web, organized by risk level. It automat… | 32 | 2877 | maintenance |
| sucong426/VPN A Chinese-language tutorial repository that walks users through renting an overseas VPS (e.g., Vultr) and deploying their own personal VPN/… | 32 | 2844 | maintenance |
| xuanhun/PythonHackingBook1 An open-source Chinese-language tutorial book, 'Python Hacking Programming: Rapid Introduction', teaching Python programming from basics th… | 32 | 2838 | maintenance |
| Voorivex/pentest-guide A curated penetration testing guide that reorganizes the OWASP Testing Guide v4 into 9 test classes with concrete test cases, plus 15 extra… | 32 | 2826 | maintenance |
| rewardone/OSCPRepo A consolidated collection of OSCP study resources, including CherryTree notebooks of commands and bookmarks, wordlists, and a Python recon … | 32 | 2752 | maintenance |
| vvmdx/Sec-Interview-4-2023 A community-curated collection of security-role interview questions and interview experience write-ups for the 2023 graduating class, prima… | 32 | 2743 | maintenance |
| freach/kubernetes-security-best-practice A curated best practice guide for securing Kubernetes clusters, written by practitioners running K8s in production. It covers general syste… | 32 | 2706 | maintenance |
| mandiant/red_team_tool_countermeasures A repository of detection rules (Snort, YARA, ClamAV, HXIOC) released by Mandiant/FireEye for countering red team tools and threats. Rules … | 10 | 2665 | maintenance |
| Kayzaks/HackingNeuralNetworks A short educational course (article plus Python exercises) on attacking and defending neural networks, covering techniques like backdooring… | 32 | 2635 | maintenance |
| sbousseaden/EVTX-ATTACK-SAMPLES A dataset of ~200 Windows EVTX event log samples mapped to MITRE ATT&CK tactics and techniques, covering attack and post-exploitation behav… | 32 | 2614 | maintenance |