Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: security

1184 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
RPISEC/Malware
Course materials for RPISEC's university-level Malware Analysis course (CSCI 4976), built around the Practical Malware Analysis book. It in…
234059maintenance
subat0mik/Misconfiguration-Manager
A central knowledge base documenting known Microsoft Configuration Manager (SCCM/ConfigMgr) attack tradecraft along with defensive and hard…
711167active
Zeyad-Azima/Offensive-Resources
A large curated collection of learning resources and labs for offensive security, covering topics like infrastructure, web, mobile, API, cl…
481167active
aws-samples/aws-security-reference-architecture-examples
A code library of example solutions from AWS that demonstrates how to deploy security services across a multi-account AWS Organizations env…
661149active
foospidy/payloads
A curated collection of web attack payloads (XSS, SQLi, CRLF, open redirect, password lists, and more) aggregated from many well-known secu…
323979maintenance
HuskyHacks/PMAT-labs
A collection of lab exercises and live malware samples accompanying the Practical Malware Analysis & Triage (PMAT) course. The repository i…
641147active
1N3/IntruderPayloads
A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodol…
323970maintenance
certsocietegenerale/IRM
A collection of operational incident response cheat sheets (IRM-2022) published by CERT Societe Generale with CERT aDvens. Each methodology…
391140active
sbwml/halflife-list
A collection of Adblock/uBlock Origin filter lists that merge popular rulesets like Easylist, EasylistChina, EasyPrivacy, and CJX's Annoyan…
771139active
learnk8s/kubernetes-production-best-practices
A free, open checklist of Kubernetes best practices for releasing applications to production, covering application behavior, manifests, sec…
691136active
ethereum/devp2p
The official specifications for Ethereum's peer-to-peer networking protocols, including node discovery (v4/v5), DNS node lists, Ethereum No…
761127active
Repcz/Tool
A curated repository of proxy rule-sets (Netflix, Telegram, AI services, China domains/IPs, etc.) and configuration profiles for proxy clie…
721126active
S3N4T0R-0X0/APTs-Adversary-Simulation
A curated collection of simulated APT campaigns modeled on real-world state-sponsored threat groups from Russia, China, Iran, and North Kor…
681123active
jakespringer/angr_ctf
A collection of capture-the-flag style challenges designed to teach binary analysis and symbolic execution with the angr framework. It incl…
321123active
The-Hacker-Recipes/The-Hacker-Recipes
The Hacker Recipes is a free and open-source collection of technical guides on hacking topics, with a focus on Active Directory and web ser…
741118active
kinopeee/cursorrules
A collection of custom instructions and workflow commands optimized for the Cursor AI code editor, provided in both Japanese and English. I…
551116active
bkerler/exploit_me
A deliberately vulnerable ARM/ARM64 C++ application offering 29 CTF-style exploitation levels covering techniques like stack overflow, form…
801106active
mikeroyal/Open-Source-Security-Guide
A curated open-source guide to security covering standards (FIPS, CIS, FedRAMP, FISMA), frameworks, threat models, encryption, benchmarks, …
451106active
indianajson/can-i-take-over-dns
A curated reference list of DNS providers and whether domains pointing to their nameservers are vulnerable to DNS (zone) takeover, with fin…
761103active
digitalknk/openclaw-runbook
An unofficial, opinionated runbook (built as an Astro documentation site) for operating OpenClaw AI agents day to day with a focus on cost …
531103active
conwnet/wpa-dictionary
A WPA/WPA2 password dictionary (wordlist) dataset intended for Wi-Fi password cracking, paired with a tutorial on using aircrack-ng on Linu…
323794maintenance
mdecrevoisier/Microsoft-eventlog-mindmap
A collection of mindmaps (PDF/PNG/SVG) detailing the auditing capacities and event logs of Microsoft products including Windows, Windows Se…
551102active
disclose/bug-bounty-platforms
A community-maintained, CC0-licensed catalog of every known bug bounty platform, vulnerability disclosure platform, and crowdsourced securi…
761101active
rodolfomarianocy/OSCP-Tricks
A curated OSCP preparation guide collecting tricks, tutorials, exercises, and machine recommendations for penetration testing. It organizes…
631101active
lovelyyoshino/Halcon_licenses
A collection of Halcon (MVTec machine vision software) license .dat files with installation instructions for placing them in the Halcon lic…
751100active
Medicean/VulApps
VulApps is a collection of Dockerized vulnerability environments (CVE-based, e.g. Struts2, Spring, Tomcat, Drupal) plus security tool envir…
103783maintenance
aws-samples/aws-incident-response-playbooks
A collection of sample incident response playbooks for AWS environments, aligned to NIST SP 800-61r3 and CSF 2.0. It provides templates and…
661099active
SourByte05/Vulnerability-Wiki-PoC
A continuously updated archive of 1-day/N-day vulnerability PoCs and reproduction write-ups focused on high-value enterprise assets such as…
611099active
OWASP/DevSecOpsGuideline
An OWASP project providing a guideline for embedding security into DevOps/CI-CD pipelines, covering practices like SAST, DAST, SCA, IaC sca…
741098active
LINCnil/Guide-RGPD-du-developpeur
An open-source GDPR compliance guide for developers published by the French data protection authority (CNIL). It consists of 18 thematic fa…
231097stable
scadastrangelove/awesome-ai-security-tools
A curated awesome-list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. It catalogs tools ac…
591095active
crypto101/book
Crypto 101 is a free, open-source introductory book on cryptography aimed at programmers, covering ciphers, hash functions, MACs, public-ke…
233765maintenance
microsoft/shell-intune-samples
A Microsoft-maintained collection of sample shell scripts for managing macOS and Linux devices through Microsoft Intune. It provides educat…
681092active
minaminao/ctf-blockchain
A curated collection of 200+ blockchain CTF challenges and wargames with categorized writeups and solutions, focused on Ethereum, Solidity,…
531092active
hak5/omg-payloads
The official community payload library for Hak5's O.MG line of covert USB attack devices (Cable, Adapter, Plug, Unblocker). It contains Duc…
571090active
Kim-Hammar/awesome-rl-for-cybersecurity
A curated awesome-list of resources for applying reinforcement learning to cyber security, including RL environments, papers, books, blog p…
741085active
platomav/CPUMicrocodes
A curated repository of the latest production CPU microcode binaries for Intel, AMD, VIA, and Freescale processors, collected from official…
711084active
javaweb-sec/javaweb-sec
An open-source knowledge base and training project summarizing Java Web security topics, published as a GitBook at javasec.org. It explains…
701083active
BC-SECURITY/Beginners-Guide-to-Obfuscation
A hands-on workshop and course material from BC Security teaching malware obfuscation and defense evasion techniques on Windows. It covers …
321080active
disclose/diodb
An open, CC0-licensed dataset of vulnerability disclosure programs (VDPs) and bug bounty programs, including their safe-harbor status, poli…
761079active
max-baz/dotfiles
A personal dotfiles repository managing NixOS system and user configurations declaratively with Nix flakes and home-manager. It configures …
761079active
GRC-Engineer/awesome-security-GRC
A curated list of resources for security Governance, Risk Management, Compliance, and Audit (GRC) professionals. It collects frameworks, bo…
501077active
kbandla/APTnotes
A curated repository of links to publicly available reports, whitepapers, and articles about Advanced Persistent Threat (APT) campaigns, so…
323668maintenance
rubysec/ruby-advisory-db
A community-maintained database of security vulnerability advisories for Ruby gems and Ruby implementations, stored as YAML files identifie…
771070active
ossf/wg-best-practices-os-developers
An OpenSSF working group repository curating security best practices, guides, and educational resources for open source developers. It host…
771064active
n0kovo/awesome-password-cracking
A curated awesome-list of tools, research papers, and projects related to password cracking and password security. It serves as a reference…
741064active
system76/firmware-open
System76's open source firmware distribution built on coreboot and EDK2 for their laptops and desktops. It provides build tooling, board de…
771057active
FeeiCN/Security-PPT
A curated collection of ~8,800 security conference slide decks, whitepapers, research reports, and free security books gathered from the in…
103604maintenance
R00tS3c/DDOS-RootSec
A curated archive of DDoS-related source code and tools, including Mirai and QBot botnet variants, scanners, exploits, Layer 4/7 attack met…
321053active
teamssix/twiki
T Wiki is a Chinese-language knowledge base focused on cloud security and cloud-native security, built with VuePress and deployable via Doc…
321052active
MicrosoftLearning/AZ500-AzureSecurityTechnologies
Official Microsoft Learning lab materials for the AZ-500 Azure Security Technologies certification course, containing hands-on lab instruct…
771049active
trickest/resolvers
A continuously updated, validated list of reliable public DNS resolver IP addresses maintained by Trickest. It ships three files: a main re…
771048active
Silverr12/DMA-CFW-Guide
A detailed guide for creating custom/modified DMA attack firmware based on pcileech-fpga for FPGA-based PCIe DMA cards. It walks through do…
531041active
googleprojectzero/0days-in-the-wild
A Google Project Zero maintained reference of 0-day vulnerabilities detected as exploited in-the-wild, including root cause analyses and a …
761039active
enovella/TEE-reversing
A curated list of public resources for learning about Trusted Execution Environments (TEE) and ARM TrustZone, including papers, blog posts,…
601036active
qazbnm456/awesome-cve-poc
A curated awesome-list collecting proof-of-concept exploits for known CVEs, organized by CVE identifier. It serves as a reference index lin…
323527maintenance
bootmortis/iran-hosted-domains
A continuously updated dataset of Iranian domains and services hosted inside Iran, packaged in formats for proxy clients like Clash, sing-b…
941033active
safe6Sec/PentestDB
A curated Chinese-language knowledge base collecting database exploitation techniques for penetration testing, covering MySQL, MSSQL, Oracl…
321032active
android/security-samples
An official Google repository of Android sample apps demonstrating security best practices, including the Play Integrity API, biometric log…
751029active
fazgal0/free-sms-receivers
A curated list of 16 free and paid SMS verification (temporary/virtual phone number) platforms for receiving OTP codes without exposing a p…
381028active
safe6Sec/command
A curated cheatsheet of commands commonly used in penetration testing and red team operations, covering command execution, file writing, an…
651023active
mitre-attack/car
The MITRE Cyber Analytics Repository (CAR) is a knowledge base of detection analytics based on the MITRE ATT&CK adversary model. Each analy…
421022active
dirtycow/dirtycow.github.io
The official documentation site and FAQ for Dirty COW (CVE-2016-5195), a privilege escalation vulnerability in the Linux kernel's copy-on-w…
323467maintenance
chanakaudaya/solution-architecture-patterns
A curated collection of reusable solution architecture patterns for enterprise software systems, covering vendor-neutral, industry-specific…
233465maintenance
spawnmason/randar-explanation
An explanation and writeup of 'Randar', a Minecraft exploit that uses LLL lattice reduction to crack the internal state of a reused java.ut…
721020active
diafygi/webrtc-ips
A demo and code snippet showing how WebRTC STUN requests in Firefox and Chrome expose a user's local and public IP addresses to JavaScript.…
323453maintenance
W01fh4cker/LearnJavaMemshellFromZero
A ~30,000-word Chinese-language tutorial that teaches Java memory webshell (memshell) techniques from absolute zero, covering Servlet, Filt…
361015stable
cleverca22/not-os
not-os is an operating system generator based on NixOS that, given a configuration, produces a small (~47 MB) read-only squashfs image with…
731009active
maestron/botnets
A curated collection of botnet source code samples gathered for educational and malware research purposes. It aggregates many historical bo…
323335maintenance
fravoll/solidity-patterns
A curated collection of design, security, upgradeability, and economic patterns for the Solidity smart contract language, each with code sa…
323323maintenance
Xyl2k/TSA-Travel-Sentry-master-keys
A collection of 3D-printable model files reproducing TSA Travel Sentry and Safe Skies master luggage keys, based on leaked key images and r…
703302maintenance
ignis-sec/Pwdb-Public
A curated dataset of password statistics and wordlists extracted from over one billion leaked credentials, including filtered lists like a …
323286maintenance
kleiton0x00/Advanced-SQL-Injection-Cheatsheet
A curated cheat sheet of advanced SQL injection queries and methodologies covering MySQL, PostgreSQL, Oracle, and MSSQL. It documents error…
323248maintenance
wmnnd/nginx-certbot
A boilerplate configuration combining nginx and certbot in a docker-compose setup, with an init script that fetches and renews Let's Encryp…
323225maintenance
Ascotbe/Kernelhub
A curated collection of kernel privilege escalation vulnerabilities for Windows, Linux, and macOS, including exploit code, compilation envi…
233196maintenance
GrrrDog/Java-Deserialization-Cheat-Sheet
A curated cheat sheet for pentesters and security researchers covering deserialization vulnerabilities across Java/JVM serialization librar…
323182maintenance
breakwa11/gfw_whitelist
A maintained whitelist-based PAC (Proxy Auto-Config) list for circumventing the Great Firewall, where all traffic goes through a proxy exce…
323149maintenance
hookmaster/frida-all-in-one
A Chinese-language handbook (《FRIDA操作手册》) collecting tutorials, scripts, and case studies for the Frida dynamic instrumentation toolkit. It…
323148maintenance
szerhusenBC/jwt-spring-security-demo
A demo application showing how to implement JWT-based authentication with Spring Security and Spring Boot 2, based on a minimal extraction …
233106maintenance
mikeroyal/Digital-Forensics-Guide
A curated guide to Digital Forensics covering tools, libraries, frameworks, books, tutorials, and certifications across computer, mobile, n…
323104maintenance
google/eddystone
Eddystone is Google's open protocol specification for Bluetooth Low Energy (BLE) proximity beacon message formats, including frame types li…
103089maintenance
byt3bl33d3r/OffensiveNim
A collection of experiments and examples demonstrating how to weaponize the Nim programming language for offensive security operations and …
323087maintenance
l3m0n/pentest_study
A Chinese-language study guide and tutorial repository for learning internal network (intranet) penetration testing from scratch, covering …
323034maintenance
kylemcdonald/FreeWifi
A tutorial repository explaining techniques for gaining internet access on public wireless networks, including MAC address randomization vi…
323005maintenance
NoorQureshi/kali-linux-cheatsheet
A community-maintained cheat sheet of Kali Linux commands and techniques for penetration testers, covering recon, enumeration, password cra…
322988maintenance
cure53/H5SC
A curated collection of HTML5-related XSS attack vectors, test files, and hidden testing features, browsable at html5sec.org. It serves as …
322938maintenance
Kitsun3Sec/Pentest-Cheat-Sheets
A curated collection of penetration testing cheat sheets containing command snippets for reconnaissance, exploitation, and post-exploitatio…
322931maintenance
HackJava/HackJava
A curated Chinese-language collection of Java security learning resources covering vulnerability analysis, code auditing, security tools, a…
322893maintenance
s0md3v/be-a-hacker
A curated guide and roadmap for becoming a self-taught hacker, covering hacking history, principles, and a learning path from computer scie…
322886maintenance
opsdisk/the_cyber_plumbers_handbook
A free PDF book, The Cyber Plumber's Handbook, teaching SSH tunneling, port redirection, and SOCKS proxying with practical penetration test…
322881maintenance
ExpLangcn/NucleiTP
A continuously updated aggregation of Nuclei vulnerability POC templates collected from across the web, organized by risk level. It automat…
322877maintenance
sucong426/VPN
A Chinese-language tutorial repository that walks users through renting an overseas VPS (e.g., Vultr) and deploying their own personal VPN/…
322844maintenance
xuanhun/PythonHackingBook1
An open-source Chinese-language tutorial book, 'Python Hacking Programming: Rapid Introduction', teaching Python programming from basics th…
322838maintenance
Voorivex/pentest-guide
A curated penetration testing guide that reorganizes the OWASP Testing Guide v4 into 9 test classes with concrete test cases, plus 15 extra…
322826maintenance
rewardone/OSCPRepo
A consolidated collection of OSCP study resources, including CherryTree notebooks of commands and bookmarks, wordlists, and a Python recon …
322752maintenance
vvmdx/Sec-Interview-4-2023
A community-curated collection of security-role interview questions and interview experience write-ups for the 2023 graduating class, prima…
322743maintenance
freach/kubernetes-security-best-practice
A curated best practice guide for securing Kubernetes clusters, written by practitioners running K8s in production. It covers general syste…
322706maintenance
mandiant/red_team_tool_countermeasures
A repository of detection rules (Snort, YARA, ClamAV, HXIOC) released by Mandiant/FireEye for countering red team tools and threats. Rules …
102665maintenance
Kayzaks/HackingNeuralNetworks
A short educational course (article plus Python exercises) on attacking and defending neural networks, covering techniques like backdooring…
322635maintenance
sbousseaden/EVTX-ATTACK-SAMPLES
A dataset of ~200 Windows EVTX event log samples mapped to MITRE ATT&CK tactics and techniques, covering attack and post-exploitation behav…
322614maintenance

← prev page 8 / 12 next →