Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: vulnerability-scanning

164 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
swisskyrepo/PayloadsAllTheThings
A curated collection of payloads, bypasses, and exploitation techniques for web application security testing. It serves as a reference chea…
6680407active
The-Art-of-Hacking/h4cker
A large curated collection of cybersecurity resources covering ethical hacking, penetration testing, DFIR, AI security, exploit development…
7629141active
enaqx/awesome-pentest
A curated awesome-list of penetration testing and offensive security resources, tools, books, conferences, and training materials. It organ…
7527017active
sbilly/awesome-security
A curated, community-driven awesome list of security software, libraries, books, documents, and resources. It organizes tools across catego…
6014797active
projectdiscovery/nuclei-templates
A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misco…
9912849active
knownsec/404StarLink
404StarLink is a curated showcase program by Knownsec 404 Lab that collects, tracks, and promotes high-quality open-source security project…
7511131active
ashishb/android-security-awesome
A curated awesome-list of Android security-related resources, including tools, academic publications, and exploit/vulnerability references.…
769646active
toniblyx/my-arsenal-of-aws-security-tools
A curated list of open-source security tools for AWS, organized into defensive, offensive, purple teaming, continuous auditing, DFIR, and d…
739502active
We5ter/Scanners-Box
A curated awesome-list of 9,000+ open-source cybersecurity tools covering subdomain enumeration, SQL injection, red team/blue team tooling,…
769024active
LOLBAS-Project/LOLBAS
A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques…
778771active
trickest/cve
An automatically updated repository collecting publicly available proof-of-concept exploits for CVEs, organized by year into markdown files…
778026active
nomi-sec/PoC-in-GitHub
An automatically curated dataset and web service that collects proof-of-concept (PoC) exploit repositories from GitHub as CVEs are publishe…
778012active
guchangan1/All-Defense-Tool
A curated, weekly auto-updated collection of open-source offensive and defensive security tools, covering information gathering, vulnerabil…
777949active
0xInfection/Awesome-WAF
A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, d…
777592active
Mr-xn/Penetration_Testing_POC
A curated collection of penetration testing resources including POCs, exploits, scripts, privilege escalation tools, and write-ups for web …
777471active
infoslack/awesome-web-hacking
A curated awesome-list of resources for learning web application security, including books, documentation, tools, cheat sheets, courses, la…
767246active
vavkamil/awesome-bugbounty-tools
A curated awesome-list of bug bounty and web security tools, organized by recon and exploitation categories. It catalogs tools for subdomai…
766199active
EdOverflow/can-i-take-over-xyz
A community-maintained reference list of services vulnerable to subdomain takeover via dangling DNS records, with guidance on how to claim …
345788active
fabacab/awesome-cybersecurity-blueteam
A curated awesome-list of free and open-source resources, tools, and references for cybersecurity blue teams focused on defensive security.…
325541active
Awesome-POC
A curated knowledge base of 1k+ vulnerability Proof-of-Concept (PoC) writeups covering CVEs across CMSs, servers, and network devices. It i…
685171active
s0md3v/AwesomeXSS
A curated awesome-list of cross-site scripting (XSS) resources including payloads, polyglots, cheatsheets, tools, challenges, and papers. I…
325138active
google/security-research
A repository of security advisories and proof-of-concept exploits from Google security research affecting third-party (non-Google) software…
774615active
A-poc/BlueTeam-Tools
A curated collection of 70+ tools and resources for blue teaming and incident response, organized as a wiki-style cheatsheet. It covers thr…
764456active
Az0x7/vulnerability-Checklist
A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 40…
303634active
snoopysecurity/awesome-burp-extensions
A curated list of awesome Burp Suite extensions for web application security testing, organized by category such as scanners, fuzzers, and …
763439active
Bo0oM/fuzz.txt
A curated wordlist of potentially dangerous and sensitive file paths for web fuzzing and directory brute-forcing. It is commonly used with …
753321active
coreruleset/coreruleset
OWASP Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity, Coraza, or other compatible web application …
993242stable
neargle/re0-kubernetes-sec-archive
A curated archive of Kubernetes and container security attack/defense materials, including conference slides (BlackHat, HITB, KubeCon), pap…
553164active
blackorbird/APT_REPORT
A curated collection of APT (Advanced Persistent Threat) reports, malware samples, and special IOCs gathered from security vendors and rese…
773084active
hacksysteam/HackSysExtremeVulnerableDriver
HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable kernel driver for Windows and Linux designed for security researche…
263083active
lirantal/awesome-nodejs-security
A curated awesome-list of Node.js security resources, including tools for framework hardening, static and dynamic analysis, vulnerability a…
763027active
CVE List
An official mirror/cache of the CVE List maintained by the CVE Program, published as CVE Records in JSON 5 format. It is updated continuous…
952934active
Endermanch/MalwareDatabase
A curated GitHub collection of malware samples (rogue/PUP, trojans, ransomware, joke programs) archived with passwords for safe storage. It…
742903active
threedr3am/learnjavabug
A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jac…
322687active
JoyChou93/java-sec-code
A Spring Boot-based Java web application containing intentionally vulnerable code examples for common vulnerability types like SQLi, SSRF, …
232673active
Mr-xn/RedTeam_BlueTeam_HW
A curated collection of red team and blue team tools, documents, and reference materials for Chinese HW (HVV) attack-defense exercises. It …
762643active
Lifka/hacking-resources
A curated collection of hacking resources, cheat sheets, tools, scripts, and tutorials for offensive and defensive security professionals. …
322611active
coffeehb/Some-PoC-oR-ExP
A curated collection of proof-of-concept (PoC) scripts and exploits for various software vulnerabilities, written and gathered in Python. I…
452502active
github/advisory-database
A free, open-source database of security vulnerabilities, including CVEs and GitHub-originated security advisories, stored as individual fi…
772441active
jgamblin/Mirai-Source-Code
A mirror of the leaked Mirai botnet source code (bot, CnC server, loader) published for cybersecurity research, malware analysis, and indic…
539457maintenance
terjanq/Tiny-XSS-Payloads
A curated collection of minimal cross-site scripting (XSS) payloads organized by injection context, with an interactive demo site. It serve…
322386active
fuzzdb-project/fuzzdb
FuzzDB is a comprehensive open-source dictionary of attack payloads, predictable resource locations, and regex patterns for black-box appli…
328980maintenance
immunefi-team/Web3-Security-Library
A curated, collaborative library of resources for learning web3 and blockchain security, maintained by Immunefi. It aggregates guides, bloc…
382193active
eeeeeeeeee-code/POC
A curated backup of the wy876 vulnerability database collecting proof-of-concept exploits (POC/EXP) for a wide range of software, mostly Ch…
612180active
FriendsOfPHP/security-advisories
A community-maintained database of known security vulnerabilities in PHP Composer packages, stored as YAML files keyed by CVE or date. It c…
772139active
m14r41/PentestingEverything
A structured penetration testing knowledge base covering 23 security domains (web, mobile, API, cloud, network, Active Directory, SAST, Dev…
832044active
hslatman/awesome-industrial-control-system-security
A curated awesome-list of resources, tools, and references for Industrial Control System (ICS) and SCADA security. It catalogs tools for IC…
532004active
eset/malware-ioc
A repository of Indicators of Compromise (IOCs) published by ESET researchers from their malware investigations. It includes YARA rules and…
721979active
yogsec/Hacking-Tools
A curated list of penetration testing and ethical hacking tools organized by category, drawing from Kali Linux and other notable sources. I…
651892active
safe6Sec/Fastjson
A curated collection of Fastjson exploitation techniques, payloads, and fingerprinting tricks for Java JSON deserialization vulnerabilities…
321860active
lutfumertceylan/top25-parameter
OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XS…
231847stable
ZhangZhuoSJTU/Web3Bugs
A curated dataset of exploitable bugs in Solidity smart contracts, extracted from code4rena audit contests and classified by bug nature (ou…
431819active
arch3rPro/PentestTools
A curated awesome-list cataloging open-source penetration testing tools, organized by category and modeled on the Kali Tools listing. It se…
671763active
magicsword-io/LOLDrivers
LOLDrivers is a community-maintained curated dataset of vulnerable and malicious Windows drivers abused by adversaries (BYOVD attacks), wit…
651763active
protectai/ai-exploits
A collection of real-world AI/ML exploits and scanning templates for responsibly disclosed vulnerabilities in machine learning tools and in…
271746active
B3nac/Android-Reports-and-Resources
A curated list of disclosed HackerOne bug bounty reports and security resources focused on Android application vulnerabilities. It organize…
511706active
LandGrey/SpringBootVulExploit
A curated collection of Spring Boot vulnerability learning materials, exploitation methods, and a black-box security assessment checklist. …
326144maintenance
github/securitylab
The main repository of GitHub Security Lab, containing security research documentation, CodeQL query examples, and proof-of-concept exploit…
621626active
phishdestroy/destroylist
A continuously updated phishing and scam domain blocklist with 208k+ curated threats, distributed in multiple formats (hosts, AdBlock, Dnsm…
721624active
psiinon/open-source-web-scanners
A curated list of open source web security scanners hosted on GitHub and GitLab, ordered by stars. It serves as a discovery resource coveri…
411615active
mazen160/secrets-patterns-db
Secrets Patterns DB is the largest open-source database of over 1600 tested regular expressions for detecting secrets, API keys, passwords,…
471609active
rapid7/metasploitable3
Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit developme…
355681maintenance
SecWiki/linux-kernel-exploits
A curated collection of Linux kernel privilege escalation exploits organized by CVE, with descriptions and affected kernel versions. It ser…
325650maintenance
davinci1010/pinduoduo_backdoor
A security research repository documenting analysis of privilege-escalation code embedded in the Pinduoduo Android APK, including a VMP-pac…
305448maintenance
elastic/protections-artifacts
Elastic's open repository of endpoint detection content, including EQL-based behavior rules, YARA malware rules, and ransomware protection …
761482active
vavkamil/awesome-vulnerable-apps
A curated awesome-list of intentionally vulnerable applications, VMs, and CTF platforms for practicing security skills. It covers web explo…
711471active
Cyber-Guy1/API-SecurityEmpire
A curated collection of mindmaps, tips, and resources for API security and API penetration testing, based on the OWASP API Top 10. It cover…
321445active
BushidoUK/Ransomware-Tool-Matrix
A curated knowledge base mapping the tools used by ransomware and extortion gangs, organized by category (RMM, exfiltration, credential the…
651434active
bollwarm/SecToolSet
A curated collection of GitHub security-related tools and projects, organized into categories like scanners, penetration testing, CTF pract…
671423active
microsoft/MSRC-Security-Research
A repository hosting security research published by the Microsoft Security Response Center (MSRC). It contains research papers, tools, and …
321392active
0xMarcio/cve
A continuously updated hub aggregating the latest CVEs alongside links to their public Proof-of-Concept exploit repositories, with a web in…
691365active
Yara-Rules/rules
A community-maintained repository of YARA rules for malware and threat detection, organized into categories like anti-debug/anti-VM, CVEs, …
324879maintenance
pashov/audits
A public repository collecting smart contract security audit reports published by the Pashov Audit Group, organized by protocol category (l…
761314active
topscoder/nuclei-wordfence-cve
A collection of 80,000+ Nuclei vulnerability-scanning templates for WordPress core, plugins, and themes, generated daily from Wordfence thr…
781278active
ax1sX/SecurityList
A curated collection of web security and code audit resources, focused on Chinese enterprise software (OA systems), common Java components,…
321262active
ybdt/exp-hub
A curated collection of proof-of-concept (PoC) and exploit (Exp) scripts for reproducing known vulnerabilities, written primarily in HTML/J…
761253active
CHYbeta/Web-Security-Learning
A curated collection of links and learning materials on web security, covering SQL injection, XSS, CSRF, SSRF, XXE, file upload vulnerabili…
324299maintenance
emadshanab/Nuclei-Templates-Collection
A curated collection of links to community Nuclei template repositories, aggregating vulnerability detection templates for the Nuclei scann…
581225active
ashishb/android-malware
A curated collection of over 300 live Android malware samples gathered from multiple sources and mailing lists. It serves as a research dat…
591222active
birdhan/SecurityProduct
A curated awesome-list collecting open-source security products and projects, including IDS, IPS, WAF, honeypots, threat intelligence, vuln…
621190active
yeswehack/vulnerable-code-snippets
A collection of intentionally vulnerable code snippets (mostly PHP) published weekly by YesWeHack for practicing secure code analysis. Each…
621176active
subat0mik/Misconfiguration-Manager
A central knowledge base documenting known Microsoft Configuration Manager (SCCM/ConfigMgr) attack tradecraft along with defensive and hard…
711167active
indianajson/can-i-take-over-dns
A curated reference list of DNS providers and whether domains pointing to their nameservers are vulnerable to DNS (zone) takeover, with fin…
761103active
Medicean/VulApps
VulApps is a collection of Dockerized vulnerability environments (CVE-based, e.g. Struts2, Spring, Tomcat, Drupal) plus security tool envir…
103783maintenance
SourByte05/Vulnerability-Wiki-PoC
A continuously updated archive of 1-day/N-day vulnerability PoCs and reproduction write-ups focused on high-value enterprise assets such as…
611099active
scadastrangelove/awesome-ai-security-tools
A curated awesome-list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. It catalogs tools ac…
591095active
nixawk/pentest-wiki
A free online knowledge library (wiki) of penetration testing and security resources, organized into sections like information gathering, v…
323751maintenance
rubysec/ruby-advisory-db
A community-maintained database of security vulnerability advisories for Ruby gems and Ruby implementations, stored as YAML files identifie…
771070active
R00tS3c/DDOS-RootSec
A curated archive of DDoS-related source code and tools, including Mirai and QBot botnet variants, scanners, exploits, Layer 4/7 attack met…
321053active
qazbnm456/awesome-cve-poc
A curated awesome-list collecting proof-of-concept exploits for known CVEs, organized by CVE identifier. It serves as a reference index lin…
323527maintenance
Ascotbe/Kernelhub
A curated collection of kernel privilege escalation vulnerabilities for Windows, Linux, and macOS, including exploit code, compilation envi…
233196maintenance
HackJava/HackJava
A curated Chinese-language collection of Java security learning resources covering vulnerability analysis, code auditing, security tools, a…
322893maintenance
ExpLangcn/NucleiTP
A continuously updated aggregation of Nuclei vulnerability POC templates collected from across the web, organized by risk level. It automat…
322877maintenance
Voorivex/pentest-guide
A curated penetration testing guide that reorganizes the OWASP Testing Guide v4 into 9 test classes with concrete test cases, plus 15 extra…
322826maintenance
wtsxDev/Penetration-Testing
A curated awesome-list of penetration testing resources, including tools, distributions, books, courses, vulnerability databases, and secur…
322783maintenance
mandiant/red_team_tool_countermeasures
A repository of detection rules (Snort, YARA, ClamAV, HXIOC) released by Mandiant/FireEye for countering red team tools and threats. Rules …
102665maintenance
r0eXpeR/redteam_vul
A curated Chinese-language reference list of high-value vulnerabilities commonly encountered during red team operations, covering systems l…
322524maintenance
nebgnahz/awesome-iot-hacks
A curated awesome-list of documented IoT hacks, security vulnerabilities, research reports, and communities. It serves as a reference catal…
322425maintenance
Bypass007/Safety-Project-Collection
A curated Chinese-language list of excellent open-source security projects aimed at helping enterprise (blue-team/defender) security practi…
322387maintenance
helloexp/0day
A continuously updated collection of exploits (EXP) and proofs-of-concept (POC) for vulnerabilities in various CMS platforms, systems, and …
322364maintenance

page 1 / 2 next →