Ross ROSS = Recommend OSS · open-source software intelligence for agents

resource: vulnerability-scanning

164 resources, primary matches first, then adoption-weighted; health v2 shown.

ResourceHealth v2StarsMaturity
tunz/js-vuln-db
A curated database of JavaScript engine vulnerabilities (CVEs) with proof-of-concept exploits, covering engines like V8, SpiderMonkey, Java…
322318maintenance
cider-security-research/cicd-goat
CI/CD Goat is a deliberately vulnerable CI/CD environment for learning CI/CD security through 11 capture-the-flag challenges. It runs local…
232295maintenance
transmissions11/solcurity
An opinionated security and code quality checklist standard for Solidity smart contracts, compiled from work by BoringCrypto, Mudit Gupta, …
322181maintenance
13o-bbr-bbq/machine_learning_security
A collection of Python source code and educational materials combining machine learning with cybersecurity, including a training course for…
692088maintenance
api0cradle/UltimateAppLockerByPassList
A curated collection of documented AppLocker bypass techniques for Windows, organized into verified, unverified, generic, and DLL-execution…
322081maintenance
YfryTchsGD/Log4jAttackSurface
A community-curated list documenting which manufacturers, products, and components were affected by the Log4j (Log4Shell) vulnerability, wi…
322069maintenance
0xSobky/HackVault
A curated collection of web security payloads, regexes, and offensive/defensive hacking notes hosted primarily in a wiki. It serves as a re…
322036maintenance
hongriSec/PHP-Audit-Labs
A Chinese-language tutorial series on PHP code auditing by HongRi Security, covering common PHP function pitfalls and vulnerabilities in fr…
321910maintenance
NCSC-NL/log4shell
A repository of operational information from the Dutch National Cyber Security Centre about the Log4Shell vulnerabilities in the Log4j logg…
101883maintenance
fabrimagic72/malware-samples
A dataset of real malware samples collected from distributed honeypots worldwide, including ransomware like WannaCry and botnets like Etern…
321840maintenance
offensive-security/exploitdb-bin-sploits
The legacy GitHub repository of Exploit-DB's binary exploit files (the old /sploits directory), now mirrored to GitLab. It archives compile…
101828maintenance
davincifans101/pinduoduo_backdoor_detailed_report
A detailed technical analysis report of malicious code and backdoors found in the Pinduoduo Android app, published as PDF documents in Chin…
301800maintenance
Hack-with-Github/Windows
A curated awesome-list of open-source tools for exploiting and post-exploiting Windows machines, covering privilege escalation, credential …
101797maintenance
LandGrey/webshell-detect-bypass
A collection of research articles and evasion-ready webshell source code (PHP, JSP, ASP) demonstrating techniques to bypass professional we…
321737maintenance
BlackFan/client-side-prototype-pollution
A curated collection of JavaScript libraries vulnerable to client-side prototype pollution via document.location parsing, along with useful…
321644maintenance
api0cradle/LOLBAS
A curated knowledge base documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' attack technique…
101613maintenance
ibaiw/2023Hvv
A curated Chinese-language intelligence feed aggregating vulnerability disclosures, POCs, and exploit write-ups collected during China's 20…
281485maintenance
dineshshetty/Android-InsecureBankv2
A deliberately vulnerable Android banking application designed for security enthusiasts and developers to learn Android insecurities by tes…
231470maintenance
xiaoZ-hc/redtool
A curated Chinese-language collection of red team tools and self-written shell scripts for offensive security testing, favoring DIY and les…
321420maintenance
threedr3am/JSP-WebShells
A curated collection of JSP webshell samples demonstrating various implementation techniques such as class loading, bytecode manipulation, …
321398maintenance
ptresearch/AttackDetection
A collection of Suricata IDS rules, PoC exploits, and network traffic samples from Positive Technologies' Attack Detection Team. The rulese…
101357maintenance
tenable/poc
A centralized collection of proof-of-concept code for vulnerabilities discovered by Tenable researchers, organized by vendor and product. I…
321330maintenance
MichaelKoczwara/Awesome-CobaltStrike-Defence
A curated awesome-list of defensive resources, tools, and detection techniques for countering Cobalt Strike, a commercial adversary simulat…
321301maintenance
research-virus/stuxnet
A public repository containing decompiled, readable C source code reconstructed from the Stuxnet (MyRTUs) malware binaries, including its d…
321279maintenance
ChALkeR/notes
A collection of public security research notes by ChALkeR, stored on GitHub in lieu of a blog. It covers vulnerability writeups on npm, Yar…
321275maintenance
nixawk/labs
A collection of vulnerability labs and proof-of-concept exploits for known CVEs, written primarily in Python. It serves as a security analy…
321162maintenance
pgaijin66/XSS-Payloads
A curated collection of advanced cross-site scripting (XSS) payloads intended for use in penetration testing. The payload lists can be load…
231141maintenance
payatu/diva-android
DIVA Android is an intentionally insecure Android application designed to teach developers, QA engineers, and security professionals about …
321140maintenance
wallarm/jwt-secrets
A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used fo…
371136maintenance
JoasASantos/Cloud-Security-Attacks
A curated collection of links to cloud security attack writeups covering AWS, Azure, and GCP, including privilege escalation, RCE, and misc…
321133maintenance
cisagov/log4j-affected-db
A CISA-maintained, community-sourced list of software affected by the Log4j vulnerability (CVE-2021-44228, Log4Shell), along with official …
101123maintenance
DawnFlame/POChouse
A curated collection of proof-of-concept (POC) and exploit (EXP) scripts for known N-day and 1-day vulnerabilities, oriented toward HVV red…
321108maintenance
oskarsve/ms-teams-rce
A security research writeup documenting zero-click, wormable remote code execution vulnerabilities in Microsoft Teams, reported to MSRC in …
321104maintenance
lcatro/Source-and-Fuzzing
A Chinese-language tutorial repository teaching source-code reading and fuzzing, covering black-box and white-box testing with real-world e…
321082maintenance
alphaSeclab/awesome-burp-suite
A curated awesome-list of Burp Suite resources, cataloging 400+ open-source Burp plugins along with 400+ posts and videos. Content is organ…
321039maintenance
guardrailsio/awesome-php-security
A curated awesome-list of PHP security resources, including tools for static analysis, framework hardening, vulnerability advisories, and e…
321034maintenance
pirate/sites-using-cloudflare
An archived dataset listing domains that used Cloudflare DNS at the time of the CloudBleed HTTPS traffic leak announcement in February 2017…
101925abandoned
Xyntax/1000php
A curated dataset of 1000 PHP code audit vulnerability cases extracted from publicly disclosed WooYun (乌云) vulnerabilities prior to July 20…
321106abandoned
vitalysim/Awesome-Hacking-Resources
A curated awesome-list of hacking, penetration testing, and AI red-teaming resources including courses, YouTube channels, labs, and tools. …
7017359active
edoardottt/awesome-hacker-search-engines
A curated awesome-list of search engines useful for penetration testing, vulnerability assessment, red/blue team operations, and bug bounty…
7611089active
infosecn1nja/Red-Teaming-Toolkit
A curated list of cutting-edge open-source security tools for red teamers and threat hunters, organized by attack lifecycle stages such as …
6910654active
sottlmarek/DevSecOps
A curated awesome-list style library of open-source DevSecOps tools and methodologies covering cloud and SDLC security. It organizes tools …
766855active
xairy/linux-kernel-exploitation
A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic…
766602active
secfigo/Awesome-Fuzzing
A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I…
325904active
devsecops/awesome-devsecops
A curated awesome-list of free and open-source DevSecOps resources, including tools, guidelines, presentations, training labs, podcasts, an…
325461active
riramar/Web-Attack-Cheat-Sheet
A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and explo…
764433active
0xor0ne/awesome-list
A curated awesome list of cybersecurity blog posts, write-ups, and papers organized by year, plus a companion list of security tools and re…
774068active
arainho/awesome-api-security
A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin…
103862active
vaib25vicky/awesome-mobile-security
A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes…
323525active
V33RU/awesome-connected-things-sec
A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin…
763524active
blaCCkHatHacEEkr/PENTESTING-BIBLE
A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi…
3213939maintenance
wgpsec/AboutSecurity
A large structured penetration testing knowledge base containing 200+ skill methodologies covering recon, exploitation, lateral movement, a…
651702active
euphrat1ca/Security-List
A curated Chinese-language security knowledge index (awesome-style list) covering the full red team attack lifecycle, from reconnaissance a…
321529active
SexyBeast233/SecBooks
A curated collection of Chinese-language cybersecurity articles and vulnerability write-ups aggregated from various security blogs and WeCh…
481308active
uphiago/recon-skills
A curated pack of Markdown skill files documenting reconnaissance and penetration-testing procedures for web apps, APIs, authentication, cl…
581199active
httpvoid/writeups
A collection of application security research writeups by the HTTPVoid team, covering their own CVEs and technical analyses of public n-day…
321199active
pe3zx/my-infosec-awesome
A curated awesome-list of links, resources, and tools covering information security topics such as adversary simulation, application securi…
741169active
1N3/IntruderPayloads
A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodol…
323970maintenance
NoorQureshi/kali-linux-cheatsheet
A community-maintained cheat sheet of Kali Linux commands and techniques for penetration testers, covering recon, enumeration, password cra…
322988maintenance
tiancode/learn-hacking
A curated collection of 83 Chinese-language tutorial notes on penetration testing, ethical hacking, and reverse engineering using Kali Linu…
702263maintenance
BaizeSec/bylibrary
BaizeSec's public vulnerability knowledge base (Baige Wenku) collecting POCs, EXPs, and security articles maintained by the BaizeSec securi…
321503maintenance
tennc/fuzzdb
A curated dictionary collection of attack patterns, payloads, and brute-force wordlists for black-box application fault injection and resou…
231399maintenance
sergey-pronin/Awesome-Vulnerability-Research
A curated awesome-list of resources for vulnerability research, including books, articles, courses, tools, write-ups, and methodologies. It…
321348maintenance
Kyuu-Ji/Awesome-Azure-Pentest
A curated awesome-list of tools, articles, labs, talks, and books for penetration testing and securing Microsoft Azure and Microsoft 365 en…
321220maintenance

← prev page 2 / 2