resource: vulnerability-scanning
164 resources, primary matches first, then adoption-weighted; health v2 shown.
| Resource | Health v2 | Stars | Maturity |
|---|---|---|---|
| tunz/js-vuln-db A curated database of JavaScript engine vulnerabilities (CVEs) with proof-of-concept exploits, covering engines like V8, SpiderMonkey, Java… | 32 | 2318 | maintenance |
| cider-security-research/cicd-goat CI/CD Goat is a deliberately vulnerable CI/CD environment for learning CI/CD security through 11 capture-the-flag challenges. It runs local… | 23 | 2295 | maintenance |
| transmissions11/solcurity An opinionated security and code quality checklist standard for Solidity smart contracts, compiled from work by BoringCrypto, Mudit Gupta, … | 32 | 2181 | maintenance |
| 13o-bbr-bbq/machine_learning_security A collection of Python source code and educational materials combining machine learning with cybersecurity, including a training course for… | 69 | 2088 | maintenance |
| api0cradle/UltimateAppLockerByPassList A curated collection of documented AppLocker bypass techniques for Windows, organized into verified, unverified, generic, and DLL-execution… | 32 | 2081 | maintenance |
| YfryTchsGD/Log4jAttackSurface A community-curated list documenting which manufacturers, products, and components were affected by the Log4j (Log4Shell) vulnerability, wi… | 32 | 2069 | maintenance |
| 0xSobky/HackVault A curated collection of web security payloads, regexes, and offensive/defensive hacking notes hosted primarily in a wiki. It serves as a re… | 32 | 2036 | maintenance |
| hongriSec/PHP-Audit-Labs A Chinese-language tutorial series on PHP code auditing by HongRi Security, covering common PHP function pitfalls and vulnerabilities in fr… | 32 | 1910 | maintenance |
| NCSC-NL/log4shell A repository of operational information from the Dutch National Cyber Security Centre about the Log4Shell vulnerabilities in the Log4j logg… | 10 | 1883 | maintenance |
| fabrimagic72/malware-samples A dataset of real malware samples collected from distributed honeypots worldwide, including ransomware like WannaCry and botnets like Etern… | 32 | 1840 | maintenance |
| offensive-security/exploitdb-bin-sploits The legacy GitHub repository of Exploit-DB's binary exploit files (the old /sploits directory), now mirrored to GitLab. It archives compile… | 10 | 1828 | maintenance |
| davincifans101/pinduoduo_backdoor_detailed_report A detailed technical analysis report of malicious code and backdoors found in the Pinduoduo Android app, published as PDF documents in Chin… | 30 | 1800 | maintenance |
| Hack-with-Github/Windows A curated awesome-list of open-source tools for exploiting and post-exploiting Windows machines, covering privilege escalation, credential … | 10 | 1797 | maintenance |
| LandGrey/webshell-detect-bypass A collection of research articles and evasion-ready webshell source code (PHP, JSP, ASP) demonstrating techniques to bypass professional we… | 32 | 1737 | maintenance |
| BlackFan/client-side-prototype-pollution A curated collection of JavaScript libraries vulnerable to client-side prototype pollution via document.location parsing, along with useful… | 32 | 1644 | maintenance |
| api0cradle/LOLBAS A curated knowledge base documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' attack technique… | 10 | 1613 | maintenance |
| ibaiw/2023Hvv A curated Chinese-language intelligence feed aggregating vulnerability disclosures, POCs, and exploit write-ups collected during China's 20… | 28 | 1485 | maintenance |
| dineshshetty/Android-InsecureBankv2 A deliberately vulnerable Android banking application designed for security enthusiasts and developers to learn Android insecurities by tes… | 23 | 1470 | maintenance |
| xiaoZ-hc/redtool A curated Chinese-language collection of red team tools and self-written shell scripts for offensive security testing, favoring DIY and les… | 32 | 1420 | maintenance |
| threedr3am/JSP-WebShells A curated collection of JSP webshell samples demonstrating various implementation techniques such as class loading, bytecode manipulation, … | 32 | 1398 | maintenance |
| ptresearch/AttackDetection A collection of Suricata IDS rules, PoC exploits, and network traffic samples from Positive Technologies' Attack Detection Team. The rulese… | 10 | 1357 | maintenance |
| tenable/poc A centralized collection of proof-of-concept code for vulnerabilities discovered by Tenable researchers, organized by vendor and product. I… | 32 | 1330 | maintenance |
| MichaelKoczwara/Awesome-CobaltStrike-Defence A curated awesome-list of defensive resources, tools, and detection techniques for countering Cobalt Strike, a commercial adversary simulat… | 32 | 1301 | maintenance |
| research-virus/stuxnet A public repository containing decompiled, readable C source code reconstructed from the Stuxnet (MyRTUs) malware binaries, including its d… | 32 | 1279 | maintenance |
| ChALkeR/notes A collection of public security research notes by ChALkeR, stored on GitHub in lieu of a blog. It covers vulnerability writeups on npm, Yar… | 32 | 1275 | maintenance |
| nixawk/labs A collection of vulnerability labs and proof-of-concept exploits for known CVEs, written primarily in Python. It serves as a security analy… | 32 | 1162 | maintenance |
| pgaijin66/XSS-Payloads A curated collection of advanced cross-site scripting (XSS) payloads intended for use in penetration testing. The payload lists can be load… | 23 | 1141 | maintenance |
| payatu/diva-android DIVA Android is an intentionally insecure Android application designed to teach developers, QA engineers, and security professionals about … | 32 | 1140 | maintenance |
| wallarm/jwt-secrets A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used fo… | 37 | 1136 | maintenance |
| JoasASantos/Cloud-Security-Attacks A curated collection of links to cloud security attack writeups covering AWS, Azure, and GCP, including privilege escalation, RCE, and misc… | 32 | 1133 | maintenance |
| cisagov/log4j-affected-db A CISA-maintained, community-sourced list of software affected by the Log4j vulnerability (CVE-2021-44228, Log4Shell), along with official … | 10 | 1123 | maintenance |
| DawnFlame/POChouse A curated collection of proof-of-concept (POC) and exploit (EXP) scripts for known N-day and 1-day vulnerabilities, oriented toward HVV red… | 32 | 1108 | maintenance |
| oskarsve/ms-teams-rce A security research writeup documenting zero-click, wormable remote code execution vulnerabilities in Microsoft Teams, reported to MSRC in … | 32 | 1104 | maintenance |
| lcatro/Source-and-Fuzzing A Chinese-language tutorial repository teaching source-code reading and fuzzing, covering black-box and white-box testing with real-world e… | 32 | 1082 | maintenance |
| alphaSeclab/awesome-burp-suite A curated awesome-list of Burp Suite resources, cataloging 400+ open-source Burp plugins along with 400+ posts and videos. Content is organ… | 32 | 1039 | maintenance |
| guardrailsio/awesome-php-security A curated awesome-list of PHP security resources, including tools for static analysis, framework hardening, vulnerability advisories, and e… | 32 | 1034 | maintenance |
| pirate/sites-using-cloudflare An archived dataset listing domains that used Cloudflare DNS at the time of the CloudBleed HTTPS traffic leak announcement in February 2017… | 10 | 1925 | abandoned |
| Xyntax/1000php A curated dataset of 1000 PHP code audit vulnerability cases extracted from publicly disclosed WooYun (乌云) vulnerabilities prior to July 20… | 32 | 1106 | abandoned |
| vitalysim/Awesome-Hacking-Resources A curated awesome-list of hacking, penetration testing, and AI red-teaming resources including courses, YouTube channels, labs, and tools. … | 70 | 17359 | active |
| edoardottt/awesome-hacker-search-engines A curated awesome-list of search engines useful for penetration testing, vulnerability assessment, red/blue team operations, and bug bounty… | 76 | 11089 | active |
| infosecn1nja/Red-Teaming-Toolkit A curated list of cutting-edge open-source security tools for red teamers and threat hunters, organized by attack lifecycle stages such as … | 69 | 10654 | active |
| sottlmarek/DevSecOps A curated awesome-list style library of open-source DevSecOps tools and methodologies covering cloud and SDLC security. It organizes tools … | 76 | 6855 | active |
| xairy/linux-kernel-exploitation A curated collection of links about Linux kernel security and exploitation, covering techniques, vulnerabilities, tools, books, and practic… | 76 | 6602 | active |
| secfigo/Awesome-Fuzzing A curated awesome-list of fuzzing resources including books, courses, videos, tutorials, tools, and vulnerable applications for practice. I… | 32 | 5904 | active |
| devsecops/awesome-devsecops A curated awesome-list of free and open-source DevSecOps resources, including tools, guidelines, presentations, training labs, podcasts, an… | 32 | 5461 | active |
| riramar/Web-Attack-Cheat-Sheet A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and explo… | 76 | 4433 | active |
| 0xor0ne/awesome-list A curated awesome list of cybersecurity blog posts, write-ups, and papers organized by year, plus a companion list of security tools and re… | 77 | 4068 | active |
| arainho/awesome-api-security A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scannin… | 10 | 3862 | active |
| vaib25vicky/awesome-mobile-security A curated awesome-list collecting Android and iOS security resources, including blogs, papers, tools, and guides for mobile penetration tes… | 32 | 3525 | active |
| V33RU/awesome-connected-things-sec A curated awesome-list of 900+ security resources for IoT, embedded, industrial control, automotive, and wireless systems. It organizes lin… | 76 | 3524 | active |
| blaCCkHatHacEEkr/PENTESTING-BIBLE A curated collection of links to articles, cheatsheets, and write-ups on penetration testing, bug bounty, red teaming, and offensive securi… | 32 | 13939 | maintenance |
| wgpsec/AboutSecurity A large structured penetration testing knowledge base containing 200+ skill methodologies covering recon, exploitation, lateral movement, a… | 65 | 1702 | active |
| euphrat1ca/Security-List A curated Chinese-language security knowledge index (awesome-style list) covering the full red team attack lifecycle, from reconnaissance a… | 32 | 1529 | active |
| SexyBeast233/SecBooks A curated collection of Chinese-language cybersecurity articles and vulnerability write-ups aggregated from various security blogs and WeCh… | 48 | 1308 | active |
| uphiago/recon-skills A curated pack of Markdown skill files documenting reconnaissance and penetration-testing procedures for web apps, APIs, authentication, cl… | 58 | 1199 | active |
| httpvoid/writeups A collection of application security research writeups by the HTTPVoid team, covering their own CVEs and technical analyses of public n-day… | 32 | 1199 | active |
| pe3zx/my-infosec-awesome A curated awesome-list of links, resources, and tools covering information security topics such as adversary simulation, application securi… | 74 | 1169 | active |
| 1N3/IntruderPayloads A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodol… | 32 | 3970 | maintenance |
| NoorQureshi/kali-linux-cheatsheet A community-maintained cheat sheet of Kali Linux commands and techniques for penetration testers, covering recon, enumeration, password cra… | 32 | 2988 | maintenance |
| tiancode/learn-hacking A curated collection of 83 Chinese-language tutorial notes on penetration testing, ethical hacking, and reverse engineering using Kali Linu… | 70 | 2263 | maintenance |
| BaizeSec/bylibrary BaizeSec's public vulnerability knowledge base (Baige Wenku) collecting POCs, EXPs, and security articles maintained by the BaizeSec securi… | 32 | 1503 | maintenance |
| tennc/fuzzdb A curated dictionary collection of attack patterns, payloads, and brute-force wordlists for black-box application fault injection and resou… | 23 | 1399 | maintenance |
| sergey-pronin/Awesome-Vulnerability-Research A curated awesome-list of resources for vulnerability research, including books, articles, courses, tools, write-ups, and methodologies. It… | 32 | 1348 | maintenance |
| Kyuu-Ji/Awesome-Azure-Pentest A curated awesome-list of tools, articles, labs, talks, and books for penetration testing and securing Microsoft Azure and Microsoft 365 en… | 32 | 1220 | maintenance |
← prev page 2 / 2