
awesome-malware-analysis
Defund the Police.
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Defund the Police.

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…


Web path scanner

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Reproduce DeFi hacked incidents using Foundry.

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A collection of links related to Linux kernel security and exploitation

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

Scapy: the Python-based interactive packet manipulation program & library.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

A list of resources for those interested in getting started in bug bounties

RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…