
awesome-cybersec — Updated!
A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security
awesome-cybersec
A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security
While this repository is still a work in progress , the goal is to build a categorized community-driven collection of very well-known resources.
All the good stuff in one place
Training
-
Darkmoon - Open source (GPL-3.0) autonomous AI penetration testing platform covering web, API, Active Directory and Kubernetes, orchestrating 80+ offensive tools as an MCP host with proof of exploitation and a local privacy gateway (the LLM never sees real IPs or credentials).
-
corelan: exploit-writing-tutorial-part-1-stack-based-overflows
-
Pwncollege pwn.college is a first-stage education platform for students (and other interested parties) to learn about, and practice, core cybersecurity concepts in a hands-on fashion. It is designed to take a “white belt” in cybersecurity to becoming a “blue belt”, able to approach (simple) CTFs and wargames. The philosophy of pwn.college is “practice makes perfect”.
-
CyberPython A hands on platform where you have to do your own research in order to solve challenges using little guidance and tips.
-
Web Application Exploits and DefensesThis codelab is built around Gruyere /ɡruːˈjɛər/ - a small, cheesy web application that allows its users to publish snippets of text and store assorted files. "Unfortunately," Gruyere has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution. The goal of this codelab is to guide you through discovering some of these bugs and learning ways to fix them both in Gruyere and in general.
WebApp/Bugbounty resources
- Web Security Academy
- https://owasp.org/www-project-juice-shop/
- Mutillidae II
- VulnWeb
- https://www.bugbountyhunter.com/
- hacker101 is a free class for web security. Whether you’re a programmer with an interest in bug bounties or a seasoned security professional, Hacker101 has something to teach you.
- https://www.hacksplaining.com/
- awesome-web-hacking
- Resources-for-Beginner-Bug-Bounty-Hunters
- https://thexssrat.podia.com/dashboard
- https://github.com/websploit/websploit
- https://dvwa.co.uk/
- https://owasp.org/www-project-webgoat/
- Resources & Disclosed Reports
- Bug-bounty-roadmaps
- Bug-hunting-methodologies
- Open Source Bug Bounty Guide - Methodology, Tools, Resources
- Thug-bounty
- Bugbounty-Writeups
- The Best Bug Bounty Recon Methodology
- Pentesting web checklist
- Web-application cheatsheet
- Web-pentesting-checklist
- OWASP Web Security Testing Guide
- OWASP Top Ten
- Bugcroud university
- OWASP Web Security Testing Guide