
webhacklist
Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved

Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved

Active Directory Attack Architecture Map Comprehensive Pentest Reference — From Recon to Domain Dominance

Red Team Operations Architecture Map Comprehensive Operator Reference — From Infrastructure to Impact

Mirrors CISA's Known Exploited Vulnerabilities (KEV) catalog as CSV and JSON with a JSON schema, enabling programmatic access and commit-history…

A repo to conduct vulnerability enrichment.

Community-maintained Markdown knowledge base covering cybersecurity foundations, offensive and defensive practice, governance, threat intelligence,…

Collection of Atredis Partners security advisories documenting vulnerabilities discovered during client engagements and independent research, with…

The Ultimate CVE Proof of Concept (PoC) & Exploit Database. A zero-API, high-performance aggregator for 0days, vulnerabilities, and Threat…

An OSINT investigation case mapping tool for organizing entities, relationships, evidence, and intelligence.

Longitudinal anycast census system that probes IPv4/IPv6 prefixes via ICMP, TCP, and DNS to detect anycast deployments and geolocate PoPs, publishing…

Live CVE PoC (Proof-of-Concepts) Aggregator with Smart Search & Threat Intelligence

Security portfolio of original responsible-disclosure findings, CTF and lab write-ups, methodology notes, and purpose-built pentest tooling covering…

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and…

Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings…

Research notes documenting CVE-2024-30350, an out-of-bounds read in Foxit PDF Reader annotation handling, covering triage, disclosure, and defensive…

A repository preserving darknet market data, including vendor lists, PGP keys, listings, and more for research & intelligence purposes.

AI-driven OSINT and security research agent that builds a live knowledge graph from public data, with bundled recon tools and offensive-security…

Search public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub, with CVSS, EPSS and CISA KEV context.