
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.


Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A curated list of resources for learning about application security

The Web Application Hacker's Handbook - Extra Content

A curated list of awesome iOS application security resources.

Application Security Verification Standard

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

A wordlist of API names for web application assessments

A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK®…

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.