
API-Security
OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Contained is all my reference material for my OSCP / Red Teaming. Designed to be a one stop shop for code, guides, command syntax, and high level…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Curated penetration testing wiki with daily-updated techniques, scripts, and checklists for reconnaissance, web, cloud, mobile, and…

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

Dracula OS is a Linux operating system meticulously designed for OSINT (Open Source Intelligence) and Cyber Intelligence missions.

Collection of YARA rules designed for usage through VirusTotal.com.

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

QuantumLock is an open-source, quantum-resistant Bitcoin protocol designed to protect digital assets from future quantum computing threats. Featuring…

Curated collection of Python scripts and tutorials for penetration testing, web security, and exploitation techniques, designed for security…

Attack and defend active directory using modern post exploitation adversary tradecraft activity

A curated list of cybersecurity tools and resources.

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.