
How-To-Secure-A-Linux-Server
Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF


Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

A curated list of resources for learning about application security

A collection of awesome security hardening guides, tools and other resources

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Automate the creation of a lab environment complete with security tooling and logging best practices


Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…