
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Hardened Android web browser forked from Mull/Firefox with privacy-focused patches, anti-fingerprinting, telemetry removal, and secure defaults for…

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

No-root network monitor, firewall and PCAP dumper for Android

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Ghidra is a software reverse engineering (SRE) framework

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

🐶 A curated list of Web Security materials and resources.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Hands-on challenges for learning how to reverse engineer Flutter applications.

Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock.

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

UNIX-like reverse engineering framework and command-line toolset

An educational Python toolkit for authorized penetration testing: threaded port scanner, subdomain & directory enumeration, banner grabber and host…