
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Course materials for hackaday.io Ghidra training

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Building 70 Projects ranging from beginner to advanced so anyone can — learn from, build upon, use as a reference, or even copy directly. Gamified…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

A collection of various awesome lists for hackers, pentesters and security researchers

Self-hosted Information Security Management System — ISO 27001, NIS2, GDPR/DSGVO, BSI IT-Grundschutz

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

A structured course built from personal study notes of the book Linux Basics for Hackers by OccupyTheWeb.

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

A curated list of cybersecurity tools and resources.