
Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers

A collection of various awesome lists for hackers, pentesters and security researchers

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering,…

Some good resources for getting started with application security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

A collection of awesome penetration testing resources and tools

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

A beginner Obsidian Vault structure for Cybersecurity, Linux, Homelabbing / Self-hosting, all about sharing knowledge.

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…