
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A collection of awesome penetration testing resources, tools and other shiny things

Curated methodology and resource collection for web application bug bounty hunting, covering reconnaissance, vulnerability analysis, and exploitation…

Curated learning path for web security, covering SQL injection, XSS, CSRF, SSRF, XXE, SSTI, and file inclusion with practical examples and CTF…

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

Curated cybersecurity learning library with tutorials, mindmaps, vulnerable code snippets, and methodology breakdowns across web pentesting, bug…

Curated library of AI agent skills for Elasticsearch, Kibana, Observability, and Security. Teaches agents correct API usage, cloud management, alert…

Security training for the apps you actually ship. Open your browser and start hacking.

Learning and hunting SQL injection bugs for 50 continuous days

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

Educational lab environment demonstrating CVE-2019-15588 RCE command injection vulnerability for hands-on exploitation practice and learning.

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.