
awesome-ethical-hacking-resources
😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…


The Secure Coding Practices Quick-reference Guide from OWASP

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists