
hackerone-reports
Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

A structured course built from personal study notes of the book Linux Basics for Hackers by OccupyTheWeb.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Rules shared by the community from 100 Days of YARA 2024

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

Rules Shared by the Community from 100 Days of YARA 2023 -

Rules shared by the community from 100 Days of YARA 2026

Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage…

In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the…

🐶 A curated list of Web Security materials and resources.

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

Materials for Windows Malware Analysis training (volume 1)

Free educational courses in cybersecurity, reverse engineering, malware analysis, and programming designed to expand access, build practical skills,…

Official Elastic Skills

Issues to consider when planning a red team exercise.

Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…