
testing-handbook
Curated guide for configuring and automating static analysis, fuzzing, and web security tools in CI/CD pipelines, with chapters on Semgrep, CodeQL,…

Curated guide for configuring and automating static analysis, fuzzing, and web security tools in CI/CD pipelines, with chapters on Semgrep, CodeQL,…

Curated collection of cybersecurity learning resources, CTF writeups, research papers, and practical labs for hands-on skill development across web…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Security training for the apps you actually ship. Open your browser and start hacking.

Curated methodology and resource collection for web application bug bounty hunting, covering reconnaissance, vulnerability analysis, and exploitation…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Curated cybersecurity learning library with tutorials, mindmaps, vulnerable code snippets, and methodology breakdowns across web pentesting, bug…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Cursor plugin teaching Hono v4 best practices with 59 LLM anti-patterns, security defaults, and Cloudflare Workers gotchas. Includes rules, skills,…

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A curated list of awesome iOS application security resources.

Docker-based personal hacklab bundling penetration testing tools, vulnerability scanners, OSINT resources, and curated learning materials for…