
the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

A collection of various awesome lists for hackers, pentesters and security researchers

A Chrome extension that demonstrates bypassing Widevine L3 DRM

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

A curated list of awesome Hacking tutorials, tools and resources

AI-powered penetration testing assistant using local LLM on linux (Parrot OS)

Penetration tests guide based on OWASP including test cases, resources and examples.

SQL Vulnerability Scanner


Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

🚨 Threat intel & incident response research on SharePoint "ToolShell" RCE zero-day (CVE-2025-53770). 🕵️♂️ Covers root-cause deserialization flaws,…