Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
awesome-ctf — CTF 框架、库、资源和软件精选列表 | Kitploit
工具/GitHubGitHub/apsdehal/awesome-ctf
漏洞利用逆向工程取证分析Web安全密码学CTF渗透测试学习与教育精选资源学习路径与课程CTF 分类第 17 名
11.7k1.6k266年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
精选资源 分类第 12 名
学习与教育 分类第 13 名
学习路径与课程 分类第 10 名
GitHubapsdehal/awesome-ctf

awesome-ctf

CTF 框架、库、资源和软件精选列表

查看仓库网站
# Awesome CTF [![Build Status](https://travis-ci.org/apsdehal/awesome-ctf.svg?branch=master)](https://travis-ci.org/apsdehal/awesome-ctf) [![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)

精心整理的 [夺旗赛](https://en.wikipedia.org/wiki/Capture_the_flag#Computer_security) (CTF) 框架、库、资源、软件和教程列表。本列表旨在帮助初学者和经验丰富的CTF玩家在一个地方找到与CTF相关的所有内容。

### 贡献

请先快速查阅 [贡献指南](https://github.com/apsdehal/ctf-tools/blob/master/CONTRIBUTING.md)。

#### _如果你知道某个工具未在此列出,欢迎提交拉取请求。_

### 为什么?

收集并记住CTF中使用的所有工具需要时间。本仓库帮助将这些分散的工具集中在一个地方。

### 目录

- [Awesome CTF](#awesome-ctf)
  - [创建](#create)
    - [取证](#forensics)
    - [平台](#platforms)
    - [隐写](#steganography)
    - [Web](#web)
  - [解决](#solve)
    - [攻击](#attacks)
    - [暴力破解](#bruteforcers)
    - [密码学](#crypto)
    - [漏洞利用](#exploits)
    - [取证](#forensics-1)
    - [网络](#networking)
    - [逆向](#reversing)
    - [服务](#services)
    - [隐写](#steganography-1)
    - [Web](#web-1)

- [资源](#resources)
  - [操作系统](#operating-systems)
  - [入门包](#starter-packs)
  - [教程](#tutorials)
  - [战争游戏](#wargames)
  - [网站](#websites)
  - [Wiki](#wikis)
  - [题解集合](#writeups-collections)


# 创建

*用于创建CTF挑战的工具*

- [Kali Linux CTF Blueprints](https://www.packtpub.com/eu/networking-and-servers/kali-linux-ctf-blueprints) - 关于构建、测试和自定义你自己的夺旗赛挑战的在线书籍。

## 取证

*用于创建取证挑战的工具*

- [Dnscat2](https://github.com/iagox86/dnscat2) - 通过DNS进行主机通信。
- [Kroll Artifact Parser and Extractor (KAPE)](https://learn.duffandphelps.com/kape) - 分流程序。
- [Magnet AXIOM](https://www.magnetforensics.com/downloadaxiom) - 以工件为中心的DFIR工具。
- [Registry Dumper](http://www.kahusecurity.com/posts/registry_dumper_find_and_dump_hidden_registry_keys.html) - 转储你的注册表。

## 平台

*可用于托管CTF的项目*

- [CTFd](https://github.com/isislab/CTFd) - 来自ISISLab(NYU Tandon)的托管Jeopardy风格CTF的平台。
- [echoCTF.RED](https://github.com/echoCTF/echoCTF.RED) - 开发、部署和维护你自己的CTF基础设施。
- [FBCTF](https://github.com/facebook/fbctf) - 来自Facebook的托管夺旗赛竞赛的平台。
- [Haaukins](https://github.com/aau-network-security/haaukins) - 一个高度可访问且自动化的安全教育虚拟化平台。
- [HackTheArch](https://github.com/mcpa-stlouis/hack-the-arch) - CTF计分平台。
- [Mellivora](https://github.com/Nakiami/mellivora) - 用PHP编写的CTF引擎。
- [MotherFucking-CTF](https://github.com/andreafioraldi/motherfucking-ctf) - 糟糕的轻量级CTF托管平台。无需JS。
- [NightShade](https://github.com/UnrealAkama/NightShade) - 一个简单的安全CTF框架。
- [OpenCTF](https://github.com/easyctf/openctf) - 盒中CTF。最少设置要求。
- [PicoCTF](https://github.com/picoCTF/picoCTF) - 用于运行picoCTF的平台。托管任何CTF的绝佳框架。
- [PyChallFactory](https://github.com/pdautry/py_chall_factory) - 用于创建/管理/打包Jeopardy风格CTF挑战的小型框架。
- [RootTheBox](https://github.com/moloch--/RootTheBox) - 黑客游戏(CTF计分板与游戏管理器)。
- [Scorebot](https://github.com/legitbs/scorebot) - 来自Legitbs(Defcon)的CTF平台。
- [SecGen](https://github.com/cliffe/SecGen) - 安全场景生成器。创建随机易受攻击的虚拟机。

## 隐写

*用于创建隐写挑战的工具*

请查看解决部分的隐写。

## Web

*用于创建Web挑战的工具*

*JavaScript混淆器*

- [Metasploit JavaScript Obfuscator](https://github.com/rapid7/metasploit-framework/wiki/How-to-obfuscate-JavaScript-in-Metasploit)
- [Uglify](https://github.com/mishoo/UglifyJS)


# 解决

*用于解决CTF挑战的工具*

## 攻击

*用于执行各种攻击的工具*

- [Bettercap](https://github.com/bettercap/bettercap) - 执行中间人攻击(MITM)的框架。
- [Yersinia](https://github.com/tomac/yersinia) - 攻击第2层的各种协议。

## 密码学

*用于解决密码学挑战的工具*

- [CyberChef](https://gchq.github.io/CyberChef) - 用于分析和解码数据的Web应用。
- [FeatherDuster](https://github.com/nccgroup/featherduster) - 一个自动化的模块化密码分析工具。
- [Hash Extender](https://github.com/iagox86/hash_extender) - 一个用于执行哈希长度扩展攻击的实用工具。
- [padding-oracle-attacker](https://github.com/KishanBagaria/padding-oracle-attacker) - 一个用于执行填充Oracle攻击的CLI工具。
- [PkCrack](https://www.unix-ag.uni-kl.de/~conrad/krypto/pkcrack.html) - 一个用于破解PkZip加密的工具。
- [QuipQuip](https://quipqiup.com) - 一个在线破解替换密码或维吉尼亚密码(无密钥)的工具。
- [RSACTFTool](https://github.com/Ganapati/RsaCtfTool) - 一个使用各种攻击恢复RSA私钥的工具。
- [RSATool](https://github.com/ius/rsatool) - 在已知p和q的情况下生成私钥。
- [XORTool](https://github.com/hellman/xortool) - 一个分析多字节XOR密码的工具。

## 暴力破解器

*用于各种暴力破解(密码等)的工具*

- [Hashcat](https://hashcat.net/hashcat/) - 密码破解器
- [Hydra](https://tools.kali.org/password-attacks/hydra) - 一个并行化的登录破解器,支持多种攻击协议
- [John The Jumbo](https://github.com/magnumripper/JohnTheRipper) - John the Ripper的社区增强版本。
- [John The Ripper](http://www.openwall.com/john/) - 密码破解器。
- [Nozzlr](https://github.com/intrd/nozzlr) - Nozzlr是一个真正模块化且对脚本友好的暴力破解框架。
- [Ophcrack](http://ophcrack.sourceforge.net/) - 基于彩虹表的Windows密码破解器。
- [Patator](https://github.com/lanjelot/patator) - Patator是一个多用途暴力破解器,采用模块化设计。
- [Turbo Intruder](https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack) - Burp Suite扩展,用于发送大量HTTP请求。

## 漏洞利用

*用于解决漏洞利用挑战的工具*

- [DLLInjector](https://github.com/OpenSecurityResearch/dllinjector) - 在进程中注入DLL。
- [libformatstr](https://github.com/hellman/libformatstr) - 简化格式化字符串漏洞利用。
- [Metasploit](http://www.metasploit.com/) - 渗透测试软件。
  - [速查表](https://www.comparitech.com/net-admin/metasploit-cheat-sheet/)
- [one_gadget](https://github.com/david942j/one_gadget) - 一个用于查找单个gadget `execve('/bin/sh', NULL, NULL)` 调用的工具。
  - `gem install one_gadget`
- [Pwntools](https://github.com/Gallopsled/pwntools) - 用于编写漏洞利用的CTF框架。
- [Qira](https://github.com/BinaryAnalysisPlatform/qira) - QEMU交互式运行时分析器。
- [ROP Gadget](https://github.com/JonathanSalwan/ROPgadget) - ROP漏洞利用框架。
- [V0lt](https://github.com/P1kachu/v0lt) - 安全CTF工具包。

## 取证

*用于解决取证挑战的工具*

- [Aircrack-Ng](http://www.aircrack-ng.org/) - 破解802.11 WEP和WPA-PSK密钥。
  - `apt-get install aircrack-ng`
- [Audacity](http://sourceforge.net/projects/audacity/) - 分析声音文件(mp3, m4a等)。
  - `apt-get install audacity`
- [Bkhive and Samdump2](http://sourceforge.net/projects/ophcrack/files/samdump2/) - 转储SYSTEM和SAM文件。
  - `apt-get install samdump2 bkhive`
- [CFF Explorer](http://www.ntcore.com/exsuite.php) - PE编辑器。
- [Creddump](https://github.com/moyix/creddump) - 转储Windows凭据。
- [DVCS Ripper](https://github.com/kost/dvcs-ripper) - 撕取Web可访问的(分布式)版本控制系统。
- [Exif Tool](http://www.sno.phy.queensu.ca/~phil/exiftool/) - 读取、写入和编辑文件元数据。
- [Extundelete](http://extundelete.sourceforge.net/) - 用于从可挂载映像恢复丢失的数据。
- [Fibratus](https://github.com/rabbitstack/fibratus) - 用于探索和跟踪Windows内核的工具。
- [Foremost](http://foremost.sourceforge.net/) - 使用标头提取特定类型的文件。
  - `apt-get install foremost`
- [Fsck.ext4](http://linux.die.net/man/8/fsck.ext3) - 用于修复损坏的文件系统。
- [Malzilla](http://malzilla.sourceforge.net/) - 恶意软件搜寻工具。
- [NetworkMiner](http://www.netresec.com/?page=NetworkMiner) - 网络取证分析工具。
- [PDF Streams Inflater](http://malzilla.sourceforge.net/downloads.html) - 查找并提取PDF文件中压缩的zlib文件。
- [Pngcheck](http://www.libpng.org/pub/png/apps/pngcheck.html) - 验证PNG的完整性,并以人类可读的形式转储所有块级信息。
  - `apt-get install pngcheck`
- [ResourcesExtract](http://www.nirsoft.net/utils/resources_extract.html) - 从exe中提取各种文件类型。
- [Shellbags](https://github.com/williballenthin/shellbags) - 调查NT\_USER.dat文件。
- [Snow](https://sbmlabs.com/notes/snow_whitespace_steganography_tool) - 空白隐写工具。
- [USBRip](https://github.com/snovvcrash/usbrip) - 用于在GNU/Linux上跟踪USB设备工件(USB事件历史)的简单CLI取证工具。
- [Volatility](https://github.com/volatilityfoundation/volatility) - 调查内存转储。
- [Wireshark](https://www.wireshark.org) - 用于分析pcap或pcapng文件。

*注册表查看器*
- [OfflineRegistryView](https://www.nirsoft.net/utils/offline_registry_view.html) - 一个简单的Windows工具,允许你从外部驱动器读取脱机注册表文件,并以.reg文件格式查看所需的注册表项。
- [Registry Viewer®](https://accessdata.com/product-download/registry-viewer-2-0-0) - 用于查看Windows注册表。

## 网络

*用于解决网络挑战的工具*

- [Masscan](https://github.com/robertdavidgraham/masscan) - 大规模IP端口扫描器,TCP端口扫描器。
- [Monit](https://linoxide.com/monitoring-2/monit-linux/) - 一个Linux工具,用于检查网络上的主机(以及其他非网络活动)。
- [Nipe](https://github.com/GouveaHeitor/nipe) - Nipe是一个使Tor网络成为默认网关的脚本。
- [Nmap](https://nmap.org/) - 一个开源网络发现和安全审计工具。
- [Wireshark](https://www.wireshark.org/) - 分析网络转储。
  - `apt-get install wireshark`
- [Zeek](https://www.zeek.org) - 一个开源网络安全监控器。
- [Zmap](https://zmap.io/) - 一个开源网络扫描器。

## 逆向

*用于解决逆向挑战的工具*

- [Androguard](https://github.com/androguard/androguard) - 逆向工程Android应用程序。
- [Angr](https://github.com/angr/angr) - 平台无关的二进制分析框架。
- [Apk2Gold](https://github.com/lxdvs/apk2gold) - 又一个Android反编译器。
- [ApkTool](http://ibotpeaches.github.io/Apktool/) - Android反编译器。
- [Barf](https://github.com/programa-stic/barf-project) - 二进制分析与逆向工程框架。
- [Binary Ninja](https://binary.ninja/) - 二进制分析框架。
- [BinUtils](http://www.gnu.org/software/binutils/binutils.html) - 二进制工具集合。
- [BinWalk](https://github.com/devttys0/binwalk) - 分析、逆向工程和提取固件映像。
- [Boomerang](https://github.com/BoomerangDecompiler/boomerang) - 将x86/SPARC/PowerPC/ST-20二进制文件反编译为C。
- [ctf_import](https://github.com/docileninja/ctf_import) – 跨平台运行去除符号的二进制文件的基本函数。
- [cwe_checker](https://github.com/fkie-cad/cwe_checker) - cwe_checker在二进制可执行文件中查找易受攻击的模式。
- [demovfuscator](https://github.com/kirschju/demovfuscator) - 一个正在进行中的、用于解除movfuscated二进制文件混淆的工具。
- [Frida](https://github.com/frida/) - 动态代码注入。
- [GDB](https://www.gnu.org/software/gdb/) - GNU项目调试器。
- [GEF](https://github.com/hugsy/gef) - GDB插件。
- [Ghidra](https://ghidra-sre.org/) - 开源逆向工程工具套件。类似于IDA Pro。
- [Hopper](http://www.hopperapp.com/) - 用于OSX和Linux的逆向工程工具(反汇编器)。
- [IDA Pro](https://www.hex-rays.com/products/ida/) - 最常用的逆向工程软件。
- [Jadx](https://github.com/skylot/jadx) - 反编译Android文件。
- [Java Decompilers](http://www.javadecompilers.com) - 一个用于Java和Android APK的在线反编译器。
- [Krakatau](https://github.com/Storyyeller/Krakatau) - Java反编译器和反汇编器。
- [Objection](https://github.com/sensepost/objection) - 运行时移动设备探索。
- [PEDA](https://github.com/longld/peda) - GDB插件(仅支持python2.7)。
- [Pin](https://software.intel.com/en-us/articles/pin-a-dynamic-binary-instrumentation-tool) - Intel的动态二进制插桩工具。
- [PINCE](https://github.com/korcankaraokcu/PINCE) - GDB前端/逆向工程工具,专注于游戏破解和自动化。
- [PinCTF](https://github.com/ChrisTheCoolHut/PinCTF) - 一个使用Intel Pin进行侧信道分析的工具。
- [Plasma](https://github.com/joelpx/plasma) - 一个交互式反汇编器,支持x86/ARM/MIPS,可以生成带有彩色语法的缩进伪代码。
- [Pwndbg](https://github.com/pwndbg/pwndbg) - 一个GDB插件,提供一套实用工具以便更容易地使用GDB。
- [radare2](https://github.com/radare/radare2) - 一个可移植的逆向框架。
- [Triton](https://github.com/JonathanSalwan/Triton/) - 动态二进制分析(DBA)框架。
- [Uncompyle](https://github.com/gstarnberger/uncompyle) - 反编译Python 2.7二进制文件(.pyc)。
- [WinDbg](http://www.windbg.org/) - 微软分发的Windows调试器。
- [Xocopy](http://reverse.lostrealm.com/tools/xocopy.html) - 一个可以复制具有执行权限但无读取权限的可执行文件的程序。
- [Z3](https://github.com/Z3Prover/z3) - 微软研究院的定理证明器。

*JavaScript反混淆器*

- [Detox](http://relentless-coding.org/projects/jsdetox/install) - 一个JavaScript恶意软件分析工具。
- [Revelo](http://www.kahusecurity.com/posts/revelo_javascript_deobfuscator.html) - 分析混淆的JavaScript代码。

*SWF分析器*
- [RABCDAsm](https://github.com/CyberShadow/RABCDAsm) - 实用工具集合,包括ActionScript 3汇编器/反汇编器。
- [Swftools](http://www.swftools.org/) - 用于处理SWF文件的实用工具集合。
- [Xxxswf](https://bitbucket.org/Alexander_Hanel/xxxswf) - 一个用于分析Flash文件的Python脚本。

## 服务

*互联网上可用的各种有用服务*

- [CSWSH](http://cow.cat/cswsh.html) - 跨站WebSocket劫持测试器。
- [Request Bin](https://requestbin.com/) - 允许你检查发送到特定URL的HTTP请求。

## 隐写

*用于解决隐写挑战的工具*

- [AperiSolve](https://aperisolve.fr/) - Aperi'Solve是一个对图像进行层分析的平台(开源)。
- [Convert](http://www.imagemagick.org/script/convert.php) - 在格式间转换图像并应用滤镜。
- [Exif](http://manpages.ubuntu.com/manpages/trusty/man1/exif.1.html) - 显示JPEG文件中的EXIF信息。
- [Exiftool](https://linux.die.net/man/1/exiftool) - 读取和写入文件中的元信息。
- [Exiv2](http://www.exiv2.org/manpage.html) - 图像元数据操作工具。
- [Image Steganography](https://sourceforge.net/projects/image-steg/) - 将文本和文件嵌入图像中,可选加密。易于使用的UI。
- [Image Steganography Online](https://incoherency.co.uk/image-steganography) - 这是一个客户端的JavaScript工具,用于将图像隐写地隐藏在另一个图像的低位中。
- [ImageMagick](http://www.imagemagick.org/script/index.php) - 用于操作图像的工具。
- [Outguess](https://www.freebsd.org/cgi/man.cgi?query=outguess+&apropos=0&sektion=0&manpath=FreeBSD+Ports+5.1-RELEASE&format=html) - 通用隐写工具。
- [Pngtools](https://packages.debian.org/sid/pngtools) - 用于与PNG相关的各种分析。
  - `apt-get install pngtools`
- [SmartDeblur](https://github.com/Y-Vladimir/SmartDeblur) - 用于去模糊和修复失焦图像。
- [Steganabara](https://www.openhub.net/p/steganabara) - 用Java编写的隐写分析工具。
- [SteganographyOnline](https://stylesuxx.github.io/steganography/) - 在线隐写编码器和解码器。
- [Stegbreak](https://linux.die.net/man/1/stegbreak) - 对JPG图像发起暴力字典攻击。
- [StegCracker](https://github.com/Paradoxis/StegCracker) - 用于发现文件中隐藏数据的隐写暴力破解工具。
- [stegextract](https://github.com/evyatarmeged/stegextract) - 检测图像中的隐藏文件和文本。
- [Steghide](http://steghide.sourceforge.net/) - 将数据隐藏在各种类型的图像中。
- [StegOnline](https://georgeom.net/StegOnline/upload) - 执行广泛的图像隐写操作,例如隐藏/揭示隐藏在比特中的文件(开源)。
- [Stegsolve](http://www.caesum.com/handbook/Stegsolve.jar) - 对图像应用各种隐写技术。
- [Zsteg](https://github.com/zed-0xff/zsteg/) - PNG/BMP分析。

## Web

*用于解决Web挑战的工具*

- [BurpSuite](https://portswigger.net/burp) - 一个用于测试网站安全性的图形化工具。
- [Commix](https://github.com/commixproject/commix) - 自动化的全能OS命令注入和利用工具。
- [Hackbar](https://addons.mozilla.org/en-US/firefox/addon/hackbartool/) - 用于轻松进行Web漏洞利用的Firefox插件。
- [OWASP ZAP](https://www.owasp.org/index.php/Projects/OWASP_Zed_Attack_Proxy_Project) - 拦截代理,用于重放、调试和模糊HTTP请求和响应。
- [Postman](https://chrome.google.com/webstore/detail/postman/fhbjgbiflinjbdggehcddcbncdddomop?hl=en) - 用于调试网络请求的Chrome扩展。
- [Raccoon](https://github.com/evyatarmeged/Raccoon) - 一个高性能的进攻性安全工具,用于侦察和漏洞扫描。
- [SQLMap](https://github.com/sqlmapproject/sqlmap) - 自动SQL注入和数据库接管工具。  ```pip install sqlmap```
- [W3af](https://github.com/andresriancho/w3af) -  Web Application Attack and Audit Framework.
- [XSSer](http://xsser.sourceforge.net/) - Automated XSS testor.


# Resources

*Where to discover about CTF*

## Operating Systems

*Penetration testing and security lab Operating Systems*

- [Android Tamer](https://androidtamer.com/) - Based on Debian.
- [BackBox](https://backbox.org/) - Based on Ubuntu.
- [BlackArch Linux](https://blackarch.org/) - Based on Arch Linux.
- [Fedora Security Lab](https://labs.fedoraproject.org/security/) - Based on Fedora.
- [Kali Linux](https://www.kali.org/) - Based on Debian.
- [Parrot Security OS](https://www.parrotsec.org/) - Based on Debian.
- [Pentoo](http://www.pentoo.ch/) - Based on Gentoo.
- [URIX OS](http://urix.us/) - Based on openSUSE.
- [Wifislax](http://www.wifislax.com/) - Based on Slackware.

*Malware analysts and reverse-engineering*

- [Flare VM](https://github.com/fireeye/flare-vm/) - Based on Windows.
- [REMnux](https://remnux.org/) - Based on Debian.

## Starter Packs

*Collections of installer scripts, useful tools*

- [CTF Tools](https://github.com/zardus/ctf-tools) - Collection of setup scripts to install various security research tools.
- [LazyKali](https://github.com/jlevitsk/lazykali) - A 2016 refresh of LazyKali which simplifies install of tools and configuration.

## Tutorials

*Tutorials to learn how to play CTFs*

- [CTF Field Guide](https://trailofbits.github.io/ctf/) - Field Guide by Trails of Bits.
- [CTF Resources](http://ctfs.github.io/resources/) -  Start Guide maintained by community.
- [How to Get Started in CTF](https://www.endgame.com/blog/how-get-started-ctf) - Short guideline for CTF beginners by Endgame
- [Intro. to CTF Course](https://www.hoppersroppers.org/courseCTF.html) - A free course that teaches beginners the basics of forensics, crypto, and web-ex.
- [IppSec](https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA) - Video tutorials and walkthroughs of popular CTF platforms.
- [LiveOverFlow](https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w) - Video tutorials on Exploitation.
- [MIPT CTF](https://github.com/xairy/mipt-ctf) - A small course for beginners in CTFs (in Russian).


## Wargames

*Always online CTFs*

- [Backdoor](https://backdoor.sdslabs.co/) - Security Platform by SDSLabs.
- [Crackmes](https://crackmes.one/) - Reverse Engineering Challenges.
- [CryptoHack](https://cryptohack.org/) - Fun cryptography challenges.
- [echoCTF.RED](https://echoctf.red/) - Online CTF with a variety of targets to attack.
- [Exploit Exercises](https://exploit-exercises.lains.space/) - Variety of VMs to learn variety of computer security issues.
- [Exploit.Education](http://exploit.education) - Variety of VMs to learn variety of computer security issues.
- [Gracker](https://github.com/Samuirai/gracker) - Binary challenges having a slow learning curve, and write-ups for each level.
- [Hack The Box](https://www.hackthebox.eu) - Weekly CTFs for all types of security enthusiasts.
- [Hack This Site](https://www.hackthissite.org/) - Training ground for hackers.
- [Hacker101](https://www.hacker101.com/) - CTF from HackerOne
- [Hacking-Lab](https://hacking-lab.com/) - Ethical hacking, computer network and security challenge platform.
- [Hone Your Ninja Skills](https://honeyourskills.ninja/) - Web challenges starting from basic ones.
- [IO](http://io.netgarage.org/) - Wargame for binary challenges.
- [Microcorruption](https://microcorruption.com) - Embedded security CTF.
- [Over The Wire](http://overthewire.org/wargames/) - Wargame maintained by OvertheWire Community.
- [PentesterLab](https://pentesterlab.com/) - Variety of VM and online challenges (paid).
- [PicoCTF](https://2019game.picoctf.com) - All year round ctf game. Questions from the yearly picoCTF competition.
- [PWN Challenge](http://pwn.eonew.cn/) - Binary Exploitation Wargame.
- [Pwnable.kr](http://pwnable.kr/) - Pwn Game.
- [Pwnable.tw](https://pwnable.tw/) - Binary wargame.
- [Pwnable.xyz](https://pwnable.xyz/) - Binary Exploitation Wargame.
- [Reversin.kr](http://reversing.kr/) - Reversing challenge.
- [Ringzer0Team](https://ringzer0team.com/) - Ringzer0 Team Online CTF.
- [Root-Me](https://www.root-me.org/) - Hacking and Information Security learning platform.
- [ROP Wargames](https://github.com/xelenonz/game) - ROP Wargames.
- [SANS HHC](https://holidayhackchallenge.com/past-challenges/) - Challenges with a holiday theme
  released annually and maintained by SANS.
- [SmashTheStack](http://smashthestack.org/) - A variety of wargames maintained by the SmashTheStack Community.
- [Viblo CTF](https://ctf.viblo.asia) - Various amazing CTF challenges, in many different categories. Has both Practice mode and Contest mode.
- [VulnHub](https://www.vulnhub.com/) - VM-based for practical in digital security, computer application & network administration.
- [W3Challs](https://w3challs.com) - A penetration testing training platform, which offers various computer challenges, in various categories.
- [WebHacking](http://webhacking.kr) - Hacking challenges for web.


*Self-hosted CTFs*
- [Damn Vulnerable Web Application](http://www.dvwa.co.uk/) - PHP/MySQL web application that is damn vulnerable.
- [Juice Shop CTF](https://github.com/bkimminich/juice-shop-ctf) - Scripts and tools for hosting a CTF on [OWASP Juice Shop](https://www.owasp.org/index.php/OWASP_Juice_Shop_Project) easily.

## Websites

*Various general websites about and on CTF*

- [Awesome CTF Cheatsheet](https://github.com/uppusaikiran/awesome-ctf-cheatsheet#awesome-ctf-cheatsheet-) - CTF Cheatsheet.
- [CTF Time](https://ctftime.org/) - General information on CTF occuring around the worlds.
- [Reddit Security CTF](http://www.reddit.com/r/securityctf) - Reddit CTF category.

## Wikis

*Various Wikis available for learning about CTFs*

- [Bamboofox](https://bamboofox.github.io/) - Chinese resources to learn CTF.
- [bi0s Wiki](https://teambi0s.gitlab.io/bi0s-wiki/) - Wiki from team bi0s.
- [CTF Cheatsheet](https://uppusaikiran.github.io/hacking/Capture-the-Flag-CheatSheet/) - CTF tips and tricks.
- [ISIS Lab](https://github.com/isislab/Project-Ideas/wiki) - CTF Wiki by Isis lab.
- [OpenToAll](https://github.com/OpenToAllCTF/Tips) - CTF tips by OTA CTF team members.

## Writeups Collections

*Collections of CTF write-ups*

- [0e85dc6eaf](https://github.com/0e85dc6eaf/CTF-Writeups) - Write-ups for CTF challenges by 0e85dc6eaf
- [Captf](http://captf.com/) - Dumped CTF challenges and materials by psifertex.
- [CTF write-ups (community)](https://github.com/ctfs/) - CTF challenges + write-ups archive maintained by the community.
- [CTFTime Scrapper](https://github.com/abdilahrf/CTFWriteupScrapper) - Scraps all writeup from CTF Time and organize which to read first.
- [HackThisSite](https://github.com/HackThisSite/CTF-Writeups) - CTF write-ups repo maintained by HackThisSite team.
- [Mzfr](https://github.com/mzfr/ctf-writeups/) - CTF competition write-ups by mzfr
- [pwntools writeups](https://github.com/Gallopsled/pwntools-write-ups) - A collection of CTF write-ups all using pwntools.
- [SababaSec](https://github.com/SababaSec/ctf-writeups) - A collection of CTF write-ups by the SababaSec team
- [Shell Storm](http://shell-storm.org/repo/CTF/) - CTF challenge archive maintained by Jonathan Salwan.
- [Smoke Leet Everyday](https://github.com/smokeleeteveryday/CTF_WRITEUPS) - CTF write-ups repo maintained by SmokeLeetEveryday team.

### LICENSE

CC0 :)
下载工具