CTF 框架、库、资源和软件精选列表
# Awesome CTF [](https://travis-ci.org/apsdehal/awesome-ctf) [](https://github.com/sindresorhus/awesome)
精心整理的 [夺旗赛](https://en.wikipedia.org/wiki/Capture_the_flag#Computer_security) (CTF) 框架、库、资源、软件和教程列表。本列表旨在帮助初学者和经验丰富的CTF玩家在一个地方找到与CTF相关的所有内容。
### 贡献
请先快速查阅 [贡献指南](https://github.com/apsdehal/ctf-tools/blob/master/CONTRIBUTING.md)。
#### _如果你知道某个工具未在此列出,欢迎提交拉取请求。_
### 为什么?
收集并记住CTF中使用的所有工具需要时间。本仓库帮助将这些分散的工具集中在一个地方。
### 目录
- [Awesome CTF](#awesome-ctf)
- [创建](#create)
- [取证](#forensics)
- [平台](#platforms)
- [隐写](#steganography)
- [Web](#web)
- [解决](#solve)
- [攻击](#attacks)
- [暴力破解](#bruteforcers)
- [密码学](#crypto)
- [漏洞利用](#exploits)
- [取证](#forensics-1)
- [网络](#networking)
- [逆向](#reversing)
- [服务](#services)
- [隐写](#steganography-1)
- [Web](#web-1)
- [资源](#resources)
- [操作系统](#operating-systems)
- [入门包](#starter-packs)
- [教程](#tutorials)
- [战争游戏](#wargames)
- [网站](#websites)
- [Wiki](#wikis)
- [题解集合](#writeups-collections)
# 创建
*用于创建CTF挑战的工具*
- [Kali Linux CTF Blueprints](https://www.packtpub.com/eu/networking-and-servers/kali-linux-ctf-blueprints) - 关于构建、测试和自定义你自己的夺旗赛挑战的在线书籍。
## 取证
*用于创建取证挑战的工具*
- [Dnscat2](https://github.com/iagox86/dnscat2) - 通过DNS进行主机通信。
- [Kroll Artifact Parser and Extractor (KAPE)](https://learn.duffandphelps.com/kape) - 分流程序。
- [Magnet AXIOM](https://www.magnetforensics.com/downloadaxiom) - 以工件为中心的DFIR工具。
- [Registry Dumper](http://www.kahusecurity.com/posts/registry_dumper_find_and_dump_hidden_registry_keys.html) - 转储你的注册表。
## 平台
*可用于托管CTF的项目*
- [CTFd](https://github.com/isislab/CTFd) - 来自ISISLab(NYU Tandon)的托管Jeopardy风格CTF的平台。
- [echoCTF.RED](https://github.com/echoCTF/echoCTF.RED) - 开发、部署和维护你自己的CTF基础设施。
- [FBCTF](https://github.com/facebook/fbctf) - 来自Facebook的托管夺旗赛竞赛的平台。
- [Haaukins](https://github.com/aau-network-security/haaukins) - 一个高度可访问且自动化的安全教育虚拟化平台。
- [HackTheArch](https://github.com/mcpa-stlouis/hack-the-arch) - CTF计分平台。
- [Mellivora](https://github.com/Nakiami/mellivora) - 用PHP编写的CTF引擎。
- [MotherFucking-CTF](https://github.com/andreafioraldi/motherfucking-ctf) - 糟糕的轻量级CTF托管平台。无需JS。
- [NightShade](https://github.com/UnrealAkama/NightShade) - 一个简单的安全CTF框架。
- [OpenCTF](https://github.com/easyctf/openctf) - 盒中CTF。最少设置要求。
- [PicoCTF](https://github.com/picoCTF/picoCTF) - 用于运行picoCTF的平台。托管任何CTF的绝佳框架。
- [PyChallFactory](https://github.com/pdautry/py_chall_factory) - 用于创建/管理/打包Jeopardy风格CTF挑战的小型框架。
- [RootTheBox](https://github.com/moloch--/RootTheBox) - 黑客游戏(CTF计分板与游戏管理器)。
- [Scorebot](https://github.com/legitbs/scorebot) - 来自Legitbs(Defcon)的CTF平台。
- [SecGen](https://github.com/cliffe/SecGen) - 安全场景生成器。创建随机易受攻击的虚拟机。
## 隐写
*用于创建隐写挑战的工具*
请查看解决部分的隐写。
## Web
*用于创建Web挑战的工具*
*JavaScript混淆器*
- [Metasploit JavaScript Obfuscator](https://github.com/rapid7/metasploit-framework/wiki/How-to-obfuscate-JavaScript-in-Metasploit)
- [Uglify](https://github.com/mishoo/UglifyJS)
# 解决
*用于解决CTF挑战的工具*
## 攻击
*用于执行各种攻击的工具*
- [Bettercap](https://github.com/bettercap/bettercap) - 执行中间人攻击(MITM)的框架。
- [Yersinia](https://github.com/tomac/yersinia) - 攻击第2层的各种协议。
## 密码学
*用于解决密码学挑战的工具*
- [CyberChef](https://gchq.github.io/CyberChef) - 用于分析和解码数据的Web应用。
- [FeatherDuster](https://github.com/nccgroup/featherduster) - 一个自动化的模块化密码分析工具。
- [Hash Extender](https://github.com/iagox86/hash_extender) - 一个用于执行哈希长度扩展攻击的实用工具。
- [padding-oracle-attacker](https://github.com/KishanBagaria/padding-oracle-attacker) - 一个用于执行填充Oracle攻击的CLI工具。
- [PkCrack](https://www.unix-ag.uni-kl.de/~conrad/krypto/pkcrack.html) - 一个用于破解PkZip加密的工具。
- [QuipQuip](https://quipqiup.com) - 一个在线破解替换密码或维吉尼亚密码(无密钥)的工具。
- [RSACTFTool](https://github.com/Ganapati/RsaCtfTool) - 一个使用各种攻击恢复RSA私钥的工具。
- [RSATool](https://github.com/ius/rsatool) - 在已知p和q的情况下生成私钥。
- [XORTool](https://github.com/hellman/xortool) - 一个分析多字节XOR密码的工具。
## 暴力破解器
*用于各种暴力破解(密码等)的工具*
- [Hashcat](https://hashcat.net/hashcat/) - 密码破解器
- [Hydra](https://tools.kali.org/password-attacks/hydra) - 一个并行化的登录破解器,支持多种攻击协议
- [John The Jumbo](https://github.com/magnumripper/JohnTheRipper) - John the Ripper的社区增强版本。
- [John The Ripper](http://www.openwall.com/john/) - 密码破解器。
- [Nozzlr](https://github.com/intrd/nozzlr) - Nozzlr是一个真正模块化且对脚本友好的暴力破解框架。
- [Ophcrack](http://ophcrack.sourceforge.net/) - 基于彩虹表的Windows密码破解器。
- [Patator](https://github.com/lanjelot/patator) - Patator是一个多用途暴力破解器,采用模块化设计。
- [Turbo Intruder](https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack) - Burp Suite扩展,用于发送大量HTTP请求。
## 漏洞利用
*用于解决漏洞利用挑战的工具*
- [DLLInjector](https://github.com/OpenSecurityResearch/dllinjector) - 在进程中注入DLL。
- [libformatstr](https://github.com/hellman/libformatstr) - 简化格式化字符串漏洞利用。
- [Metasploit](http://www.metasploit.com/) - 渗透测试软件。
- [速查表](https://www.comparitech.com/net-admin/metasploit-cheat-sheet/)
- [one_gadget](https://github.com/david942j/one_gadget) - 一个用于查找单个gadget `execve('/bin/sh', NULL, NULL)` 调用的工具。
- `gem install one_gadget`
- [Pwntools](https://github.com/Gallopsled/pwntools) - 用于编写漏洞利用的CTF框架。
- [Qira](https://github.com/BinaryAnalysisPlatform/qira) - QEMU交互式运行时分析器。
- [ROP Gadget](https://github.com/JonathanSalwan/ROPgadget) - ROP漏洞利用框架。
- [V0lt](https://github.com/P1kachu/v0lt) - 安全CTF工具包。
## 取证
*用于解决取证挑战的工具*
- [Aircrack-Ng](http://www.aircrack-ng.org/) - 破解802.11 WEP和WPA-PSK密钥。
- `apt-get install aircrack-ng`
- [Audacity](http://sourceforge.net/projects/audacity/) - 分析声音文件(mp3, m4a等)。
- `apt-get install audacity`
- [Bkhive and Samdump2](http://sourceforge.net/projects/ophcrack/files/samdump2/) - 转储SYSTEM和SAM文件。
- `apt-get install samdump2 bkhive`
- [CFF Explorer](http://www.ntcore.com/exsuite.php) - PE编辑器。
- [Creddump](https://github.com/moyix/creddump) - 转储Windows凭据。
- [DVCS Ripper](https://github.com/kost/dvcs-ripper) - 撕取Web可访问的(分布式)版本控制系统。
- [Exif Tool](http://www.sno.phy.queensu.ca/~phil/exiftool/) - 读取、写入和编辑文件元数据。
- [Extundelete](http://extundelete.sourceforge.net/) - 用于从可挂载映像恢复丢失的数据。
- [Fibratus](https://github.com/rabbitstack/fibratus) - 用于探索和跟踪Windows内核的工具。
- [Foremost](http://foremost.sourceforge.net/) - 使用标头提取特定类型的文件。
- `apt-get install foremost`
- [Fsck.ext4](http://linux.die.net/man/8/fsck.ext3) - 用于修复损坏的文件系统。
- [Malzilla](http://malzilla.sourceforge.net/) - 恶意软件搜寻工具。
- [NetworkMiner](http://www.netresec.com/?page=NetworkMiner) - 网络取证分析工具。
- [PDF Streams Inflater](http://malzilla.sourceforge.net/downloads.html) - 查找并提取PDF文件中压缩的zlib文件。
- [Pngcheck](http://www.libpng.org/pub/png/apps/pngcheck.html) - 验证PNG的完整性,并以人类可读的形式转储所有块级信息。
- `apt-get install pngcheck`
- [ResourcesExtract](http://www.nirsoft.net/utils/resources_extract.html) - 从exe中提取各种文件类型。
- [Shellbags](https://github.com/williballenthin/shellbags) - 调查NT\_USER.dat文件。
- [Snow](https://sbmlabs.com/notes/snow_whitespace_steganography_tool) - 空白隐写工具。
- [USBRip](https://github.com/snovvcrash/usbrip) - 用于在GNU/Linux上跟踪USB设备工件(USB事件历史)的简单CLI取证工具。
- [Volatility](https://github.com/volatilityfoundation/volatility) - 调查内存转储。
- [Wireshark](https://www.wireshark.org) - 用于分析pcap或pcapng文件。
*注册表查看器*
- [OfflineRegistryView](https://www.nirsoft.net/utils/offline_registry_view.html) - 一个简单的Windows工具,允许你从外部驱动器读取脱机注册表文件,并以.reg文件格式查看所需的注册表项。
- [Registry Viewer®](https://accessdata.com/product-download/registry-viewer-2-0-0) - 用于查看Windows注册表。
## 网络
*用于解决网络挑战的工具*
- [Masscan](https://github.com/robertdavidgraham/masscan) - 大规模IP端口扫描器,TCP端口扫描器。
- [Monit](https://linoxide.com/monitoring-2/monit-linux/) - 一个Linux工具,用于检查网络上的主机(以及其他非网络活动)。
- [Nipe](https://github.com/GouveaHeitor/nipe) - Nipe是一个使Tor网络成为默认网关的脚本。
- [Nmap](https://nmap.org/) - 一个开源网络发现和安全审计工具。
- [Wireshark](https://www.wireshark.org/) - 分析网络转储。
- `apt-get install wireshark`
- [Zeek](https://www.zeek.org) - 一个开源网络安全监控器。
- [Zmap](https://zmap.io/) - 一个开源网络扫描器。
## 逆向
*用于解决逆向挑战的工具*
- [Androguard](https://github.com/androguard/androguard) - 逆向工程Android应用程序。
- [Angr](https://github.com/angr/angr) - 平台无关的二进制分析框架。
- [Apk2Gold](https://github.com/lxdvs/apk2gold) - 又一个Android反编译器。
- [ApkTool](http://ibotpeaches.github.io/Apktool/) - Android反编译器。
- [Barf](https://github.com/programa-stic/barf-project) - 二进制分析与逆向工程框架。
- [Binary Ninja](https://binary.ninja/) - 二进制分析框架。
- [BinUtils](http://www.gnu.org/software/binutils/binutils.html) - 二进制工具集合。
- [BinWalk](https://github.com/devttys0/binwalk) - 分析、逆向工程和提取固件映像。
- [Boomerang](https://github.com/BoomerangDecompiler/boomerang) - 将x86/SPARC/PowerPC/ST-20二进制文件反编译为C。
- [ctf_import](https://github.com/docileninja/ctf_import) – 跨平台运行去除符号的二进制文件的基本函数。
- [cwe_checker](https://github.com/fkie-cad/cwe_checker) - cwe_checker在二进制可执行文件中查找易受攻击的模式。
- [demovfuscator](https://github.com/kirschju/demovfuscator) - 一个正在进行中的、用于解除movfuscated二进制文件混淆的工具。
- [Frida](https://github.com/frida/) - 动态代码注入。
- [GDB](https://www.gnu.org/software/gdb/) - GNU项目调试器。
- [GEF](https://github.com/hugsy/gef) - GDB插件。
- [Ghidra](https://ghidra-sre.org/) - 开源逆向工程工具套件。类似于IDA Pro。
- [Hopper](http://www.hopperapp.com/) - 用于OSX和Linux的逆向工程工具(反汇编器)。
- [IDA Pro](https://www.hex-rays.com/products/ida/) - 最常用的逆向工程软件。
- [Jadx](https://github.com/skylot/jadx) - 反编译Android文件。
- [Java Decompilers](http://www.javadecompilers.com) - 一个用于Java和Android APK的在线反编译器。
- [Krakatau](https://github.com/Storyyeller/Krakatau) - Java反编译器和反汇编器。
- [Objection](https://github.com/sensepost/objection) - 运行时移动设备探索。
- [PEDA](https://github.com/longld/peda) - GDB插件(仅支持python2.7)。
- [Pin](https://software.intel.com/en-us/articles/pin-a-dynamic-binary-instrumentation-tool) - Intel的动态二进制插桩工具。
- [PINCE](https://github.com/korcankaraokcu/PINCE) - GDB前端/逆向工程工具,专注于游戏破解和自动化。
- [PinCTF](https://github.com/ChrisTheCoolHut/PinCTF) - 一个使用Intel Pin进行侧信道分析的工具。
- [Plasma](https://github.com/joelpx/plasma) - 一个交互式反汇编器,支持x86/ARM/MIPS,可以生成带有彩色语法的缩进伪代码。
- [Pwndbg](https://github.com/pwndbg/pwndbg) - 一个GDB插件,提供一套实用工具以便更容易地使用GDB。
- [radare2](https://github.com/radare/radare2) - 一个可移植的逆向框架。
- [Triton](https://github.com/JonathanSalwan/Triton/) - 动态二进制分析(DBA)框架。
- [Uncompyle](https://github.com/gstarnberger/uncompyle) - 反编译Python 2.7二进制文件(.pyc)。
- [WinDbg](http://www.windbg.org/) - 微软分发的Windows调试器。
- [Xocopy](http://reverse.lostrealm.com/tools/xocopy.html) - 一个可以复制具有执行权限但无读取权限的可执行文件的程序。
- [Z3](https://github.com/Z3Prover/z3) - 微软研究院的定理证明器。
*JavaScript反混淆器*
- [Detox](http://relentless-coding.org/projects/jsdetox/install) - 一个JavaScript恶意软件分析工具。
- [Revelo](http://www.kahusecurity.com/posts/revelo_javascript_deobfuscator.html) - 分析混淆的JavaScript代码。
*SWF分析器*
- [RABCDAsm](https://github.com/CyberShadow/RABCDAsm) - 实用工具集合,包括ActionScript 3汇编器/反汇编器。
- [Swftools](http://www.swftools.org/) - 用于处理SWF文件的实用工具集合。
- [Xxxswf](https://bitbucket.org/Alexander_Hanel/xxxswf) - 一个用于分析Flash文件的Python脚本。
## 服务
*互联网上可用的各种有用服务*
- [CSWSH](http://cow.cat/cswsh.html) - 跨站WebSocket劫持测试器。
- [Request Bin](https://requestbin.com/) - 允许你检查发送到特定URL的HTTP请求。
## 隐写
*用于解决隐写挑战的工具*
- [AperiSolve](https://aperisolve.fr/) - Aperi'Solve是一个对图像进行层分析的平台(开源)。
- [Convert](http://www.imagemagick.org/script/convert.php) - 在格式间转换图像并应用滤镜。
- [Exif](http://manpages.ubuntu.com/manpages/trusty/man1/exif.1.html) - 显示JPEG文件中的EXIF信息。
- [Exiftool](https://linux.die.net/man/1/exiftool) - 读取和写入文件中的元信息。
- [Exiv2](http://www.exiv2.org/manpage.html) - 图像元数据操作工具。
- [Image Steganography](https://sourceforge.net/projects/image-steg/) - 将文本和文件嵌入图像中,可选加密。易于使用的UI。
- [Image Steganography Online](https://incoherency.co.uk/image-steganography) - 这是一个客户端的JavaScript工具,用于将图像隐写地隐藏在另一个图像的低位中。
- [ImageMagick](http://www.imagemagick.org/script/index.php) - 用于操作图像的工具。
- [Outguess](https://www.freebsd.org/cgi/man.cgi?query=outguess+&apropos=0&sektion=0&manpath=FreeBSD+Ports+5.1-RELEASE&format=html) - 通用隐写工具。
- [Pngtools](https://packages.debian.org/sid/pngtools) - 用于与PNG相关的各种分析。
- `apt-get install pngtools`
- [SmartDeblur](https://github.com/Y-Vladimir/SmartDeblur) - 用于去模糊和修复失焦图像。
- [Steganabara](https://www.openhub.net/p/steganabara) - 用Java编写的隐写分析工具。
- [SteganographyOnline](https://stylesuxx.github.io/steganography/) - 在线隐写编码器和解码器。
- [Stegbreak](https://linux.die.net/man/1/stegbreak) - 对JPG图像发起暴力字典攻击。
- [StegCracker](https://github.com/Paradoxis/StegCracker) - 用于发现文件中隐藏数据的隐写暴力破解工具。
- [stegextract](https://github.com/evyatarmeged/stegextract) - 检测图像中的隐藏文件和文本。
- [Steghide](http://steghide.sourceforge.net/) - 将数据隐藏在各种类型的图像中。
- [StegOnline](https://georgeom.net/StegOnline/upload) - 执行广泛的图像隐写操作,例如隐藏/揭示隐藏在比特中的文件(开源)。
- [Stegsolve](http://www.caesum.com/handbook/Stegsolve.jar) - 对图像应用各种隐写技术。
- [Zsteg](https://github.com/zed-0xff/zsteg/) - PNG/BMP分析。
## Web
*用于解决Web挑战的工具*
- [BurpSuite](https://portswigger.net/burp) - 一个用于测试网站安全性的图形化工具。
- [Commix](https://github.com/commixproject/commix) - 自动化的全能OS命令注入和利用工具。
- [Hackbar](https://addons.mozilla.org/en-US/firefox/addon/hackbartool/) - 用于轻松进行Web漏洞利用的Firefox插件。
- [OWASP ZAP](https://www.owasp.org/index.php/Projects/OWASP_Zed_Attack_Proxy_Project) - 拦截代理,用于重放、调试和模糊HTTP请求和响应。
- [Postman](https://chrome.google.com/webstore/detail/postman/fhbjgbiflinjbdggehcddcbncdddomop?hl=en) - 用于调试网络请求的Chrome扩展。
- [Raccoon](https://github.com/evyatarmeged/Raccoon) - 一个高性能的进攻性安全工具,用于侦察和漏洞扫描。
- [SQLMap](https://github.com/sqlmapproject/sqlmap) - 自动SQL注入和数据库接管工具。 ```pip install sqlmap```
- [W3af](https://github.com/andresriancho/w3af) - Web Application Attack and Audit Framework.
- [XSSer](http://xsser.sourceforge.net/) - Automated XSS testor.
# Resources
*Where to discover about CTF*
## Operating Systems
*Penetration testing and security lab Operating Systems*
- [Android Tamer](https://androidtamer.com/) - Based on Debian.
- [BackBox](https://backbox.org/) - Based on Ubuntu.
- [BlackArch Linux](https://blackarch.org/) - Based on Arch Linux.
- [Fedora Security Lab](https://labs.fedoraproject.org/security/) - Based on Fedora.
- [Kali Linux](https://www.kali.org/) - Based on Debian.
- [Parrot Security OS](https://www.parrotsec.org/) - Based on Debian.
- [Pentoo](http://www.pentoo.ch/) - Based on Gentoo.
- [URIX OS](http://urix.us/) - Based on openSUSE.
- [Wifislax](http://www.wifislax.com/) - Based on Slackware.
*Malware analysts and reverse-engineering*
- [Flare VM](https://github.com/fireeye/flare-vm/) - Based on Windows.
- [REMnux](https://remnux.org/) - Based on Debian.
## Starter Packs
*Collections of installer scripts, useful tools*
- [CTF Tools](https://github.com/zardus/ctf-tools) - Collection of setup scripts to install various security research tools.
- [LazyKali](https://github.com/jlevitsk/lazykali) - A 2016 refresh of LazyKali which simplifies install of tools and configuration.
## Tutorials
*Tutorials to learn how to play CTFs*
- [CTF Field Guide](https://trailofbits.github.io/ctf/) - Field Guide by Trails of Bits.
- [CTF Resources](http://ctfs.github.io/resources/) - Start Guide maintained by community.
- [How to Get Started in CTF](https://www.endgame.com/blog/how-get-started-ctf) - Short guideline for CTF beginners by Endgame
- [Intro. to CTF Course](https://www.hoppersroppers.org/courseCTF.html) - A free course that teaches beginners the basics of forensics, crypto, and web-ex.
- [IppSec](https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA) - Video tutorials and walkthroughs of popular CTF platforms.
- [LiveOverFlow](https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w) - Video tutorials on Exploitation.
- [MIPT CTF](https://github.com/xairy/mipt-ctf) - A small course for beginners in CTFs (in Russian).
## Wargames
*Always online CTFs*
- [Backdoor](https://backdoor.sdslabs.co/) - Security Platform by SDSLabs.
- [Crackmes](https://crackmes.one/) - Reverse Engineering Challenges.
- [CryptoHack](https://cryptohack.org/) - Fun cryptography challenges.
- [echoCTF.RED](https://echoctf.red/) - Online CTF with a variety of targets to attack.
- [Exploit Exercises](https://exploit-exercises.lains.space/) - Variety of VMs to learn variety of computer security issues.
- [Exploit.Education](http://exploit.education) - Variety of VMs to learn variety of computer security issues.
- [Gracker](https://github.com/Samuirai/gracker) - Binary challenges having a slow learning curve, and write-ups for each level.
- [Hack The Box](https://www.hackthebox.eu) - Weekly CTFs for all types of security enthusiasts.
- [Hack This Site](https://www.hackthissite.org/) - Training ground for hackers.
- [Hacker101](https://www.hacker101.com/) - CTF from HackerOne
- [Hacking-Lab](https://hacking-lab.com/) - Ethical hacking, computer network and security challenge platform.
- [Hone Your Ninja Skills](https://honeyourskills.ninja/) - Web challenges starting from basic ones.
- [IO](http://io.netgarage.org/) - Wargame for binary challenges.
- [Microcorruption](https://microcorruption.com) - Embedded security CTF.
- [Over The Wire](http://overthewire.org/wargames/) - Wargame maintained by OvertheWire Community.
- [PentesterLab](https://pentesterlab.com/) - Variety of VM and online challenges (paid).
- [PicoCTF](https://2019game.picoctf.com) - All year round ctf game. Questions from the yearly picoCTF competition.
- [PWN Challenge](http://pwn.eonew.cn/) - Binary Exploitation Wargame.
- [Pwnable.kr](http://pwnable.kr/) - Pwn Game.
- [Pwnable.tw](https://pwnable.tw/) - Binary wargame.
- [Pwnable.xyz](https://pwnable.xyz/) - Binary Exploitation Wargame.
- [Reversin.kr](http://reversing.kr/) - Reversing challenge.
- [Ringzer0Team](https://ringzer0team.com/) - Ringzer0 Team Online CTF.
- [Root-Me](https://www.root-me.org/) - Hacking and Information Security learning platform.
- [ROP Wargames](https://github.com/xelenonz/game) - ROP Wargames.
- [SANS HHC](https://holidayhackchallenge.com/past-challenges/) - Challenges with a holiday theme
released annually and maintained by SANS.
- [SmashTheStack](http://smashthestack.org/) - A variety of wargames maintained by the SmashTheStack Community.
- [Viblo CTF](https://ctf.viblo.asia) - Various amazing CTF challenges, in many different categories. Has both Practice mode and Contest mode.
- [VulnHub](https://www.vulnhub.com/) - VM-based for practical in digital security, computer application & network administration.
- [W3Challs](https://w3challs.com) - A penetration testing training platform, which offers various computer challenges, in various categories.
- [WebHacking](http://webhacking.kr) - Hacking challenges for web.
*Self-hosted CTFs*
- [Damn Vulnerable Web Application](http://www.dvwa.co.uk/) - PHP/MySQL web application that is damn vulnerable.
- [Juice Shop CTF](https://github.com/bkimminich/juice-shop-ctf) - Scripts and tools for hosting a CTF on [OWASP Juice Shop](https://www.owasp.org/index.php/OWASP_Juice_Shop_Project) easily.
## Websites
*Various general websites about and on CTF*
- [Awesome CTF Cheatsheet](https://github.com/uppusaikiran/awesome-ctf-cheatsheet#awesome-ctf-cheatsheet-) - CTF Cheatsheet.
- [CTF Time](https://ctftime.org/) - General information on CTF occuring around the worlds.
- [Reddit Security CTF](http://www.reddit.com/r/securityctf) - Reddit CTF category.
## Wikis
*Various Wikis available for learning about CTFs*
- [Bamboofox](https://bamboofox.github.io/) - Chinese resources to learn CTF.
- [bi0s Wiki](https://teambi0s.gitlab.io/bi0s-wiki/) - Wiki from team bi0s.
- [CTF Cheatsheet](https://uppusaikiran.github.io/hacking/Capture-the-Flag-CheatSheet/) - CTF tips and tricks.
- [ISIS Lab](https://github.com/isislab/Project-Ideas/wiki) - CTF Wiki by Isis lab.
- [OpenToAll](https://github.com/OpenToAllCTF/Tips) - CTF tips by OTA CTF team members.
## Writeups Collections
*Collections of CTF write-ups*
- [0e85dc6eaf](https://github.com/0e85dc6eaf/CTF-Writeups) - Write-ups for CTF challenges by 0e85dc6eaf
- [Captf](http://captf.com/) - Dumped CTF challenges and materials by psifertex.
- [CTF write-ups (community)](https://github.com/ctfs/) - CTF challenges + write-ups archive maintained by the community.
- [CTFTime Scrapper](https://github.com/abdilahrf/CTFWriteupScrapper) - Scraps all writeup from CTF Time and organize which to read first.
- [HackThisSite](https://github.com/HackThisSite/CTF-Writeups) - CTF write-ups repo maintained by HackThisSite team.
- [Mzfr](https://github.com/mzfr/ctf-writeups/) - CTF competition write-ups by mzfr
- [pwntools writeups](https://github.com/Gallopsled/pwntools-write-ups) - A collection of CTF write-ups all using pwntools.
- [SababaSec](https://github.com/SababaSec/ctf-writeups) - A collection of CTF write-ups by the SababaSec team
- [Shell Storm](http://shell-storm.org/repo/CTF/) - CTF challenge archive maintained by Jonathan Salwan.
- [Smoke Leet Everyday](https://github.com/smokeleeteveryday/CTF_WRITEUPS) - CTF write-ups repo maintained by SmokeLeetEveryday team.
### LICENSE
CC0 :)