References
Indexes, wordlists, and lookups — linked to their upstream sources.
- Open ↗Assetnote Wordlistscontent-discovery
Automatically-generated, regularly-refreshed content-discovery and subdomain wordlists; named as a companion collection worth adding as a data source.
- Open ↗awesome-vulnerable-apps (vavkamil)reference-index
Curated index of vulnerable applications organized by single vulnerability class (CORS, SSRF, XXE, XSS, request smuggling, etc.), useful for practicing one technique in isolation.
- Open ↗CISA KEV (Known Exploited Vulnerabilities Catalog)vuln-intel-reference
CISA's authoritative catalog of vulnerabilities known to be actively exploited in the wild, used as a hard prioritization override.
- Open ↗EPSS (Exploit Prediction Scoring System)vuln-intel-reference
FIRST.org's data-driven model estimating the probability a CVE will be exploited in the wild; used to prioritize actually-exploitable vulnerabilities.
- Open ↗HackTrickspentest-knowledge-base
Widely-used community knowledge base of pentesting and web-security techniques (e.g. WAF/rate-limit bypass tactics referenced in the audit).
- Open ↗NVD (National Vulnerability Database)vuln-intel-reference
NIST's national vulnerability database — CVE records with CVSS scoring and CPE mappings; a core vuln-intelligence data source.
- Open ↗OWASP VWAD (Vulnerable Web Applications Directory)reference-index
OWASP's directory of deliberately vulnerable web applications for security practice, cataloguing offline, online, and containerized targets.
- Open ↗
Community collection of payloads and bypass techniques organized by vulnerability class; a companion data source referenced alongside SecLists.
- Open ↗PortSwigger Researchtechnique-writeups
PortSwigger's web-security research writeups, cited as an authoritative source for polyglot and injection technique maintenance (educational reference, not a payload dump).
- Open ↗rmusser01/Infosec_Referencereference-index
Whole-of-infosec link and technique index spanning web attacks, fuzzing, passwords, and methodology references.
- Open ↗
Scraped list of common JWT signing secrets, used to crack weak HS256-signed tokens; named as a data source to vendor for JWT probes.
- Open ↗
~4,700 common web paths and filenames for content discovery. Hosted here for authorized testing.
- Open ↗
~30,000 directory names (RAFT medium) for content discovery. Hosted here for authorized testing.
- Open ↗
Common REST API route segments for endpoint discovery. Hosted here for authorized testing.
- Open ↗
~6,400 common HTTP parameter names for parameter discovery. Hosted here for authorized testing.
- Open ↗
Common GraphQL field names for schema exploration. Hosted here for authorized testing.
- Open ↗
Common GraphQL argument names for schema exploration. Hosted here for authorized testing.
- Open ↗
Exposed-file name checks (.git, .env, backups, configs). Hosted here for authorized testing.
- Open ↗
Parameter names used to probe for prototype pollution. Hosted here for authorized testing.
- Open ↗
A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.
- Open ↗
A maintained collection of roughly 13,760 Google search queries (dorks) in a single text file for locating publicly indexed sites and exposed files/vulnerabilities via search-engine syntax.
- Open ↗
A curated list of AI/ML security resources organized into adversarial examples, evasion attacks, poisoning attacks, feature selection, and code (e.g. CleverHans, Foolbox). Aggregates papers, libraries, videos, and blog posts on attacking and defending ML systems.
- Open ↗
A community-maintained catalog of services (80+) vulnerable to subdomain takeover, with per-service status, regex fingerprints for identifying vulnerable endpoints, and CI verification. Includes guidance for demonstrating takeovers responsibly.
- Open ↗
A large, widely-used index of curated security awesome-lists for hackers, pentesters, and researchers, spanning 50+ domains including web hacking, bug bounty, malware analysis, OSINT, Android, IoT, forensics, and cryptography.
- Open ↗Hacker Roadmaplearning-roadmap
Structured cybersecurity learning roadmaps for several tracks (hobbyist, accelerated entry, bug-bounty hunter, certification, degree), pointing to platforms like TryHackMe, Hack The Box, and PortSwigger Academy and to CompTIA/OffSec certification paths.
- Open ↗OWASP MASTGpentest-knowledge-base
The OWASP Mobile Application Security Testing Guide: a comprehensive manual for mobile app security testing and reverse engineering on Android and iOS. Covers static and dynamic analysis, runtime and network-traffic analysis, cryptography testing, and mobile penetration-testing methodology, mapped to the OWASP MASVS standard and MASWE weakness enumeration.
- Open ↗
A curated reference collection by iOS security researcher Siguza covering ARM architecture, Mach-O internals, sandboxing/IPC, kernel design, and iOS mitigations (KTRR, PPL, SPRR, PAN, PAC, MTE), alongside write-ups of real iOS vulnerabilities and exploitation chains. It links primarily to vendor docs, academic papers, and post-mortem research.
- Open ↗
A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.
- Open ↗
A community-maintained database of malicious Chrome/Edge extension indicators of compromise, cataloguing credential stealers, browser hijackers, supply-chain compromises, and ad-fraud campaigns. It publishes in plain-text blocklist, JSON, Sigma, STIX 2.1, and MISP formats with a multi-stage verification protocol.
- Open ↗
Automated and manually-curated wordlists for content and subdomain discovery, regenerated monthly (via Commonspeak2 and GitHub Actions) targeting popular internet technologies. Apache-2.0 licensed, served via CDN with a browsable DataTables interface and bulk wget download.
- Open ↗Bug Bounty Disclosed Reportstechnique-writeups
A curated archive of publicly disclosed bug bounty reports in Markdown, each covering vulnerability type, impact, reproduction steps, remediation and links to the original disclosure. Organized under a /reports directory as an educational reference for security researchers and developers.
- Open ↗Insider Threat TTP Knowledge Basethreat-informed-defense
A Center for Threat-Informed Defense knowledge base of tactics, techniques and procedures used by insiders, built from documented incidents and mapped to MITRE ATT&CK. Published in CSV, JSON and ATT&CK Navigator formats under Apache-2.0 to help defenders detect and mitigate insider threats.
- Open ↗VulnRAGvuln-intel-reference
A vulnerability-intelligence platform that aggregates CVEs from seven public sources (GHSA, NVD, CVEfixes, MegaVul, BigVul, MoreFixes, Security DPO) into a canonical schema and indexes them with vector embeddings for code-similarity, pattern-based, cross-project and natural-language search. Built on Python/FastAPI with ChromaDB and transformer embeddings, it can also generate Semgrep/CodeQL detection rules and exposes REST and CLI interfaces.
- Open ↗
An empirical, practical guide to LLM hacking from security firm Forces Unseen, covering prompt injection, offensive and defensive techniques, and interactive playgrounds. Source for the handbook hosted at doublespeak.chat.
- Open ↗Free CyberSecurity Professional Development Resourcesreference-index
A curated collection of free cybersecurity training and professional-development resources organized into 10 categories (conferences, webinars/labs, training, books, college courses, podcasts, YouTube channels, news, communities, and references/tools/cheat sheets). Some listings (conferences/webinars) are no longer actively maintained.
- Open ↗
Curated catalogue of macOS/iOS security research: a large CVE table (2014–2025) mapped to affected components with links to technical write-ups, plus references to analysis tools (IOKit probing, dyld cache analysis, kernel driver analyzers), fuzzing frameworks, and conference talks (Black Hat, CanSecWest, DEFCON).
- Open ↗Awesome Threat Intelligencevuln-intel-reference
Curated list of threat-intelligence resources organized into sources (100+ feeds like AbuseIPDB, GreyNoise, URLhaus), exchange formats (STIX/TAXII/MAEC), frameworks/platforms (MISP, OpenCTI, IntelMQ), analysis tools, and research/standards (MITRE ATT&CK, Diamond Model). ~10.5k stars.
- Open ↗Awesome OSINTreference-index
Large curated index of open-source-intelligence tools and resources across search engines (incl. dark web), social-media intelligence, domain/IP research, email verification, people investigation, data-breach search, and geospatial tooling. ~28k stars.
- Open ↗Awesome Cyber Skillsreference-index
Curated list of 100+ free, legal environments for practicing offensive security: deliberately-vulnerable apps (DVWA, Juice Shop, WebGoat, Mutillidae), CTF platforms (HackTheBox, TryHackMe, picoCTF, Root-Me), wargames (OverTheWire, pwnable.kr), and specialized labs for crypto, RE, and binary exploitation.
- Open ↗
Collection of payloads for AI red teaming, organized around the OWASP AITG-APP (AI Testing Guide) categories. A reference set of adversarial prompt/test payloads for authorized LLM/AI application security testing rather than executable malware.
- Open ↗
A curated catalogue of command-and-control (C2) frameworks that abuse legitimate services (cloud APIs, messaging platforms) to evade detection, tracking abused services, open-source C2 projects, and associated detection rules with network/file/behavioral IOCs.
- Open ↗
A pentesting and VAPT/AppSec knowledge base spanning 23 security domains (web, mobile, API, cloud, network, LLM, MCP security), aggregating methodologies, 100+ reference PDFs, 200+ tools organized by category, and an AI-assisted pentest agent skill.
- Open ↗
A curated index of publicly disclosed bug bounty write-ups organized by vulnerability type (XSS, SQLi, CSRF, RCE, SSRF, auth bypass, etc.), linking out to the original researcher reports.
- Open ↗
A repository that aggregates and ranks disclosed HackerOne bug bounty reports, categorizing them by vulnerability type (XSS, SQLi, RCE, SSRF, etc.) and by affected program, linking out to the original disclosures.
- Open ↗LLM4Pentestreference-index
A curated index of resources on applying LLMs to automated penetration testing: 105+ academic papers grouped into systems/agents, benchmarks/cyber-ranges, empirical evaluations, surveys, and defense/ethics, plus links to code repositories (PentestGPT, VulnBot, Shannon and others) and evaluation benchmarks. Tied to the paper 'Hackers or Hallucinators?'.
- Open ↗Awesome Burp Extensionsreference-index
A curated, categorized index of Burp Suite extensions for web application penetration testing, organized by domain: active/passive scanners, decoders/beautifiers, cloud security (AWS/Azure/GCP), auth testing (OAuth/SAML/JWT/SSO), vulnerability-specific plugins (XSS/SQLi/CSRF/XXE/SSRF), WAF evasion, integrations (Nuclei/Elasticsearch), and payload/fuzzing generators.
- Open ↗
A study/reference repository for OSCP exam preparation with command references organized by tool (Nmap, Hydra, Hashcat, Wfuzz, Cewl), technique notes on reverse shells, privilege escalation, Active Directory, buffer overflow, SQLi and XSS, plus write-ups from HackTheBox, VulnHub, Proving Grounds and TryHackMe.
- Open ↗
A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.
- Open ↗
A curated collection of hacking, penetration-testing, and AI red-teaming learning resources: educational courses, YouTube channels, skill-building platforms (HackTheBox, TryHackMe, CTFs), reverse-engineering/privesc/OSINT/malware-analysis training, vulnerable practice apps, exploit databases, and pentest distros (Kali, ParrotOS, BlackArch).
- Open ↗
A structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).
- Open ↗
A community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.
- Open ↗Security Certification Roadmapcertification-roadmap
A reference chart by Paul Jerimy cataloging roughly 480 cybersecurity certifications, organized by specialty domain (network/communications security, cloud, penetration testing, forensics, incident handling, GRC) and by experience tier from foundational to expert, spanning issuers such as GIAC, CompTIA, EC-Council, and Cisco.
- Open ↗The Anatomy of a Prompt Injectionprompt-injection
A research paper proposing a component model for the structured analysis of prompt-injection attacks — decomposing an injection into its functional parts (the framing that terminates trusted context, fake system tags, the payload) so defenders can reason about and detect them systematically.
- Open ↗AI Security Institute — Research Blogmodel-evaluation-research
Primary research from the UK AI Security Institute (DSIT): frontier-model cyber-capability evaluations, safeguard and jailbreak testing, and incident reports from their own agent testing.
- Open ↗AI Megalistreference-index
MIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.
- Open ↗
MIT-licensed catalogue of open-source generative-AI SaaS templates (image, video, virtual try-on, writing, chatbots, voice) on a shared Next.js/Stripe/Google-OAuth stack, built to be forked and resold; no security content.
- Open ↗
Dataset of 15,140 in-the-wild prompts collected from Reddit, Discord, websites and open-source datasets, 1,405 of them jailbreaks, plus a 390-question forbidden-scenario set for measuring jailbreak effectiveness.
- Open ↗
Dataset of harmful-behaviour prompts (drug, chemical, biological, radiological, nuclear, explosive) and a reference PRBO reward function for training jailbreaking agents; the RL training loop is not included.
- Open ↗
README-only collection of copy-paste jailbreak prompts for DeepSeek R1, Grok 3, Gemini 2.0, ChatGPT (DAN), Claude 2 and Llama 2, plus a Gemini system-prompt leak prompt, mostly reposted from linked Reddit, blog and GitHub posts.
- Open ↗
Vendor-organised collection of files, mostly Markdown, presenting what it says are the verbatim system prompts of major chatbots and coding agents (Anthropic, OpenAI, Google, xAI, Cursor, Kimi and others), with a dated additions table and an open invitation to PRs.