All resources

References

Indexes, wordlists, and lookups — linked to their upstream sources.

61 shown
  1. Assetnote Wordlistscontent-discovery

    Automatically-generated, regularly-refreshed content-discovery and subdomain wordlists; named as a companion collection worth adding as a data source.

    Open ↗
  2. Curated index of vulnerable applications organized by single vulnerability class (CORS, SSRF, XXE, XSS, request smuggling, etc.), useful for practicing one technique in isolation.

    Open ↗
  3. CISA's authoritative catalog of vulnerabilities known to be actively exploited in the wild, used as a hard prioritization override.

    Open ↗
  4. FIRST.org's data-driven model estimating the probability a CVE will be exploited in the wild; used to prioritize actually-exploitable vulnerabilities.

    Open ↗
  5. HackTrickspentest-knowledge-base

    Widely-used community knowledge base of pentesting and web-security techniques (e.g. WAF/rate-limit bypass tactics referenced in the audit).

    Open ↗
  6. NIST's national vulnerability database — CVE records with CVSS scoring and CPE mappings; a core vuln-intelligence data source.

    Open ↗
  7. OWASP's directory of deliberately vulnerable web applications for security practice, cataloguing offline, online, and containerized targets.

    Open ↗
  8. PayloadsAllTheThingstechnique-and-payload-referencedual-use

    Community collection of payloads and bypass techniques organized by vulnerability class; a companion data source referenced alongside SecLists.

    Open ↗
  9. PortSwigger Researchtechnique-writeups

    PortSwigger's web-security research writeups, cited as an authoritative source for polyglot and injection technique maintenance (educational reference, not a payload dump).

    Open ↗
  10. Whole-of-infosec link and technique index spanning web attacks, fuzzing, passwords, and methodology references.

    Open ↗
  11. SecListsdiscovery/fuzzing/payloadsdual-use

    Curated collection of security-testing wordlists and payload corpora across nine content areas (Discovery, Fuzzing, Passwords, Usernames, Payloads, Web-Shells, and more).

    Open ↗
  12. Wallarm JWT Secrets (jwt-secret)jwt-signing-secretsdual-use

    Scraped list of common JWT signing secrets, used to crack weak HS256-signed tokens; named as a data source to vendor for JWT probes.

    Open ↗
  13. Common paths wordlistwordlistdual-use

    ~4,700 common web paths and filenames for content discovery. Hosted here for authorized testing.

    Open ↗
  14. ~30,000 directory names (RAFT medium) for content discovery. Hosted here for authorized testing.

    Open ↗
  15. API endpoints wordlistwordlistdual-use

    Common REST API route segments for endpoint discovery. Hosted here for authorized testing.

    Open ↗
  16. HTTP parameters wordlistwordlistdual-use

    ~6,400 common HTTP parameter names for parameter discovery. Hosted here for authorized testing.

    Open ↗
  17. GraphQL fields wordlistwordlistdual-use

    Common GraphQL field names for schema exploration. Hosted here for authorized testing.

    Open ↗
  18. Common GraphQL argument names for schema exploration. Hosted here for authorized testing.

    Open ↗
  19. Sensitive files wordlistwordlistdual-use

    Exposed-file name checks (.git, .env, backups, configs). Hosted here for authorized testing.

    Open ↗
  20. Parameter names used to probe for prototype pollution. Hosted here for authorized testing.

    Open ↗
  21. Awesome Bug Bounty Buildertechnique-writeupsdual-uselicence

    A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.

    Open ↗
  22. Google Dork Listgoogle-dorksdual-use

    A maintained collection of roughly 13,760 Google search queries (dorks) in a single text file for locating publicly indexed sites and exposed files/vulnerabilities via search-engine syntax.

    Open ↗
  23. Awesome AI Securityreference-indexdual-use

    A curated list of AI/ML security resources organized into adversarial examples, evasion attacks, poisoning attacks, feature selection, and code (e.g. CleverHans, Foolbox). Aggregates papers, libraries, videos, and blog posts on attacking and defending ML systems.

    Open ↗
  24. Can I take over xyz?vuln-intel-referencedual-use

    A community-maintained catalog of services (80+) vulnerable to subdomain takeover, with per-service status, regex fingerprints for identifying vulnerable endpoints, and CI verification. Includes guidance for demonstrating takeovers responsibly.

    Open ↗
  25. Awesome Hackingreference-indexdual-use

    A large, widely-used index of curated security awesome-lists for hackers, pentesters, and researchers, spanning 50+ domains including web hacking, bug bounty, malware analysis, OSINT, Android, IoT, forensics, and cryptography.

    Open ↗
  26. Hacker Roadmaplearning-roadmap

    Structured cybersecurity learning roadmaps for several tracks (hobbyist, accelerated entry, bug-bounty hunter, certification, degree), pointing to platforms like TryHackMe, Hack The Box, and PortSwigger Academy and to CompTIA/OffSec certification paths.

    Open ↗
  27. OWASP MASTGpentest-knowledge-base

    The OWASP Mobile Application Security Testing Guide: a comprehensive manual for mobile app security testing and reverse engineering on Android and iOS. Covers static and dynamic analysis, runtime and network-traffic analysis, cryptography testing, and mobile penetration-testing methodology, mapped to the OWASP MASVS standard and MASWE weakness enumeration.

    Open ↗
  28. iOS Hacking Resourcesreference-indexdual-use

    A curated reference collection by iOS security researcher Siguza covering ARM architecture, Mach-O internals, sandboxing/IPC, kernel design, and iOS mitigations (KTRR, PPL, SPRR, PAN, PAC, MTE), alongside write-ups of real iOS vulnerabilities and exploitation chains. It links primarily to vendor docs, academic papers, and post-mortem research.

    Open ↗
  29. Google Dorks for Bug Bountytechnique-and-payload-referencedual-usepassive

    A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.

    Open ↗
  30. chrome-mal-idsvuln-intel-referencepassive

    A community-maintained database of malicious Chrome/Edge extension indicators of compromise, cataloguing credential stealers, browser hijackers, supply-chain compromises, and ad-fraud campaigns. It publishes in plain-text blocklist, JSON, Sigma, STIX 2.1, and MISP formats with a multi-stage verification protocol.

    Open ↗
  31. Assetnote Wordlistscontent-discoverydual-use

    Automated and manually-curated wordlists for content and subdomain discovery, regenerated monthly (via Commonspeak2 and GitHub Actions) targeting popular internet technologies. Apache-2.0 licensed, served via CDN with a browsable DataTables interface and bulk wget download.

    Open ↗
  32. A curated archive of publicly disclosed bug bounty reports in Markdown, each covering vulnerability type, impact, reproduction steps, remediation and links to the original disclosure. Organized under a /reports directory as an educational reference for security researchers and developers.

    Open ↗
  33. Insider Threat TTP Knowledge Basethreat-informed-defense

    A Center for Threat-Informed Defense knowledge base of tactics, techniques and procedures used by insiders, built from documented incidents and mapped to MITRE ATT&CK. Published in CSV, JSON and ATT&CK Navigator formats under Apache-2.0 to help defenders detect and mitigate insider threats.

    Open ↗
  34. VulnRAGvuln-intel-reference

    A vulnerability-intelligence platform that aggregates CVEs from seven public sources (GHSA, NVD, CVEfixes, MegaVul, BigVul, MoreFixes, Security DPO) into a canonical schema and indexes them with vector embeddings for code-similarity, pattern-based, cross-project and natural-language search. Built on Python/FastAPI with ChromaDB and transformer embeddings, it can also generate Semgrep/CodeQL detection rules and exposes REST and CLI interfaces.

    Open ↗
  35. LLM Hacker's Handbookpentest-knowledge-basedual-use

    An empirical, practical guide to LLM hacking from security firm Forces Unseen, covering prompt injection, offensive and defensive techniques, and interactive playgrounds. Source for the handbook hosted at doublespeak.chat.

    Open ↗
  36. A curated collection of free cybersecurity training and professional-development resources organized into 10 categories (conferences, webinars/labs, training, books, college courses, podcasts, YouTube channels, news, communities, and references/tools/cheat sheets). Some listings (conferences/webinars) are no longer actively maintained.

    Open ↗
  37. macOS-iOS-system-securitytechnique-writeupsdual-use

    Curated catalogue of macOS/iOS security research: a large CVE table (2014–2025) mapped to affected components with links to technical write-ups, plus references to analysis tools (IOKit probing, dyld cache analysis, kernel driver analyzers), fuzzing frameworks, and conference talks (Black Hat, CanSecWest, DEFCON).

    Open ↗
  38. Awesome Threat Intelligencevuln-intel-reference

    Curated list of threat-intelligence resources organized into sources (100+ feeds like AbuseIPDB, GreyNoise, URLhaus), exchange formats (STIX/TAXII/MAEC), frameworks/platforms (MISP, OpenCTI, IntelMQ), analysis tools, and research/standards (MITRE ATT&CK, Diamond Model). ~10.5k stars.

    Open ↗
  39. Awesome OSINTreference-index

    Large curated index of open-source-intelligence tools and resources across search engines (incl. dark web), social-media intelligence, domain/IP research, email verification, people investigation, data-breach search, and geospatial tooling. ~28k stars.

    Open ↗
  40. Awesome Cyber Skillsreference-index

    Curated list of 100+ free, legal environments for practicing offensive security: deliberately-vulnerable apps (DVWA, Juice Shop, WebGoat, Mutillidae), CTF platforms (HackTheBox, TryHackMe, picoCTF, Root-Me), wargames (OverTheWire, pwnable.kr), and specialized labs for crypto, RE, and binary exploitation.

    Open ↗
  41. payloads (AI Red Teaming)technique-and-payload-referencedual-use

    Collection of payloads for AI red teaming, organized around the OWASP AITG-APP (AI Testing Guide) categories. A reference set of adversarial prompt/test payloads for authorized LLM/AI application security testing rather than executable malware.

    Open ↗
  42. LOLC2reference-indexdual-usehigh-risk

    A curated catalogue of command-and-control (C2) frameworks that abuse legitimate services (cloud APIs, messaging platforms) to evade detection, tracking abused services, open-source C2 projects, and associated detection rules with network/file/behavioral IOCs.

    Open ↗
  43. PentestingEverythingpentest-knowledge-basedual-use

    A pentesting and VAPT/AppSec knowledge base spanning 23 security domains (web, mobile, API, cloud, network, LLM, MCP security), aggregating methodologies, 100+ reference PDFs, 200+ tools organized by category, and an AI-assisted pentest agent skill.

    Open ↗
  44. Bug Bounty Referencetechnique-writeupsdual-use

    A curated index of publicly disclosed bug bounty write-ups organized by vulnerability type (XSS, SQLi, CSRF, RCE, SSRF, auth bypass, etc.), linking out to the original researcher reports.

    Open ↗
  45. HackerOne Reportstechnique-writeupsdual-use

    A repository that aggregates and ranks disclosed HackerOne bug bounty reports, categorizing them by vulnerability type (XSS, SQLi, RCE, SSRF, etc.) and by affected program, linking out to the original disclosures.

    Open ↗
  46. LLM4Pentestreference-index

    A curated index of resources on applying LLMs to automated penetration testing: 105+ academic papers grouped into systems/agents, benchmarks/cyber-ranges, empirical evaluations, surveys, and defense/ethics, plus links to code repositories (PentestGPT, VulnBot, Shannon and others) and evaluation benchmarks. Tied to the paper 'Hackers or Hallucinators?'.

    Open ↗
  47. A curated, categorized index of Burp Suite extensions for web application penetration testing, organized by domain: active/passive scanners, decoders/beautifiers, cloud security (AWS/Azure/GCP), auth testing (OAuth/SAML/JWT/SSO), vulnerability-specific plugins (XSS/SQLi/CSRF/XXE/SSRF), WAF evasion, integrations (Nuclei/Elasticsearch), and payload/fuzzing generators.

    Open ↗
  48. OSCP-Notespentest-knowledge-basedual-use

    A study/reference repository for OSCP exam preparation with command references organized by tool (Nmap, Hydra, Hashcat, Wfuzz, Cewl), technique notes on reverse shells, privilege escalation, Active Directory, buffer overflow, SQLi and XSS, plus write-ups from HackTheBox, VulnHub, Proving Grounds and TryHackMe.

    Open ↗
  49. Awesome Bug Bounty Toolsreference-indexdual-use

    A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.

    Open ↗
  50. Awesome Hacking Resourcesreference-indexdual-usetraining only

    A curated collection of hacking, penetration-testing, and AI red-teaming learning resources: educational courses, YouTube channels, skill-building platforms (HackTheBox, TryHackMe, CTFs), reverse-engineering/privesc/OSINT/malware-analysis training, vulnerable practice apps, exploit databases, and pentest distros (Kali, ParrotOS, BlackArch).

    Open ↗
  51. AboutSecurity (WgpSec)pentest-knowledge-basedual-usehigh-risk

    A structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).

    Open ↗
  52. ZAP Community Scriptstechnique-and-payload-referenceactive

    A community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.

    Open ↗
  53. Security Certification Roadmapcertification-roadmap

    A reference chart by Paul Jerimy cataloging roughly 480 cybersecurity certifications, organized by specialty domain (network/communications security, cloud, penetration testing, forensics, incident handling, GRC) and by experience tier from foundational to expert, spanning issuers such as GIAC, CompTIA, EC-Council, and Cisco.

    Open ↗
  54. A research paper proposing a component model for the structured analysis of prompt-injection attacks — decomposing an injection into its functional parts (the framing that terminates trusted context, fake system tags, the payload) so defenders can reason about and detect them systematically.

    Open ↗
  55. Primary research from the UK AI Security Institute (DSIT): frontier-model cyber-capability evaluations, safeguard and jailbreak testing, and incident reports from their own agent testing.

    Open ↗
  56. AI Megalistreference-index

    MIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.

    Open ↗
  57. Awesome Generative AI Appsreference-indexcloud cost

    MIT-licensed catalogue of open-source generative-AI SaaS templates (image, video, virtual try-on, writing, chatbots, voice) on a shared Next.js/Stripe/Google-OAuth stack, built to be forked and resold; no security content.

    Open ↗
  58. In-The-Wild Jailbreak Prompts on LLMsprompt-datasetdual-usepassive

    Dataset of 15,140 in-the-wild prompts collected from Reddit, Discord, websites and open-source datasets, 1,405 of them jailbreaks, plus a 390-question forbidden-scenario set for measuring jailbreak effectiveness.

    Open ↗
  59. Jailbreaking Frontier Modelsprompt-datasetactivecloud costdual-usehigh-risklicence

    Dataset of harmful-behaviour prompts (drug, chemical, biological, radiological, nuclear, explosive) and a reference PRBO reward function for training jailbreaking agents; the RL training loop is not included.

    Open ↗
  60. LLM-Jailbreaksprompt-datasetdual-use

    README-only collection of copy-paste jailbreak prompts for DeepSeek R1, Grok 3, Gemini 2.0, ChatGPT (DAN), Claude 2 and Llama 2, plus a Gemini system-prompt leak prompt, mostly reposted from linked Reddit, blog and GitHub posts.

    Open ↗
  61. System Prompts Leaksprompt-datasetpassive

    Vendor-organised collection of files, mostly Markdown, presenting what it says are the verbatim system prompts of major chatbots and coding agents (Anthropic, OpenAI, Google, xAI, Cursor, Kimi and others), with a dated additions table and an open invitation to PRs.

    Open ↗