Reference · reference-indexdual-use
Awesome AI Security
A curated list of AI/ML security resources organized into adversarial examples, evasion attacks, poisoning attacks, feature selection, and code (e.g. CleverHans, Foolbox). Aggregates papers, libraries, videos, and blog posts on attacking and defending ML systems.
Use responsibly
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More references
- AI Megalistreference-indexMIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.
- Awesome Bug Bounty Toolsreference-indexA curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.
- Awesome Burp Extensionsreference-indexA curated, categorized index of Burp Suite extensions for web application penetration testing, organized by domain: active/passive scanners, decoders/beautifiers, cloud security (AWS/Azure/GCP), auth testing (OAuth/SAML/JWT/SSO), vulnerability-specific plugins (XSS/SQLi/CSRF/XXE/SSRF), WAF evasion, integrations (Nuclei/Elasticsearch), and payload/fuzzing generators.
- Awesome Cyber Skillsreference-indexCurated list of 100+ free, legal environments for practicing offensive security: deliberately-vulnerable apps (DVWA, Juice Shop, WebGoat, Mutillidae), CTF platforms (HackTheBox, TryHackMe, picoCTF, Root-Me), wargames (OverTheWire, pwnable.kr), and specialized labs for crypto, RE, and binary exploitation.
- Awesome Generative AI Appsreference-indexMIT-licensed catalogue of open-source generative-AI SaaS templates (image, video, virtual try-on, writing, chatbots, voice) on a shared Next.js/Stripe/Google-OAuth stack, built to be forked and resold; no security content.
- Awesome Hackingreference-indexA large, widely-used index of curated security awesome-lists for hackers, pentesters, and researchers, spanning 50+ domains including web hacking, bug bounty, malware analysis, OSINT, Android, IoT, forensics, and cryptography.