Reference · reference-indexdual-usetraining only
Awesome Hacking Resources
A curated collection of hacking, penetration-testing, and AI red-teaming learning resources: educational courses, YouTube channels, skill-building platforms (HackTheBox, TryHackMe, CTFs), reverse-engineering/privesc/OSINT/malware-analysis training, vulnerable practice apps, exploit databases, and pentest distros (Kali, ParrotOS, BlackArch).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More references
- AI Megalistreference-indexMIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.
- Awesome AI Securityreference-indexA curated list of AI/ML security resources organized into adversarial examples, evasion attacks, poisoning attacks, feature selection, and code (e.g. CleverHans, Foolbox). Aggregates papers, libraries, videos, and blog posts on attacking and defending ML systems.
- Awesome Bug Bounty Toolsreference-indexA curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.
- Awesome Burp Extensionsreference-indexA curated, categorized index of Burp Suite extensions for web application penetration testing, organized by domain: active/passive scanners, decoders/beautifiers, cloud security (AWS/Azure/GCP), auth testing (OAuth/SAML/JWT/SSO), vulnerability-specific plugins (XSS/SQLi/CSRF/XXE/SSRF), WAF evasion, integrations (Nuclei/Elasticsearch), and payload/fuzzing generators.
- Awesome Cyber Skillsreference-indexCurated list of 100+ free, legal environments for practicing offensive security: deliberately-vulnerable apps (DVWA, Juice Shop, WebGoat, Mutillidae), CTF platforms (HackTheBox, TryHackMe, picoCTF, Root-Me), wargames (OverTheWire, pwnable.kr), and specialized labs for crypto, RE, and binary exploitation.
- Awesome Generative AI Appsreference-indexMIT-licensed catalogue of open-source generative-AI SaaS templates (image, video, virtual try-on, writing, chatbots, voice) on a shared Next.js/Stripe/Google-OAuth stack, built to be forked and resold; no security content.