Reference · technique-and-payload-referencedual-use
PayloadsAllTheThings
Community collection of payloads and bypass techniques organized by vulnerability class; a companion data source referenced alongside SecLists.
Use responsibly
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More references
- Google Dorks for Bug Bountytechnique-and-payload-referenceA categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.
- payloads (AI Red Teaming)technique-and-payload-referenceCollection of payloads for AI red teaming, organized around the OWASP AITG-APP (AI Testing Guide) categories. A reference set of adversarial prompt/test payloads for authorized LLM/AI application security testing rather than executable malware.
- ZAP Community Scriptstechnique-and-payload-referenceA community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.
- [un]prompted 2026 slide archiveai-security-programCommunity GitHub archive of 49 slide decks from [un]prompted 2026, the AI Security Practitioner Conference (March 3-4, San Francisco), spanning AI governance, agent security, offensive AI and agent evaluation; no licence stated.
- AboutSecurity (WgpSec)pentest-knowledge-baseA structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).
- AI Megalistreference-indexMIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.