CTF Field Guide
Written by Trail of Bits.
🐶 A curated list of Web Security materials and resources.
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Written by Trail of Bits.
Written by hackerone.
Written by Mark Robinson.
Written by @swisskyrepo.
Written by PortSwigger.
Written by @bitvijays.
Written by Netsparker.
Weekly summary of top security tools, blog posts, and security research.
Connecting The Information Security Community.
Dig high-quality web security articles for hacker.
Ezine written by and for hackers.
The security podcast network.
Security in a serious way.
Biting the hand that feeds IT.
Written by @JakobKallin and Irene Lobo Valbuena.
Written by Google.
Written by @cure53.
Written by Paulos Yibelo.
Written by @s0md3v.
Written by @jackmasa.
Written by @swisskyrepo.
Hands-on guide to implementing Content Security Policy in Laravel — nonce lifecycle, Vite and Livewire integration, violation reporting, and a pre-enforcement checklist, by @itxshakil.
Written by @HoLyVieR.
Written by Andy.
Written by George Mauer.
Written by @swisskyrepo.
Written by @netsparker.
Written by @LightOS.
Written by NETSPI.
Written by @swisskyrepo.
Written by @drigg3r.
Written by @swisskyrepo.
Written by @h3xstream.
Written by Simone Onofri.
Written by Mikhail Egorov.
Written by Timothy Morgan.
Written by Alexander Klink.
Written by @phonexicum.
Written by @swisskyrepo.
Written by portswigger.
Written by @jrozner.
Written by @swisskyrepo.
Written by Imperva.
Written by Mario Heiderich.
Written by Wallarm.
Written by @swisskyrepo.
Written by @albinowax.
Written by @swisskyrepo.
Written by The Morning Paper.
Written by Mitsui Bussan Secure Directions, Inc..
Written by s0cket7.
Written by @swisskyrepo.
Written by epi.
Written by epi.
Written by epi.
Written by @swisskyrepo.
Written by Haboob Team.
Written by @swisskyrepo.
Written by @qazbnm456.
Written by Rails team.
Written by @presidentbeef.
Written by @brunofacca.
Written by @garethheyes.
Written by Gareth Heyes.
Written by Daniel LeCheminant.
Written by APTIVE.
Written by @Hakky54.
Live-data research across thousands of scanned hosts: protocol adoption, the TLS-versus-headers maturity gap, ECDSA drawing even with RSA, certificate lifetimes against the CA/B Forum 47-day schedule, and the end of OCSP stapling. Figures recompute from the scan corpus on each load.
Written by PENETRATION ACADEMY.
Written by Dwight Hohnstein from Rhino Security Labs.
Written by VirtueSecurity.
Written by VirtueSecurity.
Written by @spengietz.
Written by @rhinobenjamin.
Written by The bettercrypto.org Team.
Written by J.M Porup.
Written by @_nullbind.
Written by Jacob Baines.
Written by @s3yfullah.
Written by Philippe Lin.
Presented by @kirbstr.
Written by Timur Daudpota.
Written by @brannondorsey.
Written by @radekk.
Written by @noperator.
Written by @pwntester.
Written by CRISTIAN CORNEA.
Written by @synacktiv.
Root-cause analysis and reproducible PoC for a XAML deserialization RCE (CVSS 7.3) in a SCADA HMI engineering IDE, including affected versions and a self-contained exploit script, published by 0day Rubbish.
Written by @damianrusinek.
Written by @PhilippeDeRyck.
Written by @ermil0v.
Written by @SpiderSec.
Written by Detectify Labs.
Written by Paulos Yibelo.
Written by Wallarm.
Written by portswigger.
Written by @ptoomey3.
Written by @ptoomey3.
Written by @shhnjk.
Written by @Brett Buerhaus.
Written by @d0znpp.
Written by @secjuice.
Written by @secjuice.
Written by Mario Heiderich.
Written by @malerisch and @steventseeley.
Written by Twosecurity.
Written by @dxa4481.
Written by @GraphX.
Written by @raushanraj_65039.
Written by Ambionics Security.
Written by OpSecX.
Written by @iblue.
Written by @capacitorset.
Written by Ezequiel Pereira.
Written by CODE WHITE.
Written by @blaklis_.
Written by Badcode@Knownsec 404 Team.
Written by @yu5k3.
Written by Sebastian Lekies, Krzysztof Kotowicz, and Eduardo Vela.
Written by Mario Heiderich.
Written by @marin_m.
Written by kenziy.
Written by zhchbin.
Written by Enguerran Gillier.
Written by Michał Bentkowski.
Written by Michał Bentkowski.
Written by @terjanq.
Written by @garethheyes.
Written by Orange.
Written by TomNomNom.
Written by Tarlogic.
Written by @osandamalith.
Written by @denandz.
Written by Pete.
Written by @a66at and Alexey Osipov.
Written by Arseniy Sharoglazov.
Written by Philippe Arteau.
Written by Arseniy Sharoglazov.
Written by Antti Rantasaari.
Written by Renaud Dubourguais.
Written by @a66at and Alexey Osipov.
Written by Rose Jackcode.
Written by skavans.
Written by aesteral.
Written by @themiddleblue.
Written by @0xacb.
Written by opnsec.
Written by Alyssa Herrera.
Written by @Auxy233.
Written by Gwen.
Written by @albinowax.
Written by Wallarm.
Written by Timothy Morgan.
Written by Sergey Bobrov.
Written by Xudong Zheng.
Written by Chris Palmer.
Written by VRGSEC.
Written by @epidemics-scepticism.
Written by @signalchaos.
Written by @alex.birsan.
Written by phithon.
Written by James Lee.
Written by portswigger.
Written by Bo0oM.
Written by aaj at google.com and mkwst at google.com.
Written by Michał Bentkowski.
Written by jameshfisher.
Written by @rafaybaloch.
Written by @filedescriptor.
Written by @shhnjk.
Written by @kinugawamasato.
Written by SecuriTeam Secure Disclosure (SSD).
Written by @wanderingglitch.
Written by RET2 SYSTEMS, INC.
Written by Diary of a reverse-engineer.
Written by Доктор Веб.
Curated list of CVE PoCs by @qazbnm456.
Collection of JavaScript engine CVEs with PoCs by @tunz.
各种漏洞poc、Exp的收集或编写 by @coffeehb.
Collection of UXSS CVEs with PoCs by @Metnew.
ultimate archive of Exploits, Shellcode, and Security Papers by Offensive Security.
Written by @uppusaikiran.
Written by @brutelogic.
Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.
FOCA (Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans by ElevenPaths.
Cyberspace Search Engine by BAIMAOHUI.
Github Sensitive Information Leakage(Github敏感信息泄露)by @FeeiCN.
THREAT INTELLIGENCE PORTAL by NSFOCUS GLOBAL.
raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin by @0x09AL.
Shodan is the world's first search engine for Internet-connected devices by @shodanhq.
Open source footprinting and intelligence-gathering tool by @binarypool.
Service which analyses websites and the resources they request by @heipei.
XRay is a tool for recon, mapping and OSINT gathering from public networks by @evilsocket.
Various databases which you can use for your OSINT research by @technisette.
the easy way to find people on Facebook by postkassen.
The most complete open-source tool for Twitter intelligence analysis by @vaguileradiaz.
Reconnaissance Swiss Army Knife by @s0md3v.
Dockerfiles for various OSINT tools by @espi0n.
High performance offensive security tool for reconnaissance and vulnerability scanning by @evyatarmeged.
Social Media Enumeration & Correlation Tool by Jacob Wilkin (Greenwolf).
OSINT and security extensions for the Marshall privacy browser, providing reconnaissance and security-testing plugins by @bad-antics.
Search engine for misconfigured public cloud storage buckets across any provider.
Enter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by @crtsh.
Google's Certificate Transparency project fixes several structural flaws in the SSL certificate system by @google.
Analyze the security of any domain by finding all the information possible by @eldraco.
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible by @ChrisTruncer.
Domain searcher named GoogleSSLdomainFinder by @We5ter.
A simple and fast sub domain brute tool for pentesters by @lijiejie.
Searching for domain information by VirusTotal.
Vulnerable Web applications Generator by @qazbnm456.
Script that inspects multi-byte character sets looking for characters with specific user-defined properties by @hack-all-the-things.
Simple tool to convert the IP to a DWORD IP by @OsandaMalith.
DOM fuzzer by @google.
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
Web crawler optimized for searching and analyzing the directory structure of a site by @nekmo.
Online service that performs a deep analysis of the configuration of any SSL web server on the public internet. Provided by Qualys SSL Labs.
Potentially dangerous files by @Bo0oM.
Cross-platform Python CLI that fetches historical URLs from the Wayback CDX API and outputs normalized parameterized URLs for fuzzing, by @aleff-github.
Cross-platform web security crawler supporting standard, headless, interactive, brute-force, and archive crawling modes, for attack-surface mapping and endpoint discovery, by @3nock.
Free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan by @drego85.
WPScan is a black box WordPress vulnerability scanner by @wpscanteam.
Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use by @projectdiscovery.
High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision, maintained by @j3ssie.
Open-source web application security scanner maintained by the ZAP Core Team.
URL security scanner combining threat intelligence (URLhaus, PhishTank, Spamhaus) with 40+ scam and phishing pattern detection by @undeadlist.
Privacy-first Chrome extension that analyzes website security locally with on-device AI (WebGPU), producing trust scores from HTTPS, phishing, malicious-script, and cookie-compliance signals, by @sattyamjjain.
Free online collection of 29 client-side web security tools: web auditor, JWT attacker/decoder, CVE search, CSP evaluator, email security checker (SPF/DKIM/DMARC), subdomain scanner, and more. 100% client-side, privacy-first, open source by @ReplikanteK.
Burp Suite is an integrated platform for performing security testing of web applications by portswigger.
Automated Security Testing For REST API's by @flipkart-incubator.
A collection of AWS penetration testing junk by @dagrz.
Public buckets by grayhatwarfare.
A comprehensive web application audit framework to cover up everything from Reconnaissance and OSINT to Vulnerability Analysis by @_tID.
AI-driven penetration-testing platform that coordinates 10 agents and 38 vulnerability scanners covering OWASP Top 10, by @FrancescoStabile.
Offline-first, self-hosted pentest & bug-bounty arsenal - searchable payloads, a click-to-build command generator, GTFOBins, wordlists, an embedded CyberChef, reverse shells and per-vulnerability checklists, with a live static demo - by @inflictx.
XSS'OR - Hack with JavaScript by @evilcos.
XSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs by @s0md3v.
Get a JavaScript shell with XSS by @s0md3v.
A tool for evaluating content-security-policies by Csper.
Code and Server-Side Template Injection Detection and Exploitation Tool by @epinna.
List DTDs and generate XXE payloads using those local DTDs by @GoSecure.
The Prime CSRF Audit & Exploitation Toolkit by @0xInfection.
Chrome extension and Express server that exploits keylogging abilities of CSS by @maxchehab.
Pillage web accessible GIT, HG and BZR repositories by @evilpacket.
Rip web accessible (distributed) version control systems: SVN/GIT/HG... by @kost.
Tool for advanced mining for content on Github by @UnkL4b.
All possible ways, a website can leak HTTP requests by @cure53.
Git manager for pentesters by @allyshka.
Tool to scan for secret files on HTTP servers by @hannob.
Python script that finds endpoints in JavaScript files by @GerbenJavado.
bXSS is a simple Blind XSS application adapted from cure53.de/m by @LewisArdern.
Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction by @HynekPetrak.
Scan your code for security misconfiguration, search for passwords and secrets.
Scanner detecting the use of JavaScript libraries with known vulnerabilities by @RetireJS.
SQL injection detection engine by chaitin.
XSS detection engine by chaitin.
An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.
A GitHub App that provides security feedback in Pull Requests.
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist by @leizongmin.
Client-side encryption engine for SQL databases, with strong selective encryption, SQL injections prevention and intrusion detection by @cossacklabs.
DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG by Cure53.
A set of tools for building/evaluating/monitoring content-security-policy to prevent/detect cross site scripting by Csper.
An open-source web application firewall and API security gateway maintained by UUCORP.
A next-generation open-source Web Application Firewall built on nginx, maintained by Bunkerity.
Self-hosted CAPTCHA with behavioral analysis, vision-AI agent detection, headless-browser fingerprinting, and SHA-256 proof-of-work, maintained by WebDecoy.
In-process file-upload security middleware for Node.js that scans untrusted uploads before storage to detect malware, MIME spoofing, and risky archives, maintained by pompelmi.
Zero-configuration WordPress bot-detection plugin combining WebDriver detection, headless-browser fingerprinting, behavioral analysis, and SHA-256 proof-of-work, maintained by WebDecoy.
Open-source collaborative IPS written in Go that analyzes visitor behavior and shares threat signals across a community of operators, maintained by CrowdSec.
Interactive Content Security Policy builder for Laravel that outputs ready-to-use PHP middleware with nonce support and violation reporting, by @itxshakil.
Browser-side integrity verification and resumable downloads for large files using SRI hashes, defending against CDN compromise and supply-chain attacks, by @hamzaydia.
HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet.
Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers by @mitmproxy.
Single-binary intercepting proxy for HTTP, HTTPS, and WebSocket traffic that pauses and edits requests in flight, replays them, rewrites traffic with Lua hooks, and exports captures as HAR, curl, or raw HTTP, available as a terminal UI, web GUI, or headless REST API, by @emanuele-em.
Reverse Shell as a Service by @lukechilds.
Reverse Shell Manager via Terminal @WangYihang.
This is a webshell open source project by @tennc.
Manage your website via terminal by @WangYihang.
Weaponized web shell by @epinna.
Family of code golfed PHP shells by @s0md3v.
Another java decompiler by @LeeAtBenf.
DNS Rebind Toolkit is a frontend JavaScript framework for developing DNS Rebinding exploits against vulnerable hosts and services on a local area network (LAN) by @brannondorsey.
DNS Rebinding Exploitation Framework. Dref does the heavy-lifting for DNS rebinding by @mwrlabs.
It includes the necessary components to rebind the IP address of the attack server DNS name to the target machine's IP address and to serve attack payloads to exploit vulnerable software on the target machine by @nccgroup.
A malicious DNS server for executing DNS Rebinding attacks on the fly by @brannondorsey.
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis - by @GCHQ.
Minimal code to connect to a CEF debugger by @taviso.
Parse NTLM over HTTP challenge messages by @b17zr.
Check if you have an account that has been compromised in a data breach by Troy Hunt.
Check if your email or domain was compromised by infostealer malware, maintained by Hudson Rock.
Vulnerability disclosures and rambles on application security.
Fun with Browser Vulnerabilities.
Head of Research at PortSwigger Web Security.
China's talented web penetrator.
~# n0tr00t Security Team.
Open Mind Security!.
Taiwan's talented web penetrator.
Internet Security through Web Browsers by Dhiraj Mishra.
Awesome bug-bounty and challenges writeups.
Security Researching and Reverse Engineering.
Cure53 is a German cybersecurity firm.
Active penetrator often tweets and writes useful articles.
English web penetrator.
Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.
Initiative to showcase open source hacking tools for hackers and pentesters.
Japanese javascript security researcher.
Japanese web penetrator.
The wonderland of JavaScript unexpected usages, and more.
Web and Browsers Security Researcher.
Learn SELinux by doing. Solve Puzzles, show skillz - Written by @selinuxgame.
Vulnerable web application for training - Written by @SecureSkyTechnology.
Realistic web application hacking game - Written by @albinowax.
Probably the most modern and sophisticated insecure web application - Written by @bkimminich and the @owasp_juiceshop team.
Free trainings and labs - Written by PortSwigger.
Intentionally vulnerable e-commerce application built with Next.js - Written by @kOaDT.
Shows how a correct-looking Next.js headers() block can overwrite route-specific rules or differ from final CDN responses, with an inventory, merge, preview, deployed-route verification, and rollback workflow.
Technical write-up on designing an AI-assisted VAPT pipeline with deterministic CVSS scoring, passive confidence verification, and LLM-generated vulnerability explanations and remediation.
Why a 200 OK is not proof of an access-control bug: a seeded BOLA benchmark where a model asked to confirm a secure endpoint 79 times and a downgrade-only code gate refused every one, plus the similarity thresholds, a deterministic check that failed the same way, and a plausible fix measured and…
Series of XSS challenges - Written by @steike.
Series of XSS challenges - Written by yamagata21.
Google XSS Challenge - Written by Google.
Series of tutorials to install, configure and tune ModSecurity and the Core Rule Set - Written by @ChrFolini.
Written by @gregose.
Comprehensive curated list of available Bug Bounty & Disclosure Programs and write-ups by @djadmin.
Written by PwnDizzle.
List of bug bounty write-up that is categorized by the bug nature by @ngalongc.
Written by Belfer Center for Science and International Affairs.
Decrypted content of eqgrp-auction-file.tar.xz by @x0rz.
Written by Daniel Stelter-Gliese.
Information Security Reference That Doesn't Suck by @rmusser01.
Some public notes by @ChALkeR.
Penetration Testing and Exploit Dev CheatSheet.
Written by JASON TROS.
Written by Ezequiel Pereira.
Written by @jhaddix.
Written by Chris Patten, Tom Steele.
Written by @itsC0rg1, @jmkeads and @matir.
Written by Paul Dannewitz.
Written by @0daywork.
Written by Jayson.
Written by Mariem.
Written by Gwen.
Written by @AntoGarand.
Written by @t0nk42.
Written by @sandrogauci.
Written by @clr2of8.
Written by @cj.fairhead.
Hands-on introduction to web application security fundamentals by Malcolm McDonald (Manning).
Comprehensive Hack The Box writeup collection covering 75+ web challenges including XSS, SQLi, SSTI, SSRF, and deserialization, by @momenbasel.
How DNSSEC, DANE, SPF/DKIM/DMARC and SMTP transport evidence becomes a finding, with the decision logic for each, the dig invocations to reproduce it independently, and the false positives to expect.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
kdeldycke/awesome-iam
👤 Identity and Access Management knowledge for cloud platforms