Skip to content
87

Awesome Web Security

🐶 A curated list of Web Security materials and resources.

14k stars1,825 forks368 entriesLast push Sep 14, 2026 (15 days ago)License none

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Digests

CTF Field Guide

Written by Trail of Bits.

In 5 listsDetails

Hacker101

Written by hackerone.

In 3 lists

Infosec Newbie

Written by Mark Robinson.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

The Daily Swig - Web security digest

Written by PortSwigger.

The Magic of Learning

Written by @bitvijays.

Web Application Security Zone by Netsparker

Written by Netsparker.

tl;dr sec

Weekly summary of top security tools, blog posts, and security research.

In 3 lists

Forums

Dark Reading

Connecting The Information Security Community.

HackDig

Dig high-quality web security articles for hacker.

Phrack Magazine

Ezine written by and for hackers.

Security Weekly

The security podcast network.

In 2 lists

The Hacker News

Security in a serious way.

The Register

Biting the hand that feeds IT.

In 2 lists

Introduction >XSS - Cross-Site Scripting

C.XSS Guide

Written by @JakobKallin and Irene Lobo Valbuena.

Cross-Site Scripting – Application Security – Google

Written by Google.

H5SC

Written by @cure53.

In 2 lists

THE BIG BAD WOLF - XSS AND MAINTAINING ACCESS

Written by Paulos Yibelo.

AwesomeXSS

Written by @s0md3v.

XSS.png

Written by @jackmasa.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Laravel Content Security Policy: Complete Implementation Guide

Hands-on guide to implementing Content Security Policy in Laravel — nonce lifecycle, Vite and Livewire integration, violation reporting, and a pre-enforcement checklist, by @itxshakil.

Introduction >Prototype Pollution

Prototype pollution attack in NodeJS application

Written by @HoLyVieR.

Introduction >CSV Injection

CSV Injection -> Meterpreter on Pornhub

Written by Andy.

The Absurdly Underestimated Dangers of CSV Injection

Written by George Mauer.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >SQL Injection

SQL Injection Cheat Sheet

Written by @netsparker.

In 3 lists

SQL Injection Pocket Reference

Written by @LightOS.

SQL Injection Wiki

Written by NETSPI.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Command Injection

Potential command injection in resolv.rb

Written by @drigg3r.

In 2 lists

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >ORM Injection

HQL : Hyperinsane Query Language (or how to access the whole SQL API within a HQL injection ?)

Written by @_m0bius.

HQL for pentesters

Written by @h3xstream.

ORM Injection

Written by Simone Onofri.

ORM2Pwn: Exploiting injections in Hibernate ORM

Written by Mikhail Egorov.

Introduction >FTP Injection

Advisory: Java/Python FTP Injections Allow for Firewall Bypass

Written by Timothy Morgan.

SMTP over XXE − how to send emails using Java's XML parser

Written by Alexander Klink.

Introduction >XXE - XML eXternal Entity

XXE

Written by @phonexicum.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

XML external entity (XXE) injection

Written by portswigger.

Introduction >CSRF - Cross-Site Request Forgery

Wiping Out CSRF

Written by @jrozner.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Clickjacking

Clickjacking

Written by Imperva.

X-Frame-Options: All about Clickjacking?

Written by Mario Heiderich.

Introduction >SSRF - Server-Side Request Forgery

SSRF bible. Cheatsheet

Written by Wallarm.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Web Cache Poisoning

Practical Web Cache Poisoning

Written by @albinowax.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Relative Path Overwrite

Large-scale analysis of style injection by relative path overwrite

Written by The Morning Paper.

MBSD Technical Whitepaper - A few RPO exploitation techniques

Written by Mitsui Bussan Secure Directions, Inc..

Introduction >Open Redirect

Open Redirect Vulnerability

Written by s0cket7.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Security Assertion Markup Language (SAML)

How to Hunt Bugs in SAML; a Methodology - Part I

Written by epi.

How to Hunt Bugs in SAML; a Methodology - Part II

Written by epi.

How to Hunt Bugs in SAML; a Methodology - Part III

Written by epi.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Upload

File Upload Restrictions Bypass

Written by Haboob Team.

PayloadsAllTheThings

Written by @swisskyrepo.

In 12 listsDetails

Introduction >Rails

Rails Security - First part

Written by @qazbnm456.

Official Rails Security Guide

Written by Rails team.

In 2 lists

Rails SQL Injection

Written by @presidentbeef.

Zen Rails Security Checklist

Written by @brunofacca.

Introduction >AngularJS

DOM based Angular sandbox escapes

Written by @garethheyes.

XSS without HTML: Client-Side Template Injection with AngularJS

Written by Gareth Heyes.

Introduction >ReactJS

XSS via a spoofed React element

Written by Daniel LeCheminant.

Introduction >SSL/TLS

SSL & TLS Penetration Testing

Written by APTIVE.

Practical introduction to SSL/TLS

Written by @Hakky54.

In 2 lists

State of TLS on the public web

Live-data research across thousands of scanned hosts: protocol adoption, the TLS-versus-headers maturity gap, ECDSA drawing even with RSA, certificate lifetimes against the CA/B Forum 47-day schedule, and the end of OCSP stapling. Figures recompute from the scan corpus on each load.

Introduction >NFS

NFS | PENETRATION TESTING ACADEMY

Written by PENETRATION ACADEMY.

Introduction >AWS

PENETRATION TESTING AWS STORAGE: KICKING THE S3 BUCKET

Written by Dwight Hohnstein from Rhino Security Labs.

In 2 lists

AWS PENETRATION TESTING PART 1. S3 BUCKETS

Written by VirtueSecurity.

AWS PENETRATION TESTING PART 2. S3, IAM, EC2

Written by VirtueSecurity.

Introduction >Azure

Cloud Security Risks (Part 1): Azure CSV Injection Vulnerability

Written by @spengietz.

Common Azure Security Vulnerabilities and Misconfigurations

Written by @rhinobenjamin.

Introduction >Crypto

Applied Crypto Hardening

Written by The bettercrypto.org Team.

In 3 lists

What is a Side-Channel Attack ?

Written by J.M Porup.

Introduction >Web Shell

Hacking with JSP Shells

Written by @_nullbind.

Hunting for Web Shells

Written by Jacob Baines.

Introduction >OSINT

Hacking Cryptocurrency Miners with OSINT Techniques

Written by @s3yfullah.

OSINT x UCCU Workshop on Open Source Intelligence

Written by Philippe Lin.

102 Deep Dive in the Dark Web OSINT Style Kirby Plessas

Presented by @kirbstr.

The most complete guide to finding anyone’s email

Written by Timur Daudpota.

Introduction >DNS Rebinding

Attacking Private Networks from the Internet with DNS Rebinding

Written by @brannondorsey.

Hacking home routers from the Internet

Written by @radekk.

Introduction >Deserialization

What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.

Written by @breenmachine.

.NET Roulette: Exploiting Insecure Deserialization in Telerik UI

Written by @noperator.

Attacking .NET deserialization

Written by @pwntester.

How to exploit the DotNetNuke Cookie Deserialization

Written by CRISTIAN CORNEA.

HOW TO EXPLOIT LIFERAY CVE-2020-7961 : QUICK JOURNEY TO POC

Written by @synacktiv.

Altus iX Developer XAML Deserialization RCE

Root-cause analysis and reproducible PoC for a XAML deserialization RCE (CVSS 7.3) in a SCADA HMI engineering IDE, including affected versions and a self-contained exploit script, published by 0day Rubbish.

Introduction >OAuth

What is going on with OAuth 2.0? And why you should not use it for authentication.

Written by @damianrusinek.

Introduction to OAuth 2.0 and OpenID Connect

Written by @PhilippeDeRyck.

Introduction >JWT

Hardcoded secrets, unverified tokens, and other common JWT mistakes

Written by @ermil0v.

Evasions >XXE

Bypass Fix of OOB XXE Using Different encoding

Written by @SpiderSec.

Evasions >CSP

CSP: bypassing form-action with reflected XSS

Written by Detectify Labs.

TWITTER XSS + CSP BYPASS

Written by Paulos Yibelo.

Neatly bypassing CSP

Written by Wallarm.

Evading CSP with DOM-based dangling markup

Written by portswigger.

GitHub's CSP journey

Written by @ptoomey3.

GitHub's post-CSP journey

Written by @ptoomey3.

Any protection against dynamic module import?

Written by @shhnjk.

Evasions >WAF

Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities

Written by @Brett Buerhaus.

How to bypass libinjection in many WAF/NGWAF

Written by @d0znpp.

Web Application Firewall (WAF) Evasion Techniques

Written by @secjuice.

In 2 lists

Web Application Firewall (WAF) Evasion Techniques #2

Written by @secjuice.

In 2 lists

Evasions >JSMVC

JavaScript MVC and Templating Frameworks

Written by Mario Heiderich.

Evasions >Authentication

Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584)

Written by @malerisch and @steventseeley.

Tricks >CSRF

Neat tricks to bypass CSRF-protection

Written by Twosecurity.

Stealing CSRF tokens with CSS injection (without iFrames)

Written by @dxa4481.

If HttpOnly You Could Still CSRF… Of CORS you can!

Written by @GraphX.

Tricks >Clickjacking

Clickjackings in Google worth 14981.7$

Written by @raushanraj_65039.

Tricks >Remote Code Execution

DRUPAL 7.X SERVICES MODULE UNSERIALIZE() TO RCE

Written by Ambionics Security.

Exploiting Node.js deserialization bug for Remote Code Execution

Written by OpSecX.

GitHub Enterprise Remote Code Execution

Written by @iblue.

How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!

Written by Orange.

How we exploited a remote code execution vulnerability in math.js

Written by @capacitorset.

$36k Google App Engine RCE

Written by Ezequiel Pereira.

Poor RichFaces

Written by CODE WHITE.

Remote Code Execution on a Facebook server

Written by @blaklis_.

WebLogic RCE (CVE-2019-2725) Debug Diary

Written by Badcode@Knownsec 404 Team.

What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.

Written by @breenmachine.

CVE-2019-1306: ARE YOU MY INDEX?

Written by @yu5k3.

Tricks >XSS

DON'T TRUST THE DOM: BYPASSING XSS MITIGATIONS VIA SCRIPT GADGETS

Written by Sebastian Lekies, Krzysztof Kotowicz, and Eduardo Vela.

ECMAScript 6 from an Attacker's Perspective - Breaking Frameworks, Sandboxes, and everything else

Written by Mario Heiderich.

How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)

Written by @marin_m.

Query parameter reordering causes redirect page to render unsafe URL

Written by kenziy.

Uber XSS via Cookie

Written by zhchbin.

Stored XSS on Facebook

Written by Enguerran Gillier.

Another XSS in Google Colaboratory

Written by Michał Bentkowski.

XSS in Google Colaboratory + CSP bypass

Written by Michał Bentkowski.

XSS-Auditor — the protector of unprotected and the deceiver of protected.

Written by @terjanq.

XSS without parentheses and semi-colons

Written by @garethheyes.

Tricks >SQL Injection

GitHub Enterprise SQL Injection

Written by Orange.

Making a Blind SQL Injection a little less blind

Written by TomNomNom.

Red Team Tales 0x01: From MSSQL to RCE

Written by Tarlogic.

MySQL Error Based SQL Injection Using EXP

Written by @osandamalith.

SQL INJECTION AND POSTGRES - AN ADVENTURE TO EVENTUAL RCE

Written by @denandz.

Tricks >NoSQL Injection

GraphQL NoSQL Injection Through JSON Types

Written by Pete.

Tricks >FTP Injection

XML Out-Of-Band Data Retrieval

Written by @a66at and Alexey Osipov.

Tricks >XXE

Evil XML with two encodings

Written by Arseniy Sharoglazov.

Automating local DTD discovery for XXE exploitation

Written by Philippe Arteau.

Exploiting XXE with local DTD files

Written by Arseniy Sharoglazov.

Forcing XXE Reflection through Server Error Messages

Written by Antti Rantasaari.

Pre-authentication XXE vulnerability in the Services Drupal module

Written by Renaud Dubourguais.

XML Out-Of-Band Data Retrieval

Written by @a66at and Alexey Osipov.

XXE in WeChat Pay Sdk ( WeChat leave a backdoor on merchant websites)

Written by Rose Jackcode.

XXE OOB extracting via HTTP+FTP using single opened port

Written by skavans.

Tricks >SSRF

A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!

Written by Orange.

SSRF in https://imgur.com/vidgif/url

Written by aesteral.

PHP SSRF Techniques

Written by @themiddleblue.

SSRF in Exchange leads to ROOT access in all instances

Written by @0xacb.

Into the Borg – SSRF inside Google production network

Written by opnsec.

Piercing the Veil: Server Side Request Forgery to NIPRNet access

Written by Alyssa Herrera.

All you need to know about SSRF and how may we write tools to do auto-detect

Written by @Auxy233.

AWS takeover through SSRF in JavaScript

Written by Gwen.

Tricks >Web Cache Poisoning

Bypassing Web Cache Poisoning Countermeasures

Written by @albinowax.

Cache poisoning and other dirty tricks

Written by Wallarm.

Tricks >Header Injection

Advisory: Java/Python FTP Injections Allow for Firewall Bypass

Written by Timothy Morgan.

Tricks >URL

[dev.twitter.com] XSS

Written by Sergey Bobrov.

Phishing with Unicode Domains

Written by Xudong Zheng.

Some Problems Of URLs

Written by Chris Palmer.

Unicode Domains are bad and you should feel bad for supporting them

Written by VRGSEC.

Tricks >Others

Inducing DNS Leaks in Onion Web Services

Written by @epidemics-scepticism.

Stored XSS, and SSRF in Google using the Dataset Publishing Language

Written by @signalchaos.

How I hacked Google’s bug tracking system itself for $15,600 in bounties

Written by @alex.birsan.

Some Tricks From My Secret Group

Written by phithon.

Browser Exploitation >Frontend (like SOP bypass, URL spoofing, and something like that)

IE11 Information disclosure - local file detection

Written by James Lee.

JSON hijacking for the modern web

Written by portswigger.

Особенности Safari в client-side атаках

Written by Bo0oM.

How do we Stop Spilling the Beans Across Origins?

Written by aaj at google.com and mkwst at google.com.

Setting arbitrary request headers in Chromium via CRLF injection

Written by Michał Bentkowski.

The inception bar: a new phishing method

Written by jameshfisher.

Bypassing Mobile Browser Security For Fun And Profit

Written by @rafaybaloch.

The Cookie Monster in Your Browsers

Written by @filedescriptor.

The world of Site Isolation and compromised renderer

Written by @shhnjk.

Sending arbitrary IPC messages via overriding Function.prototype.apply

Written by @kinugawamasato.

Browser Exploitation >Backend (core of Browser implementation, and often refers to C or C++ part)

SSD Advisory – Chrome Turbofan Remote Code Execution

Written by SecuriTeam Secure Disclosure (SSD).

PUSHING WEBKIT'S BUTTONS WITH A MOBILE PWN2OWN EXPLOIT

Written by @wanderingglitch.

A Methodical Approach to Browser Exploitation

Written by RET2 SYSTEMS, INC.

In 2 lists

CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime.

Written by Diary of a reverse-engineer.

Breaking UC Browser

Written by Доктор Веб.

PoCs >Database

awesome-cve-poc

Curated list of CVE PoCs by @qazbnm456.

js-vuln-db

Collection of JavaScript engine CVEs with PoCs by @tunz.

In 2 lists

Some-PoC-oR-ExP

各种漏洞poc、Exp的收集或编写 by @coffeehb.

uxss-db

Collection of UXSS CVEs with PoCs by @Metnew.

In 2 lists

SPLOITUS

Exploits & Tools Search Engine by @i_bo0om.

In 4 listsDetails

Exploit Database

ultimate archive of Exploits, Shellcode, and Security Papers by Offensive Security.

In 8 listsDetails

Cheetsheets

Capture the Flag CheatSheet

Written by @uppusaikiran.

In 2 lists

XSS Cheat Sheet - 2018 Edition

Written by @brutelogic.

Tools >Auditing

A2SV

Auto Scanning to SSL Vulnerability by @hahwul.

prowler

Tool for AWS security assessment, auditing and hardening by @Alfresco.

slurp

Evaluate the security of S3 buckets by @hehnope.

Tools >Command Injection

commix

Automated All-in-One OS command injection and exploitation tool by @commixproject.

In 7 listsDetails

Tools >Reconnaissance

Censys

Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.

In 7 listsDetails

FOCA

FOCA (Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans by ElevenPaths.

In 4 listsDetails

FOFA

Cyberspace Search Engine by BAIMAOHUI.

gitrob

Reconnaissance tool for GitHub organizations by @michenriksen.

In 6 listsDetails

GSIL

Github Sensitive Information Leakage(Github敏感信息泄露)by @FeeiCN.

In 2 lists

NSFOCUS

THREAT INTELLIGENCE PORTAL by NSFOCUS GLOBAL.

raven

raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin by @0x09AL.

Shodan

Shodan is the world's first search engine for Internet-connected devices by @shodanhq.

In 12 listsDetails

SpiderFoot

Open source footprinting and intelligence-gathering tool by @binarypool.

In 7 listsDetails

urlscan.io

Service which analyses websites and the resources they request by @heipei.

In 7 listsDetails

xray

XRay is a tool for recon, mapping and OSINT gathering from public networks by @evilsocket.

In 4 listsDetails

ZoomEye

Cyberspace Search Engine by @zoomeye_team.

In 7 listsDetails

Databases - start.me

Various databases which you can use for your OSINT research by @technisette.

peoplefindThor

the easy way to find people on Facebook by postkassen.

tinfoleak

The most complete open-source tool for Twitter intelligence analysis by @vaguileradiaz.

Photon

Incredibly fast crawler designed for OSINT by @s0md3v.

In 5 listsDetails

ReconDog

Reconnaissance Swiss Army Knife by @s0md3v.

In 2 lists

espi0n/Dockerfiles

Dockerfiles for various OSINT tools by @espi0n.

Raccoon

High performance offensive security tool for reconnaissance and vulnerability scanning by @evyatarmeged.

In 4 listsDetails

Social Mapper

Social Media Enumeration & Correlation Tool by Jacob Wilkin (Greenwolf).

Marshall Extensions

OSINT and security extensions for the Marshall privacy browser, providing reconnaissance and security-testing plugins by @bad-antics.

OpenBuckets

Search engine for misconfigured public cloud storage buckets across any provider.

AQUATONE

Tool for Domain Flyovers by @michenriksen.

In 5 listsDetails

Certificate Search

Enter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by @crtsh.

In 6 listsDetails

Certificate Transparency

Google's Certificate Transparency project fixes several structural flaws in the SSL certificate system by @google.

In 2 lists

domain_analyzer

Analyze the security of any domain by finding all the information possible by @eldraco.

EyeWitness

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible by @ChrisTruncer.

In 2 lists

GSDF

Domain searcher named GoogleSSLdomainFinder by @We5ter.

subDomainsBrute

A simple and fast sub domain brute tool for pentesters by @lijiejie.

In 2 lists

VirusTotal domain information

Searching for domain information by VirusTotal.

Sublist3r

Sublist3r is a multi-threaded sub-domain enumeration tool for penetration testers by @aboul3la.

In 7 listsDetails

Tools >Code Generating

VWGen

Vulnerable Web applications Generator by @qazbnm456.

Tools >Fuzzing

charsetinspect

Script that inspects multi-byte character sets looking for characters with specific user-defined properties by @hack-all-the-things.

IPObfuscator

Simple tool to convert the IP to a DWORD IP by @OsandaMalith.

wfuzz

Web application bruteforcer by @xmendez.

In 5 listsDetails

domato

DOM fuzzer by @google.

In 2 lists

FuzzDB

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

In 6 listsDetails

dirhunt

Web crawler optimized for searching and analyzing the directory structure of a site by @nekmo.

In 2 lists

ssltest

Online service that performs a deep analysis of the configuration of any SSL web server on the public internet. Provided by Qualys SSL Labs.

In 3 lists

fuzz.txt

Potentially dangerous files by @Bo0oM.

In 3 lists

wayparam

Cross-platform Python CLI that fetches historical URLs from the Wayback CDX API and outputs normalized parameterized URLs for fuzzing, by @aleff-github.

In 2 lists

SpiderSuite

Cross-platform web security crawler supporting standard, headless, interactive, brute-force, and archive crawling modes, for attack-surface mapping and endpoint discovery, by @3nock.

Tools >Scanning

JoomlaScan

Free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan by @drego85.

wpscan

WPScan is a black box WordPress vulnerability scanner by @wpscanteam.

In 3 lists

Nuclei

Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use by @projectdiscovery.

In 8 listsDetails

Vigolium

High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision, maintained by @j3ssie.

In 2 lists

ZAP by Checkmarx

Open-source web application security scanner maintained by the ZAP Core Team.

In 4 listsDetails

Trust Scan

URL security scanner combining threat intelligence (URLhaus, PhishTank, Spamhaus) with 40+ scam and phishing pattern detection by @undeadlist.

In 2 lists

ZeroTrust

Privacy-first Chrome extension that analyzes website security locally with on-device AI (WebGPU), producing trust scores from HTTPS, phishing, malicious-script, and cookie-compliance signals, by @sattyamjjain.

SecuriTool

Free online collection of 29 client-side web security tools: web auditor, JWT attacker/decoder, CVE search, CSP evaluator, email security checker (SPF/DKIM/DMARC), subdomain scanner, and more. 100% client-side, privacy-first, open source by @ReplikanteK.

Tools >Penetration Testing

Burp Suite

Burp Suite is an integrated platform for performing security testing of web applications by portswigger.

In 7 listsDetails

Astra

Automated Security Testing For REST API's by @flipkart-incubator.

In 2 lists

aws_pwn

A collection of AWS penetration testing junk by @dagrz.

In 2 lists

grayhatwarfare

Public buckets by grayhatwarfare.

In 5 listsDetails

TIDoS-Framework

A comprehensive web application audit framework to cover up everything from Reconnaissance and OSINT to Vulnerability Analysis by @_tID.

numasec

AI-driven penetration-testing platform that coordinates 10 agents and 38 vulnerability scanners covering OWASP Top 10, by @FrancescoStabile.

ARS3NAL

Offline-first, self-hosted pentest & bug-bounty arsenal - searchable payloads, a click-to-build command generator, GTFOBins, wordlists, an embedded CyberChef, reverse shells and per-vulnerability checklists, with a live static demo - by @inflictx.

In 2 lists

Darkmoon

Open source autonomous AI penetration testing platform that orchestrates 80+ offensive tools via Markdown playbooks and MCP across web, cloud, Active Directory and Kubernetes, with an evidence trail per finding by @ASCIT31.

In 10 listsDetails

Tools >Offensive

xssor2

XSS'OR - Hack with JavaScript by @evilcos.

In 2 lists

XSStrike

XSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs by @s0md3v.

In 5 listsDetails

beef

The Browser Exploitation Framework Project by beefproject.

In 4 listsDetails

JShell

Get a JavaScript shell with XSS by @s0md3v.

csp evaluator

A tool for evaluating content-security-policies by Csper.

sqlmap

Automatic SQL injection and database takeover tool.

In 10 listsDetails

tplmap

Code and Server-Side Template Injection Detection and Exploitation Tool by @epinna.

In 3 lists

dtd-finder

List DTDs and generate XXE payloads using those local DTDs by @GoSecure.

In 2 lists

XSRFProbe

The Prime CSRF Audit & Exploitation Toolkit by @0xInfection.

In 2 lists

Tools >Leaking

CSS-Keylogging

Chrome extension and Express server that exploits keylogging abilities of CSS by @maxchehab.

DVCS-Pillage

Pillage web accessible GIT, HG and BZR repositories by @evilpacket.

dvcs-ripper

Rip web accessible (distributed) version control systems: SVN/GIT/HG... by @kost.

In 4 listsDetails

gitleaks

Searches full repo history for secrets and keys by @zricethezav.

In 5 listsDetails

GitMiner

Tool for advanced mining for content on Github by @UnkL4b.

In 2 lists

HTTPLeaks

All possible ways, a website can leak HTTP requests by @cure53.

In 2 lists

pwngitmanager

Git manager for pentesters by @allyshka.

snallygaster

Tool to scan for secret files on HTTP servers by @hannob.

In 2 lists

LinkFinder

Python script that finds endpoints in JavaScript files by @GerbenJavado.

In 4 listsDetails

keyFinder

Chrome extension that passively scans web pages for leaked API keys, tokens, and credentials across 10 attack surfaces using 80+ detection patterns and Shannon-entropy analysis, by @momenbasel.

In 5 listsDetails

Tools >Detecting

bXSS

bXSS is a simple Blind XSS application adapted from cure53.de/m by @LewisArdern.

In 2 lists

malware-jail

Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction by @HynekPetrak.

repo-supervisor

Scan your code for security misconfiguration, search for passwords and secrets.

In 3 lists

retire.js

Scanner detecting the use of JavaScript libraries with known vulnerabilities by @RetireJS.

In 3 lists

sqlchop

SQL injection detection engine by chaitin.

xsschop

XSS detection engine by chaitin.

OpenRASP

An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.

In 3 lists

GuardRails

A GitHub App that provides security feedback in Pull Requests.

In 4 listsDetails

Tools >Preventing

js-xss

Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist by @leizongmin.

In 5 listsDetails

Acra

Client-side encryption engine for SQL databases, with strong selective encryption, SQL injections prevention and intrusion detection by @cossacklabs.

In 6 listsDetails

DOMPurify

DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG by Cure53.

In 5 listsDetails

Csper

A set of tools for building/evaluating/monitoring content-security-policy to prevent/detect cross site scripting by Csper.

UUSEC WAF

An open-source web application firewall and API security gateway maintained by UUCORP.

BunkerWeb

A next-generation open-source Web Application Firewall built on nginx, maintained by Bunkerity.

In 4 listsDetails

FCaptcha

Self-hosted CAPTCHA with behavioral analysis, vision-AI agent detection, headless-browser fingerprinting, and SHA-256 proof-of-work, maintained by WebDecoy.

In 3 lists

Pompelmi

In-process file-upload security middleware for Node.js that scans untrusted uploads before storage to detect malware, MIME spoofing, and risky archives, maintained by pompelmi.

In 5 listsDetails

WebDecoy

Zero-configuration WordPress bot-detection plugin combining WebDriver detection, headless-browser fingerprinting, behavioral analysis, and SHA-256 proof-of-work, maintained by WebDecoy.

CrowdSec

Open-source collaborative IPS written in Go that analyzes visitor behavior and shares threat signals across a community of operators, maintained by CrowdSec.

Laravel CSP Generator

Interactive Content Security Policy builder for Laravel that outputs ready-to-use PHP middleware with nonce support and violation reporting, by @itxshakil.

verifyfetch

Browser-side integrity verification and resumable downloads for large files using SRI hashes, defending against CDN compromise and supply-chain attacks, by @hamzaydia.

In 4 listsDetails

Tools >Proxy

Charles

HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet.

In 6 listsDetails

mitmproxy

Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers by @mitmproxy.

In 10 listsDetails

Proxelar

Single-binary intercepting proxy for HTTP, HTTPS, and WebSocket traffic that pauses and edits requests in flight, replays them, rewrites traffic with Lua hooks, and exports captures as HAR, curl, or raw HTTP, available as a terminal UI, web GUI, or headless REST API, by @emanuele-em.

In 3 lists

Tools >Webshell

reverse-shell

Reverse Shell as a Service by @lukechilds.

In 2 lists

Reverse-Shell-Manager

Reverse Shell Manager via Terminal @WangYihang.

webshell

This is a webshell open source project by @tennc.

Webshell-Sniper

Manage your website via terminal by @WangYihang.

Weevely

Weaponized web shell by @epinna.

In 3 lists

nano

Family of code golfed PHP shells by @s0md3v.

PhpSploit

Full-featured C2 framework which silently persists on webserver via evil PHP oneliner by @nil0x42.

In 4 listsDetails

Tools >Disassembler

Iaitō

Qt and C++ GUI for radare2 reverse engineering framework by @hteso.

In 2 lists

plasma

Plasma is an interactive disassembler for x86/ARM/MIPS by @plasma-disassembler.

In 2 lists

radare2

Unix-like reverse engineering framework and commandline tools by @radare.

In 5 listsDetails

Tools >Decompiler

CFR

Another java decompiler by @LeeAtBenf.

Tools >DNS Rebinding

DNS Rebind Toolkit

DNS Rebind Toolkit is a frontend JavaScript framework for developing DNS Rebinding exploits against vulnerable hosts and services on a local area network (LAN) by @brannondorsey.

In 2 lists

dref

DNS Rebinding Exploitation Framework. Dref does the heavy-lifting for DNS rebinding by @mwrlabs.

Singularity of Origin

It includes the necessary components to rebind the IP address of the attack server DNS name to the target machine's IP address and to serve attack payloads to exploit vulnerable software on the target machine by @nccgroup.

In 2 lists

Whonow DNS Server

A malicious DNS server for executing DNS Rebinding attacks on the fly by @brannondorsey.

In 2 lists

Tools >Others

CyberChef

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis - by @GCHQ.

In 5 listsDetails

cefdebug

Minimal code to connect to a CEF debugger by @taviso.

ctftool

Interactive CTF Exploration Tool by @taviso.

In 4 listsDetails

ntlm_challenger

Parse NTLM over HTTP challenge messages by @b17zr.

Social Engineering Database

haveibeenpwned

Check if you have an account that has been compromised in a data breach by Troy Hunt.

In 8 listsDetails

Hudson Rock

Check if your email or domain was compromised by infostealer malware, maintained by Hudson Rock.

In 6 listsDetails

Blogs

BRETT BUERHAUS

Vulnerability disclosures and rambles on application security.

Broken Browser

Fun with Browser Vulnerabilities.

James Kettle

Head of Research at PortSwigger Web Security.

leavesongs

China's talented web penetrator.

n0tr00t

~# n0tr00t Security Team.

OpnSec

Open Mind Security!.

Orange

Taiwan's talented web penetrator.

Scrutiny

Internet Security through Web Browsers by Dhiraj Mishra.

0Day Labs

Awesome bug-bounty and challenges writeups.

Blog of Osanda

Security Researching and Reverse Engineering.

Twitter Users

@cure53berlin

Cure53 is a German cybersecurity firm.

@filedescriptor

Active penetrator often tweets and writes useful articles.

@garethheyes

English web penetrator.

@h3xstream

Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.

@HackwithGitHub

Initiative to showcase open source hacking tools for hackers and pentesters.

@hasegawayosuke

Japanese javascript security researcher.

@kinugawamasato

Japanese web penetrator.

@XssPayloads

The wonderland of JavaScript unexpected usages, and more.

@shhnjk

Web and Browsers Security Researcher.

Practices >Application

SELinux Game

Learn SELinux by doing. Solve Puzzles, show skillz - Written by @selinuxgame.

BadLibrary

Vulnerable web application for training - Written by @SecureSkyTechnology.

Hackxor

Realistic web application hacking game - Written by @albinowax.

OWASP Juice Shop

Probably the most modern and sophisticated insecure web application - Written by @bkimminich and the @owasp_juiceshop team.

In 3 lists

Portswigger Web Security Academy

Free trainings and labs - Written by PortSwigger.

In 4 listsDetails

OopsSec Store

Intentionally vulnerable e-commerce application built with Next.js - Written by @kOaDT.

In 4 listsDetails

The Next.js security-headers pitfall

Shows how a correct-looking Next.js headers() block can overwrite route-specific rules or differ from final CDN responses, with an inventory, merge, preview, deployed-route verification, and rollback workflow.

Where the LLM Stops: Deterministic Scoring in an AI-Assisted VAPT Pipeline

Technical write-up on designing an AI-assisted VAPT pipeline with deterministic CVSS scoring, passive confidence verification, and LLM-generated vulnerability explanations and remediation.

The 200 That Proved Nothing

Why a 200 OK is not proof of an access-control bug: a seeded BOLA benchmark where a model asked to confirm a secure endpoint 79 times and a downgrade-only code gate refused every one, plus the similarity thresholds, a deterministic check that failed the same way, and a plausible fix measured and…

Practices >AWS

FLAWS

Amazon AWS CTF challenge - Written by @0xdabbad00.

In 2 lists

CloudGoat

Rhino Security Labs' "Vulnerable by Design" AWS infrastructure setup tool - Written by @RhinoSecurityLabs.

In 3 lists

Practices >XSS

alert(1) to win

Series of XSS challenges - Written by @steike.

XSS Challenges

Series of XSS challenges - Written by yamagata21.

XSS game

Google XSS Challenge - Written by Google.

In 3 lists

Practices >ModSecurity / OWASP ModSecurity Core Rule Set

ModSecurity / OWASP ModSecurity Core Rule Set

Series of tutorials to install, configure and tune ModSecurity and the Core Rule Set - Written by @ChrFolini.

Community

Reddit

Stack Overflow

Miscellaneous

A glimpse into GitHub's Bug Bounty workflow

Written by @gregose.

awesome-bug-bounty

Comprehensive curated list of available Bug Bounty & Disclosure Programs and write-ups by @djadmin.

In 2 lists

Brute Forcing Your Facebook Email and Phone Number

Written by PwnDizzle.

bug-bounty-reference

List of bug bounty write-up that is categorized by the bug nature by @ngalongc.

In 3 lists

Cybersecurity Campaign Playbook

Written by Belfer Center for Science and International Affairs.

EQGRP

Decrypted content of eqgrp-auction-file.tar.xz by @x0rz.

Google VRP and Unicorns

Written by Daniel Stelter-Gliese.

Infosec_Reference

Information Security Reference That Doesn't Suck by @rmusser01.

In 6 listsDetails

notes

Some public notes by @ChALkeR.

Pentest + Exploit dev Cheatsheet wallpaper

Penetration Testing and Exploit Dev CheatSheet.

The Definitive Security Data Science and Machine Learning Guide

Written by JASON TROS.

$7.5k Google services mix-up

Written by Ezequiel Pereira.

The Bug Hunters Methodology v2.1

Written by @jhaddix.

How I exploited ACME TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain using shared hosting

Written by @fransrosen.

TL:DR: VPN leaks users’ IPs via WebRTC. I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC…

Written by voidsec.

Be careful what you copy: Invisibly inserting usernames into text with Zero-Width Characters

Written by @umpox.

Escape and Evasion Egressing Restricted Networks

Written by Chris Patten, Tom Steele.

Introduction to Web Application Security

Written by @itsC0rg1, @jmkeads and @matir.

Finding The Real Origin IPs Hiding Behind CloudFlare or TOR

Written by Paul Dannewitz.

An example why NAT is NOT security

Written by @0daywork.

WEB APPLICATION PENETRATION TESTING NOTES

Written by Jayson.

List of bug bounty writeups

Written by Mariem.

In 2 lists

The bug bounty program that changed my life

Written by Gwen.

Why Facebook's api starts with a for loop

Written by @AntoGarand.

WCTF2019: Gyotaku The Flag

Written by @t0nk42.

How we abused Slack's TURN servers to gain access to internal services

Written by @sandrogauci.

DOS File Path Magic Tricks

Written by @clr2of8.

How I got my first big bounty payout with Tesla

Written by @cj.fairhead.

Grokking Web Application Security

Hands-on introduction to web application security fundamentals by Malcolm McDonald (Manning).

In 2 lists

htb-writeups

Comprehensive Hack The Box writeup collection covering 75+ web challenges including XSS, SQLi, SSTI, SSRF, and deserialization, by @momenbasel.

In 2 lists

From DNS Evidence to a Finding: DNS and Mail Security Methodology

How DNSSEC, DANE, SPF/DKIM/DMARC and SMTP transport evidence becomes a finding, with the decision logic for each, the dig invocations to reproduce it independently, and the false positives to expect.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
86

Awesome Iam

kdeldycke/awesome-iam

👤 Identity and Access Management knowledge for cloud platforms

Fresh★ 2.3k237 entriesPushed 2 days ago