
Starred repositories
Learn how to design large-scale systems. Prep for the system design interview. Includes Anki flashcards.
An opinionated list of awesome Python frameworks, libraries, software and resources.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics…
Fast subdomains enumeration tool for penetration testers
Bandit is a tool designed to find common security issues in Python code.
🔥 Web-application firewalls (WAFs) from security standpoint.
Standard and Advanced Demos for learn.cantrill.io courses
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
Awesome IoT. A collaborative list of great resources about IoT Framework, Library, OS, Platform
Top disclosed reports from HackerOne
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
Automated Security Testing For REST API's
SSRF (Server Side Request Forgery) testing resources
The SpecterOps project management and reporting engine
A pentest reporting tool written in Python. Free yourself from Microsoft Word.
Open-source vulnerability disclosure and bug bounty program database
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
Scripts and a (future) library to improve users' interactions with the ATT&CK content