awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to momenbasel/htb-writeups

Projects sharing features with Htb Writeups

30 open-source projects similar to momenbasel/htb-writeups, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • sagishahar/lpeworkshopsagishahar avatar

    sagishahar/lpeworkshop

    2,091View on GitHub↗

    Windows / Linux Local Privilege Escalation Workshop

    Batchfile
    View on GitHub↗2,091
  • koadt/oss-oopssec-storekOaDT avatar

    kOaDT/oss-oopssec-store

    22View on GitHub↗

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript
    View on GitHub↗22
  • rhinosecuritylabs/cloudgoatRhinoSecurityLabs avatar

    RhinoSecurityLabs/cloudgoat

    3,639View on GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python
    View on GitHub↗3,639
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu avatar

    zhuifengshaonianhanlu/pikachu

    4,421View on GitHub↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    View on GitHub↗4,421

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • edoverflow/bugbounty-cheatsheetEdOverflow avatar

    EdOverflow/bugbounty-cheatsheet

    6,498View on GitHub↗

    This project is a bug bounty resource directory, vulnerability research cheatsheet, and web security payload library. It serves as a centralized collection of curated payloads and common attack vectors used to identify security vulnerabilities in web applications. The repository provides a directory of platforms, books, and tools to support vulnerability discovery skills. It includes a reference for tested payloads and techniques used to trigger bugs and identify vulnerabilities during security audits. The content covers web application pentesting, security vulnerability testing, and general

    View on GitHub↗6,498
  • daffainfo/allaboutbugbountydaffainfo avatar

    daffainfo/AllAboutBugBounty

    6,644View on GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    View on GitHub↗6,644
  • antonio-morales/fuzzing101antonio-morales avatar

    antonio-morales/Fuzzing101

    3,796View on GitHub↗

    Fuzzing101 is an educational resource providing a structured curriculum and containerized security labs for learning software fuzzing and vulnerability research. It functions as a training course that guides users through the process of identifying security flaws using systematic input manipulation and memory corruption analysis. The project distinguishes itself by providing isolated environments that ensure consistent build dependencies for practicing software instrumentation and crash triaging. It includes a practical tutorial on using evolutionary fuzzing engines and instrumentation tools

    View on GitHub↗3,796
  • voorivex/pentest-guideVoorivex avatar

    Voorivex/pentest-guide

    2,761View on GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    View on GitHub↗2,761
  • dolevf/damn-vulnerable-graphql-applicationdolevf avatar

    dolevf/Damn-Vulnerable-GraphQL-Application

    1,691View on GitHub↗

    Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

    JavaScript
    View on GitHub↗1,691
  • facebook/threatexchangefacebook avatar

    facebook/ThreatExchange

    1,342View on GitHub↗

    Trust & Safety tools for working together to fight digital harms.

    C++
    View on GitHub↗1,342
  • google/google-ctfgoogle avatar

    google/google-ctf

    4,977View on GitHub↗

    This project is a capture the flag platform and cybersecurity training environment. It provides a framework for deploying security challenges and tracking participant progress through a real-time scoring leaderboard. The platform serves as a security competition scoreboard and management system, hosting intentionally vulnerable infrastructure for practicing reverse engineering and software exploitation techniques. It manages the discovery of secret strings within these puzzles to determine team rankings. The system covers cybersecurity competition management, security challenge deployment, a

    Pythonctfctf-challengesgoogle
    View on GitHub↗4,977
  • ine-labs/awsgoatine-labs avatar

    ine-labs/AWSGoat

    2,025View on GitHub↗

    AWSGoat : A Damn Vulnerable AWS Infrastructure

    PHP
    View on GitHub↗2,025
  • ine-labs/azuregoatine-labs avatar

    ine-labs/AzureGoat

    939View on GitHub↗

    AzureGoat : A Damn Vulnerable Azure Infrastructure

    Python
    View on GitHub↗939
  • jerryhoff/webgoat.netjerryhoff avatar

    jerryhoff/WebGoat.NET

    252View on GitHub↗

    OWASP WebGoat.NET

    C#
    View on GitHub↗252
  • adamdoupe/wackopickoadamdoupe avatar

    adamdoupe/WackoPicko

    350View on GitHub↗

    WackoPicko is a vulnerable web application used to test web application vulnerability scanners.

    PHP
    View on GitHub↗350
  • m6a-uds/dvcam6a-UdS avatar

    m6a-UdS/dvca

    211View on GitHub↗

    Damn Vulnerable Cloud Application

    CSS
    View on GitHub↗211
  • nccgroup/sadcloudnccgroup avatar

    nccgroup/sadcloud

    778View on GitHub↗

    A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

    HCL
    View on GitHub↗778
  • owasp/serverless-goatOWASP avatar

    OWASP/Serverless-Goat

    329View on GitHub↗

    OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

    Python
    View on GitHub↗329
  • paralax/lfi-labsparalax avatar

    paralax/lfi-labs

    335View on GitHub↗

    small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns

    PHP
    View on GitHub↗335
  • rapid7/hackazonrapid7 avatar

    rapid7/hackazon

    1,035View on GitHub↗

    A modern vulnerable web app

    HTML
    View on GitHub↗1,035
  • rpisec/malwareRPISEC avatar

    RPISEC/Malware

    4,028View on GitHub↗

    This project is a cybersecurity educational resource and courseware designed for malware analysis and reverse engineering. It provides a structured curriculum of lessons, labs, and guided projects focused on detecting and understanding the behavior of malicious software. The resource includes a lab guide for building isolated virtual machine environments to safely execute and study malware. It covers the setup of a specialized toolchain consisting of disassemblers and debuggers used to analyze compiled machine code. The training material covers both static analysis, which examines binary cod

    View on GitHub↗4,028
  • rpisec/mbeRPISEC avatar

    RPISEC/MBE

    5,989View on GitHub↗

    MBE is a security research educational resource providing binary exploitation courseware and a deployable CTF wargame environment. It functions as a structured curriculum of labs and materials designed for learning reverse engineering and memory corruption. The project provides containerized lab infrastructure and a binary analysis toolchain to ensure a controlled setting for vulnerability research. It utilizes isolated environments to deploy binary exploitation tasks, preventing interference and system instability. The system covers the provisioning of vulnerable environments through virtua

    Cctfexploitationwargame
    View on GitHub↗5,989
  • samsar4/ethical-hacking-labsSamsar4 avatar

    Samsar4/Ethical-Hacking-Labs

    3,397View on GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    View on GitHub↗3,397
  • secureskytechnology/badlibrarySecureSkyTechnology avatar

    SecureSkyTechnology/BadLibrary

    59View on GitHub↗

    vulnerable web application for training

    JavaScript
    View on GitHub↗59
  • sonofagl1tch/awsdetonationlabsonofagl1tch avatar

    sonofagl1tch/AWSDetonationLab

    73View on GitHub↗

    This script is used to generate some basic detections of the aws security services

    Shell
    View on GitHub↗73
  • tegal1337/0l4bstegal1337 avatar

    tegal1337/0l4bs

    341View on GitHub↗

    Cross-site scripting labs for web application security enthusiasts

    PHP
    View on GitHub↗341
  • x0rz/eqgrpx0rz avatar

    x0rz/EQGRP

    4,201View on GitHub↗

    EQGRP is a remote access trojan framework and post-exploitation toolkit. It provides a centralized command and control infrastructure for deploying persistent implants and managing remote agents across diverse operating systems. The project includes tools for digital forensic evasion, such as modifying system logs and filesystem timestamps to remove execution traces. It features a network interception system for capturing and reconstructing data streams by hooking into the system root, as well as exploits designed for kernel privilege escalation to elevate process permissions to administrativ

    Perl
    View on GitHub↗4,201
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530