awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

16 repository-uri

Awesome GitHub RepositoriesSecurity References

Curated lists, cheat sheets, and documentation for security research.

Explore 16 awesome GitHub repositories matching part of an awesome list · Security References. Refine with filters or upvote what's useful.

Awesome Security References GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • swisskyrepo/payloadsallthethingsAvatar swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434Vezi pe GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Useful payloads and bypasses for web security and CTFs.

    Pythonbountybugbountybypass
    Vezi pe GitHub↗78,434
  • owasp/cheatsheetseriesAvatar OWASP

    OWASP/CheatSheetSeries

    32,298Vezi pe GitHub↗

    The OWASP Cheat Sheet Series is a comprehensive, community-driven repository of concise security best practices and defensive coding patterns. It serves as a centralized knowledge base for developers and security professionals, providing actionable guidance to secure applications across the entire software development lifecycle. The project covers a vast array of security domains, ranging from fundamental web application hardening and authentication protocols to specialized controls for modern infrastructure and artificial intelligence systems. What distinguishes this project is its decentral

    Comprehensive guides for secure development and testing.

    Pythonapplication-securityappsecbest-practices
    Vezi pe GitHub↗32,298
  • enaqx/awesome-pentestAvatar enaqx

    enaqx/awesome-pentest

    26,410Vezi pe GitHub↗

    A collection of awesome penetration testing resources, tools and other shiny things

    Curated list of penetration testing tools and resources.

    awesomeawesome-list
    Vezi pe GitHub↗26,410
  • owasp/owasp-mstgAvatar OWASP

    OWASP/owasp-mstg

    12,973Vezi pe GitHub↗

    The Mobile Application Security Testing Guide is a comprehensive manual and compliance framework for verifying the security of mobile applications. It provides a standardized reference for identifying and validating common software security weaknesses and performing reverse engineering based on industry standards. The project provides a structured set of technical processes and checklists used to audit applications against established security weakness enumerations. It encompasses guidance for analyzing application binaries and runtime behavior to identify hidden functionality and security ga

    Comprehensive manual for mobile app security testing.

    Python
    Vezi pe GitHub↗12,973
  • juliocesarfort/public-pentesting-reportsAvatar juliocesarfort

    juliocesarfort/public-pentesting-reports

    9,587Vezi pe GitHub↗

    A list of public penetration test reports published by several consulting firms and academic security groups.

    List of public pentest reports from security groups.

    HTML
    Vezi pe GitHub↗9,587
  • jakejarvis/awesome-shodan-queriesAvatar jakejarvis

    jakejarvis/awesome-shodan-queries

    7,213Vezi pe GitHub↗

    Search queries for the Shodan search engine.

    awesomeawesome-listcloud
    Vezi pe GitHub↗7,213
  • daffainfo/allaboutbugbountyAvatar daffainfo

    daffainfo/AllAboutBugBounty

    6,644Vezi pe GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Includes methods for testing default credentials as part of security assessment workflows.

    bugbugbountybugbountytips
    Vezi pe GitHub↗6,644
  • edoverflow/bugbounty-cheatsheetAvatar EdOverflow

    EdOverflow/bugbounty-cheatsheet

    6,498Vezi pe GitHub↗

    This project is a bug bounty resource directory, vulnerability research cheatsheet, and web security payload library. It serves as a centralized collection of curated payloads and common attack vectors used to identify security vulnerabilities in web applications. The repository provides a directory of platforms, books, and tools to support vulnerability discovery skills. It includes a reference for tested payloads and techniques used to trigger bugs and identify vulnerabilities during security audits. The content covers web application pentesting, security vulnerability testing, and general

    Serves as a centralized security reference for strings and patterns used in vulnerability testing.

    Vezi pe GitHub↗6,498
  • ihebski/defaultcreds-cheat-sheetAvatar ihebski

    ihebski/DefaultCreds-cheat-sheet

    6,409Vezi pe GitHub↗

    DefaultCreds-cheat-sheet is a searchable reference database of default usernames and passwords for thousands of hardware and software products, designed for use during security assessments. It functions as a curated directory that maps vendor products to their known factory-set login credentials, enabling rapid lookup during penetration testing and security preparation workflows. The tool is delivered as a single-file client application with no backend dependencies, serving static content from any web server or local file system for offline use. It stores credential mappings in a flat JSON da

    Provides a searchable database of default usernames and passwords for thousands of products during security assessments.

    Pythonblueteamblueteam-toolsblueteaming
    Vezi pe GitHub↗6,409
  • streaak/keyhacksAvatar streaak

    streaak/keyhacks

    6,069Vezi pe GitHub↗

    Keyhacks is a command-line tool that tests whether API keys and tokens for dozens of cloud services are valid and active. It automates the verification of discovered credentials during security auditing and penetration testing, confirming if leaked or harvested API keys, tokens, and secrets are still operational. The tool validates credentials by sending lightweight, service-specific HTTP requests to each platform's API endpoint and inspecting the response status or body. Each validation runs independently without storing state between requests, using pre-defined request templates with the co

    Methods to check leaked API keys from bug bounties.

    Vezi pe GitHub↗6,069
  • mebus/cuppAvatar Mebus

    Mebus/cupp

    5,762Vezi pe GitHub↗

    CUPP is a suite of tools for extracting default credentials from aggregated databases, generating password dictionaries from personal data, profiling targets interactively, and expanding wordlists from dictionary sources. It functions as a password dictionary generator and target profiling tool that collects personal details through interactive questions to build custom password lists for security testing. The project distinguishes itself through a modular command pipeline architecture that chains independent subcommands for downloading remote wordlists, parsing structured credential database

    Parses default credentials from the Alecto database for security assessments.

    Pythondictionary-attackpasswordpassword-strength
    Vezi pe GitHub↗5,762
  • djadmin/awesome-bug-bountyAvatar djadmin

    djadmin/awesome-bug-bounty

    5,708Vezi pe GitHub↗

    A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.

    Curated list of bug bounty programs.

    Vezi pe GitHub↗5,708
  • owasp/go-scpO

    OWASP/Go-SCP

    5,285Vezi pe GitHub↗

    Go-SCP este un ghid de codare securizată și un framework de prevenire a vulnerabilităților pentru limbajul de programare Go. Servește drept manual tehnic pentru implementarea tiparelor de programare defensivă și a benchmark-urilor de securitate pentru a preveni vulnerabilitățile software comune. Proiectul funcționează ca o referință de securitate statică, mapând slăbiciunile software cunoscute la tipare specifice de remediere în Go. Oferă un repository curatoriat de standarde de codare securizată și practici de implementare verificate, axate în mod specific pe securitatea aplicațiilor web. Framework-ul acoperă auditarea securității prin compararea codului sursă cu benchmark-urile stabilite și utilizează maparea vulnerabilităților bazată pe tipare pentru a identifica defectele de programare. Ghidul este distribuit printr-o arhitectură de referință structurată și este disponibil în formate portabile precum PDF și ePub pentru referință offline.

    Provides a curated repository of secure coding standards as a finalized technical reference.

    Go
    Vezi pe GitHub↗5,285
  • s0md3v/awesomexssAvatar s0md3v

    s0md3v/AwesomeXSS

    5,058Vezi pe GitHub↗

    Collection of XSS resources and vectors.

    JavaScriptpayloadpayload-listxss
    Vezi pe GitHub↗5,058
  • securitum/researchAvatar securitum

    securitum/research

    151Vezi pe GitHub↗

    research

    Proof of Concepts of security research.

    JavaScript
    Vezi pe GitHub↗151
  • payloadbox/command-injection-payload-listP

    payloadbox/command-injection-payload-list

    0Vezi pe GitHub↗

    List of command injection payloads.

    Vezi pe GitHub↗0
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Security References

Explorează sub-etichetele

  • Default Credential DatabasesCurated collections of factory-set usernames and passwords for hardware and software products used in security assessments. **Distinct from Security References:** Distinct from Security References: focuses specifically on default credential lookups for penetration testing, not general security references or cheat sheets.