For security research lists, the strongest matches are offensive-security/exploitdb (This is a comprehensive, industry-standard archive of exploit code), offensive-security/exploit-database (This repository is a comprehensive, industry-standard archive of software) and opencti-platform/opencti (OpenCTI is a comprehensive cyber threat intelligence platform that). rshipp/awesome-malware-analysis and hack-with-github/awesome-hacking round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Explore hand-picked security research repositories ranked by activity and community impact. Compare top tools to find the best fit for your workflow.
ExploitDB is a curated archive of exploit code and vulnerability data designed for penetration testing and security research. It serves as an offensive security knowledge base and a repository of publicly available proof-of-concept code used to validate software flaws. The project provides a searchable collection of historical and current exploit vectors. It supports security threat intelligence by tracking public releases and aids in vulnerability research by providing a reference library for analyzing how specific systems can be compromised. The archive is managed through a curated input p
This is a comprehensive, industry-standard archive of exploit code and vulnerability data that serves as a primary resource for security researchers and penetration testers.
This project is a public exploit code archive and vulnerability database. It serves as a collection of documented software exploits and vulnerability data, providing a reference library of exploit scripts and payloads used to validate security flaws in target environments. The archive supports security threat intelligence, vulnerability research, and penetration testing workflows. It functions as a historical record of software vulnerabilities and the proof-of-concept code used to trigger them. The codebase is organized through directory-based categorization and flat-file data storage, utili
This repository is a comprehensive, industry-standard archive of software exploits and vulnerability data that serves as a foundational resource for security research and penetration testing.
OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
OpenCTI is a comprehensive cyber threat intelligence platform that serves as a centralized repository for managing vulnerability data, threat actor intelligence, and security research, making it a flagship tool for this category.
This project is a comprehensive, community-driven directory of open-source tools, datasets, and documentation for malware analysis and cybersecurity research. It serves as a centralized index for security professionals and researchers to locate resources for investigating, reverse engineering, and analyzing malicious software. The directory organizes information through a structured taxonomy, covering specialized domains such as memory forensics, network traffic inspection, and honeypot threat research. By aggregating links to external utilities and frameworks, it provides a platform-agnostic
This repository is a comprehensive, community-curated directory that aggregates a wide range of security research resources, malware analysis tools, and threat intelligence datasets, perfectly matching the intent for a centralized security knowledge hub.
This project is a community-maintained, open-source knowledge base that serves as a structured index for cybersecurity resources. It provides a centralized directory of tools, frameworks, and documentation designed to assist security researchers, penetration testers, and developers in hardening digital infrastructure and navigating the security tooling ecosystem. The repository distinguishes itself through a collaborative curation model that relies on distributed user contributions to maintain an accurate and up-to-date registry of technical assets. By organizing information into structured m
This repository is a comprehensive, community-maintained index that aggregates security tools, research resources, and vulnerability-related documentation, perfectly matching the intent for a curated security intelligence collection.
This project is a curated archive and cybersecurity research dataset of raw source code from various malware families. It serves as a malware analysis library designed to help researchers study the inner workings of different threats and identify attack patterns across multiple platforms and programming languages. The repository supports security research by providing raw text distribution of original source code. This allows for the study of platform vulnerabilities, threat intelligence gathering, and the development of security products and detection signatures. The collection is organized
This repository serves as a specialized archive of malware source code, providing a valuable dataset for security researchers to study threat patterns and develop detection signatures.
OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability schema to track security flaws. It functions as a system for collecting and normalizing security data from diverse ecosystems into a single unified format, providing a web API for querying package vulnerabilities and submitting standardized records. The project distinguishes itself through a security advisory distribution service that supports bulk dataset exports via cloud storage buckets and incremental synchronization of security record updates. It also employs sandbox-bas
OSV.dev is a comprehensive, standardized vulnerability database and aggregation platform that provides a unified API and dataset for tracking security flaws across diverse open-source ecosystems.
Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit
Vuls is an automated vulnerability scanner and intelligence aggregator that cross-references software versions against CVE databases, serving as a functional tool for security auditing and vulnerability management.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
MISP is a comprehensive threat intelligence platform that serves as a central repository for collecting, correlating, and sharing structured vulnerability and threat data, making it a flagship tool for security research and intelligence.
This project is a vulnerability intelligence database and aggregator that organizes common vulnerabilities and exposures alongside their corresponding proof-of-concept exploit code. It functions as a security vulnerability tracker and an indexed directory of public exploit payloads. The system monitors new security flaws and updates to known exploits through repository watches and atom feeds. It utilizes automated aggregation to collect vulnerability details from centralized repositories and discovers associated exploit code via reference analysis and global searches. The tool provides capab
This repository functions as a centralized vulnerability intelligence database and aggregator that tracks CVEs and their associated proof-of-concept exploits, directly serving the need for a curated security research resource.
This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c
This repository is a comprehensive, community-curated directory that aggregates a vast array of security tools, vulnerability research resources, and threat intelligence platforms, perfectly matching the intent for a centralized security knowledge base.
Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous assessment of distributed infrastructure. It functions as a collection of structured configuration files that define how to identify security flaws and misconfigurations across web applications and network services. The project utilizes a declarative domain-specific language to decouple detection logic from the underlying execution engine. This approach allows for the creation of modular, protocol-agnostic scanning rules that can be updated independently of the core software. By
This repository provides a comprehensive, community-driven collection of vulnerability detection templates that serve as the core intelligence for automated security scanning.
IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco
IntelOwl is a threat intelligence platform that aggregates and enriches security data from various sources, serving as a powerful tool for incident investigation and threat analysis rather than a static repository of research papers or vulnerability disclosures.
This is a public archive of vulnerability findings, proof-of-concept code, and technical reports detailing security flaws discovered in third-party software. It functions as a coordinated vulnerability disclosure platform, enabling private reporting to vendors and structured publication of advisories after a fix is released or a 90-day deadline passes. The repository provides modular security analysis tooling—standalone scripts and binaries each targeting a specific bug class for automated detection—alongside a cross-platform fuzzing framework that runs tests across multiple operating systems
This repository serves as a comprehensive archive for vulnerability disclosures, proof-of-concept exploits, and automated security analysis tools, directly fulfilling the need for a centralized security research and intelligence platform.
This project is a security training wiki and markdown knowledge base that provides technical guides, categorized exercises, and tool directories for participants in competitive security challenges. It serves as a comprehensive resource for capture the flag training, organizing learning materials into a searchable website. The knowledge base covers specialized security domains including cryptography, web security, and reverse engineering. It includes a curated directory of research tools and software used for vulnerability research and exploitation, alongside a repository of practical challeng
This repository serves as a comprehensive, curated knowledge base for security research and offensive techniques, providing the educational resources and tool directories necessary for vulnerability analysis and security training.
This project is a comprehensive, community-curated directory of resources and methodologies for open-source intelligence gathering. It serves as a centralized reference framework for researchers, providing a structured index of specialized tools, databases, and search techniques used to collect and analyze publicly available information from across the global internet. The directory distinguishes itself through a hierarchical taxonomy that organizes complex investigative domains, ranging from cyber threat intelligence and digital forensic investigation to geospatial analysis and operational s
This repository is a comprehensive, community-curated directory that aggregates a wide range of OSINT tools and intelligence-gathering resources, fitting the requirement for a curated collection of security research and investigative intelligence.
Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting. The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging
This repository provides a collection of pre-configured, vulnerable environments specifically designed for security research and penetration testing practice, serving as a practical resource for vulnerability analysis.
This project serves as a centralized, community-driven repository of technical knowledge and administrative resources. It provides a structured taxonomy that aggregates disparate information into a searchable framework, supporting continuous learning and rapid problem-solving for system administrators and cybersecurity practitioners. By mapping resources across offensive security, infrastructure management, and software development, it offers a unified path for skill acquisition and professional reference. The project is defined by a command-line-first design philosophy, prioritizing terminal
This repository is a comprehensive, community-curated collection of security resources, research links, and offensive/defensive tooling references that directly serves as a centralized knowledge base for cybersecurity practitioners.
This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i
This repository serves as a comprehensive, community-driven knowledge base for offensive security techniques and vulnerability research, functioning as a central reference for security professionals conducting assessments.
Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno
Strix is an automated security research and vulnerability scanning platform that provides the core capability of executing security analysis and vulnerability discovery, fitting the category as a functional tool for security research rather than a static collection or database.
This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil
This repository functions as a curated hub for web security research and documentation, effectively serving as a centralized resource for vulnerability intelligence and security training materials.
The OWASP Cheat Sheet Series is a comprehensive, community-driven repository of concise security best practices and defensive coding patterns. It serves as a centralized knowledge base for developers and security professionals, providing actionable guidance to secure applications across the entire software development lifecycle. The project covers a vast array of security domains, ranging from fundamental web application hardening and authentication protocols to specialized controls for modern infrastructure and artificial intelligence systems. What distinguishes this project is its decentral
This repository serves as a centralized knowledge base for security best practices and defensive coding patterns, acting as a key resource for security research and application hardening.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
This repository serves as a comprehensive, industry-standard collection of security assessment data, payloads, and wordlists that directly supports the vulnerability discovery and testing workflows requested.
This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for cybersecurity competitions and offensive security research. It serves as a centralized index for tools used in cryptography, forensics, reverse engineering, and web exploitation, while providing structured materials for training and skill development. The repository distinguishes itself through a community-driven maintenance model that aggregates and organizes technical resources into a searchable, hierarchical structure. It facilitates knowledge transfer by cataloging expert pr
This repository is a curated collection of security tools and educational resources that directly serves as a centralized index for offensive security research and vulnerability analysis.
This project is a comprehensive cybersecurity knowledge repository that provides a structured collection of technical documentation, training materials, and professional development roadmaps. It serves as a centralized resource for practitioners to navigate complex security disciplines, ranging from offensive and defensive fundamentals to specialized infrastructure and application security. The repository distinguishes itself through a modular resource framework that enables users to construct isolated cyber range environments for hands-on practice. It also features a specialized reference gu
This repository is a comprehensive, curated collection of cybersecurity resources, training materials, and technical documentation that serves as a centralized knowledge base for security research and vulnerability management.
The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s
This repository serves as a centralized database for open-source software vulnerabilities and CVEs, providing a core component of security intelligence even though it lacks broader research papers or automated scanning tools.
This project serves as a comprehensive knowledge base and technical reference for identifying and mitigating security vulnerabilities in smart contracts. It provides a structured catalog of common attack vectors, logic errors, and insecure coding patterns, offering developers and auditors a centralized resource for implementing secure decentralized applications. The repository distinguishes itself by covering the full lifecycle of contract security, from low-level arithmetic safety and compiler constraints to high-level architectural patterns. It details specific defensive strategies for mana
This repository serves as a curated collection of smart contract vulnerabilities and mitigation strategies, functioning as a specialized intelligence resource for blockchain security research.
This project is a centralized repository and research database dedicated to the collection of technical documentation and source code concerning offensive security, malware development, and system exploitation. It serves as an archive for security professionals and researchers to study threat actor methodologies and historical security research. The repository functions as a static, version-controlled archive that organizes research papers and code samples into a flat-file directory structure. This approach ensures long-term availability and offline access to the materials, while a decentrali
This repository serves as a curated collection of security research papers and malware-related source code, directly providing the specialized intelligence and research resources requested.
This project hosts security research from the Microsoft Security Response Center (MSRC).
This repository serves as a direct collection of security research and vulnerability analysis published by Microsoft, aligning with the core intent of aggregating expert security findings.
This repository contains a curated list of papers relevant to: software security; program analysis; and systems security.
This repository is a curated collection of academic and industry research papers focused on software and systems security, directly addressing the research-aggregation aspect of your search.
list-of-lists
This repository is a curated collection of lists covering various security domains, which directly aligns with your search for aggregated security research and resource directories.
Security-related Slide Presentation & Security Research Report(大安全各领域各公司各会议分享的PPT以及各类安全研究报告)
This repository serves as a curated collection of security research reports and conference presentations, directly addressing the need for aggregated security intelligence and research documentation.
This repository serves as a comprehensive educational guide and curriculum for individuals beginning their journey in web security and bug bounty hunting. It functions as a centralized hub that aggregates foundational knowledge, technical guides, and practical resources to assist newcomers in mastering the core principles of vulnerability research and ethical hacking. The project distinguishes itself through a community-driven curation model, where educational materials such as books, blogs, and labs are organized into structured learning paths. By leveraging a version-controlled, markdown-ba
This repository acts as a curated collection of educational resources and methodologies for security research, fitting the category of a security resource aggregator even though it focuses on training rather than raw vulnerability intelligence feeds.
Hacker Roadmap is a community-driven repository that functions as a structured learning path and resource directory for cybersecurity and ethical hacking. It organizes complex security concepts into sequential modules, guiding users from fundamental knowledge to advanced technical exploitation skills through a curated collection of educational materials and professional development resources. The project distinguishes itself by acting as a centralized index that maps specialized third-party security software and isolated training environments to specific operational use cases. By aggregating
This repository serves as a comprehensive, community-driven index that aggregates security research, learning paths, and links to various vulnerability and penetration testing tools, fitting the role of a curated resource platform.
HackTricks is a comprehensive cybersecurity knowledge base and wiki designed to support ethical hacking, penetration testing, and infrastructure security auditing. It serves as a structured reference guide for security professionals, providing detailed documentation on common vulnerabilities, attack vectors, and remediation strategies across diverse software and network environments. The project distinguishes itself by offering actionable methodologies for identifying and analyzing security flaws. It functions as a centralized repository for security research, enabling practitioners to study
This repository is a comprehensive, community-driven knowledge base that aggregates extensive security research, attack methodologies, and vulnerability documentation, serving as a central reference for security professionals.
Mindmap is a cybersecurity knowledge base and reference library that organizes security tools, frameworks, and methodologies into a visual knowledge map. It functions as a curated directory of cheat sheets and command guides for offensive and defensive security operations, presented as a hierarchical interface with collapsible nodes. The project converts structured markdown files into navigable visual trees to facilitate the study of penetration testing workflows and DevOps learning roadmaps. It also serves as a security compliance framework, providing structured mappings of NIST and ISO 2700
This repository serves as a curated knowledge base and reference library for security methodologies and tools, effectively acting as an organized directory for offensive and defensive security research.
A collective list of public APIs for use in security. Contributions welcome
This repository provides a curated collection of public security-focused APIs that serve as building blocks for vulnerability intelligence and security research workflows.
Learn-Web-Hacking is a structured web security study guide and penetration testing knowledge base. It provides a collection of research notes focused on identifying and exploiting vulnerabilities in web applications and network protocols. The project includes specialized frameworks for evaluating security risks in large language models to prevent prompt injection, as well as guides for hardening cloud-native infrastructure, including container standards and orchestration tools. It also covers the analysis of identity standards and authentication protocols. The material spans a broad range of
This repository serves as a structured knowledge base and study guide for security research, offering a curated collection of vulnerability analysis, penetration testing methodologies, and defensive hardening resources.
| 仓库 | Star 数 | 语言 | 许可证 | 最后推送 |
|---|---|---|---|---|
| offensive-security/exploitdb | 7.8K | — | gpl-2.0 | |
| offensive-security/exploit-database | 7.8K | — | GPL-2.0 | |
| opencti-platform/opencti | 8.8K | TypeScript | other | |
| rshipp/awesome-malware-analysis | 13.9K | — | NOASSERTION | |
| hack-with-github/awesome-hacking | 114.5K | — | CC0-1.0 | |
| vxunderground/malwaresourcecode | 18.4K | Assembly | — | |
| google/osv.dev | 2.5K | Python | apache-2.0 | |
| future-architect/vuls | 12.2K | Go | GPL-3.0 | |
| misp/misp | 6.4K | PHP | AGPL-3.0 | |
| trickest/cve | 7.9K | HTML | MIT |