awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Security research resources

排名更新于 2026年7月18日

For security research lists, the strongest matches are offensive-security/exploitdb (This is a comprehensive, industry-standard archive of exploit code), offensive-security/exploit-database (This repository is a comprehensive, industry-standard archive of software) and opencti-platform/opencti (OpenCTI is a comprehensive cyber threat intelligence platform that). rshipp/awesome-malware-analysis and hack-with-github/awesome-hacking round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Explore hand-picked security research repositories ranked by activity and community impact. Compare top tools to find the best fit for your workflow.

Security research resources

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • offensive-security/exploitdboffensive-security 的头像

    offensive-security/exploitdb

    7,845在 GitHub 上查看↗

    ExploitDB is a curated archive of exploit code and vulnerability data designed for penetration testing and security research. It serves as an offensive security knowledge base and a repository of publicly available proof-of-concept code used to validate software flaws. The project provides a searchable collection of historical and current exploit vectors. It supports security threat intelligence by tracking public releases and aids in vulnerability research by providing a reference library for analyzing how specific systems can be compromised. The archive is managed through a curated input p

    This is a comprehensive, industry-standard archive of exploit code and vulnerability data that serves as a primary resource for security researchers and penetration testers.

    Threat Intelligence ResourcesExploit DatabasesSecurity Tools
    在 GitHub 上查看↗7,845
  • offensive-security/exploit-databaseoffensive-security 的头像

    offensive-security/exploit-database

    7,849在 GitHub 上查看↗

    This project is a public exploit code archive and vulnerability database. It serves as a collection of documented software exploits and vulnerability data, providing a reference library of exploit scripts and payloads used to validate security flaws in target environments. The archive supports security threat intelligence, vulnerability research, and penetration testing workflows. It functions as a historical record of software vulnerabilities and the proof-of-concept code used to trigger them. The codebase is organized through directory-based categorization and flat-file data storage, utili

    This repository is a comprehensive, industry-standard archive of software exploits and vulnerability data that serves as a foundational resource for security research and penetration testing.

    Threat Intelligence ResourcesVulnerability Databases
    在 GitHub 上查看↗7,849
  • opencti-platform/openctiOpenCTI-Platform 的头像

    OpenCTI-Platform/opencti

    8,812在 GitHub 上查看↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    OpenCTI is a comprehensive cyber threat intelligence platform that serves as a centralized repository for managing vulnerability data, threat actor intelligence, and security research, making it a flagship tool for this category.

    TypeScriptThreat Intelligence PlatformsThreat Intelligence
    在 GitHub 上查看↗8,812
  • rshipp/awesome-malware-analysisrshipp 的头像

    rshipp/awesome-malware-analysis

    13,864在 GitHub 上查看↗

    This project is a comprehensive, community-driven directory of open-source tools, datasets, and documentation for malware analysis and cybersecurity research. It serves as a centralized index for security professionals and researchers to locate resources for investigating, reverse engineering, and analyzing malicious software. The directory organizes information through a structured taxonomy, covering specialized domains such as memory forensics, network traffic inspection, and honeypot threat research. By aggregating links to external utilities and frameworks, it provides a platform-agnostic

    This repository is a comprehensive, community-curated directory that aggregates a wide range of security research resources, malware analysis tools, and threat intelligence datasets, perfectly matching the intent for a centralized security knowledge hub.

    Security Research DirectoriesThreat Intelligence Resources
    在 GitHub 上查看↗13,864
  • hack-with-github/awesome-hackingHack-with-Github 的头像

    Hack-with-Github/Awesome-Hacking

    114,503在 GitHub 上查看↗

    This project is a community-maintained, open-source knowledge base that serves as a structured index for cybersecurity resources. It provides a centralized directory of tools, frameworks, and documentation designed to assist security researchers, penetration testers, and developers in hardening digital infrastructure and navigating the security tooling ecosystem. The repository distinguishes itself through a collaborative curation model that relies on distributed user contributions to maintain an accurate and up-to-date registry of technical assets. By organizing information into structured m

    This repository is a comprehensive, community-maintained index that aggregates security tools, research resources, and vulnerability-related documentation, perfectly matching the intent for a curated security intelligence collection.

    Security Research Directories
    在 GitHub 上查看↗114,503
  • vxunderground/malwaresourcecodevxunderground 的头像

    vxunderground/MalwareSourceCode

    18,415在 GitHub 上查看↗

    This project is a curated archive and cybersecurity research dataset of raw source code from various malware families. It serves as a malware analysis library designed to help researchers study the inner workings of different threats and identify attack patterns across multiple platforms and programming languages. The repository supports security research by providing raw text distribution of original source code. This allows for the study of platform vulnerabilities, threat intelligence gathering, and the development of security products and detection signatures. The collection is organized

    This repository serves as a specialized archive of malware source code, providing a valuable dataset for security researchers to study threat patterns and develop detection signatures.

    AssemblySecurity Research DirectoriesThreat Intelligence Resources
    在 GitHub 上查看↗18,415
  • google/osv.devgoogle 的头像

    google/osv.dev

    2,494在 GitHub 上查看↗

    OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability schema to track security flaws. It functions as a system for collecting and normalizing security data from diverse ecosystems into a single unified format, providing a web API for querying package vulnerabilities and submitting standardized records. The project distinguishes itself through a security advisory distribution service that supports bulk dataset exports via cloud storage buckets and incremental synchronization of security record updates. It also employs sandbox-bas

    OSV.dev is a comprehensive, standardized vulnerability database and aggregation platform that provides a unified API and dataset for tracking security flaws across diverse open-source ecosystems.

    PythonVulnerability DatabasesVulnerability Database APIs
    在 GitHub 上查看↗2,494
  • future-architect/vulsfuture-architect 的头像

    future-architect/vuls

    12,185在 GitHub 上查看↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Vuls is an automated vulnerability scanner and intelligence aggregator that cross-references software versions against CVE databases, serving as a functional tool for security auditing and vulnerability management.

    GoVulnerability DatabasesVulnerability ScannersVulnerability Scanners
    在 GitHub 上查看↗12,185
  • misp/mispMISP 的头像

    MISP/MISP

    6,360在 GitHub 上查看↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    MISP is a comprehensive threat intelligence platform that serves as a central repository for collecting, correlating, and sharing structured vulnerability and threat data, making it a flagship tool for security research and intelligence.

    PHPThreat IntelligenceThreat IntelligenceThreat Intelligence
    在 GitHub 上查看↗6,360
  • trickest/cvetrickest 的头像

    trickest/cve

    7,882在 GitHub 上查看↗

    This project is a vulnerability intelligence database and aggregator that organizes common vulnerabilities and exposures alongside their corresponding proof-of-concept exploit code. It functions as a security vulnerability tracker and an indexed directory of public exploit payloads. The system monitors new security flaws and updates to known exploits through repository watches and atom feeds. It utilizes automated aggregation to collect vulnerability details from centralized repositories and discovers associated exploit code via reference analysis and global searches. The tool provides capab

    This repository functions as a centralized vulnerability intelligence database and aggregator that tracks CVEs and their associated proof-of-concept exploits, directly serving the need for a curated security research resource.

    HTMLThreat Intelligence ResourcesVulnerability DatabasesSecurity Tools
    在 GitHub 上查看↗7,882
  • jekil/awesome-hackingjekil 的头像

    jekil/awesome-hacking

    3,746在 GitHub 上查看↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    This repository is a comprehensive, community-curated directory that aggregates a vast array of security tools, vulnerability research resources, and threat intelligence platforms, perfectly matching the intent for a centralized security knowledge base.

    PythonThreat Intelligence PlatformsThreat Intelligence
    在 GitHub 上查看↗3,746
  • projectdiscovery/nuclei-templatesprojectdiscovery 的头像

    projectdiscovery/nuclei-templates

    12,518在 GitHub 上查看↗

    Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous assessment of distributed infrastructure. It functions as a collection of structured configuration files that define how to identify security flaws and misconfigurations across web applications and network services. The project utilizes a declarative domain-specific language to decouple detection logic from the underlying execution engine. This approach allows for the creation of modular, protocol-agnostic scanning rules that can be updated independently of the core software. By

    This repository provides a comprehensive, community-driven collection of vulnerability detection templates that serve as the core intelligence for automated security scanning.

    JavaScriptVulnerability ScannersVulnerability Scanners
    在 GitHub 上查看↗12,518
  • intelowlproject/intelowlintelowlproject 的头像

    intelowlproject/IntelOwl

    4,605在 GitHub 上查看↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    IntelOwl is a threat intelligence platform that aggregates and enriches security data from various sources, serving as a powerful tool for incident investigation and threat analysis rather than a static repository of research papers or vulnerability disclosures.

    PythonThreat Intelligence PlatformsThreat IntelligenceThreat Intelligence
    在 GitHub 上查看↗4,605
  • google/security-researchgoogle 的头像

    google/security-research

    4,362在 GitHub 上查看↗

    This is a public archive of vulnerability findings, proof-of-concept code, and technical reports detailing security flaws discovered in third-party software. It functions as a coordinated vulnerability disclosure platform, enabling private reporting to vendors and structured publication of advisories after a fix is released or a 90-day deadline passes. The repository provides modular security analysis tooling—standalone scripts and binaries each targeting a specific bug class for automated detection—alongside a cross-platform fuzzing framework that runs tests across multiple operating systems

    This repository serves as a comprehensive archive for vulnerability disclosures, proof-of-concept exploits, and automated security analysis tools, directly fulfilling the need for a centralized security research and intelligence platform.

    CCoordinated Vulnerability DisclosuresVulnerability ResearchBug Class Detection Tools
    在 GitHub 上查看↗4,362
  • ctf-wiki/ctf-wikictf-wiki 的头像

    ctf-wiki/ctf-wiki

    9,449在 GitHub 上查看↗

    This project is a security training wiki and markdown knowledge base that provides technical guides, categorized exercises, and tool directories for participants in competitive security challenges. It serves as a comprehensive resource for capture the flag training, organizing learning materials into a searchable website. The knowledge base covers specialized security domains including cryptography, web security, and reverse engineering. It includes a curated directory of research tools and software used for vulnerability research and exploitation, alongside a repository of practical challeng

    This repository serves as a comprehensive, curated knowledge base for security research and offensive techniques, providing the educational resources and tool directories necessary for vulnerability analysis and security training.

    PythonSecurity Research Directories
    在 GitHub 上查看↗9,449
  • jivoi/awesome-osintjivoi 的头像

    jivoi/awesome-osint

    26,831在 GitHub 上查看↗

    This project is a comprehensive, community-curated directory of resources and methodologies for open-source intelligence gathering. It serves as a centralized reference framework for researchers, providing a structured index of specialized tools, databases, and search techniques used to collect and analyze publicly available information from across the global internet. The directory distinguishes itself through a hierarchical taxonomy that organizes complex investigative domains, ranging from cyber threat intelligence and digital forensic investigation to geospatial analysis and operational s

    This repository is a comprehensive, community-curated directory that aggregates a wide range of OSINT tools and intelligence-gathering resources, fitting the requirement for a curated collection of security research and investigative intelligence.

    Threat Intelligence PlatformsThreat Intelligence Resources
    在 GitHub 上查看↗26,831
  • vulhub/vulhubvulhub 的头像

    vulhub/vulhub

    20,279在 GitHub 上查看↗

    Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting. The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging

    This repository provides a collection of pre-configured, vulnerable environments specifically designed for security research and penetration testing practice, serving as a practical resource for vulnerability analysis.

    DockerfileVulnerability ScannersSecurity Tools
    在 GitHub 上查看↗20,279
  • trimstray/the-book-of-secret-knowledgetrimstray 的头像

    trimstray/the-book-of-secret-knowledge

    228,641在 GitHub 上查看↗

    This project serves as a centralized, community-driven repository of technical knowledge and administrative resources. It provides a structured taxonomy that aggregates disparate information into a searchable framework, supporting continuous learning and rapid problem-solving for system administrators and cybersecurity practitioners. By mapping resources across offensive security, infrastructure management, and software development, it offers a unified path for skill acquisition and professional reference. The project is defined by a command-line-first design philosophy, prioritizing terminal

    This repository is a comprehensive, community-curated collection of security resources, research links, and offensive/defensive tooling references that directly serves as a centralized knowledge base for cybersecurity practitioners.

    Security Research DirectoriesVulnerability Databases
    在 GitHub 上查看↗228,641
  • swisskyrepo/payloadsallthethingsswisskyrepo 的头像

    swisskyrepo/PayloadsAllTheThings

    78,434在 GitHub 上查看↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    This repository serves as a comprehensive, community-driven knowledge base for offensive security techniques and vulnerability research, functioning as a central reference for security professionals conducting assessments.

    PythonCommunity-Sourced Knowledge BasesSecurity Tools
    在 GitHub 上查看↗78,434
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is an automated security research and vulnerability scanning platform that provides the core capability of executing security analysis and vulnerability discovery, fitting the category as a functional tool for security research rather than a static collection or database.

    PythonVulnerability Scanners
    在 GitHub 上查看↗20,138
  • qazbnm456/awesome-web-securityqazbnm456 的头像

    qazbnm456/awesome-web-security

    13,097在 GitHub 上查看↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    This repository functions as a curated hub for web security research and documentation, effectively serving as a centralized resource for vulnerability intelligence and security training materials.

    Security Tools
    在 GitHub 上查看↗13,097
  • owasp/cheatsheetseriesOWASP 的头像

    OWASP/CheatSheetSeries

    32,298在 GitHub 上查看↗

    The OWASP Cheat Sheet Series is a comprehensive, community-driven repository of concise security best practices and defensive coding patterns. It serves as a centralized knowledge base for developers and security professionals, providing actionable guidance to secure applications across the entire software development lifecycle. The project covers a vast array of security domains, ranging from fundamental web application hardening and authentication protocols to specialized controls for modern infrastructure and artificial intelligence systems. What distinguishes this project is its decentral

    This repository serves as a centralized knowledge base for security best practices and defensive coding patterns, acting as a key resource for security research and application hardening.

    PythonSecurity Tools
    在 GitHub 上查看↗32,298
  • danielmiessler/seclistsdanielmiessler 的头像

    danielmiessler/SecLists

    71,596在 GitHub 上查看↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    This repository serves as a comprehensive, industry-standard collection of security assessment data, payloads, and wordlists that directly supports the vulnerability discovery and testing workflows requested.

    PHPSecurity WordlistsVulnerability Assessment and TestingAwesome List
    在 GitHub 上查看↗71,596
  • apsdehal/awesome-ctfapsdehal 的头像

    apsdehal/awesome-ctf

    11,614在 GitHub 上查看↗

    This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for cybersecurity competitions and offensive security research. It serves as a centralized index for tools used in cryptography, forensics, reverse engineering, and web exploitation, while providing structured materials for training and skill development. The repository distinguishes itself through a community-driven maintenance model that aggregates and organizes technical resources into a searchable, hierarchical structure. It facilitates knowledge transfer by cataloging expert pr

    This repository is a curated collection of security tools and educational resources that directly serves as a centralized index for offensive security research and vulnerability analysis.

    JavaScriptCapture The Flag CompetitionsAwesome ListCTF Hosting Platforms
    在 GitHub 上查看↗11,614
  • the-art-of-hacking/h4ckerThe-Art-of-Hacking 的头像

    The-Art-of-Hacking/h4cker

    27,620在 GitHub 上查看↗

    This project is a comprehensive cybersecurity knowledge repository that provides a structured collection of technical documentation, training materials, and professional development roadmaps. It serves as a centralized resource for practitioners to navigate complex security disciplines, ranging from offensive and defensive fundamentals to specialized infrastructure and application security. The repository distinguishes itself through a modular resource framework that enables users to construct isolated cyber range environments for hands-on practice. It also features a specialized reference gu

    This repository is a comprehensive, curated collection of cybersecurity resources, training materials, and technical documentation that serves as a centralized knowledge base for security research and vulnerability management.

    Jupyter NotebookKnowledge RepositoriesAwesome ListAI Security
    在 GitHub 上查看↗27,620
  • github/advisory-databasegithub 的头像

    github/advisory-database

    2,337在 GitHub 上查看↗

    The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s

    This repository serves as a centralized database for open-source software vulnerabilities and CVEs, providing a core component of security intelligence even though it lacks broader research papers or automated scanning tools.

    Vulnerability AggregatorsOpen Source SecuritySoftware Supply Chain Security
    在 GitHub 上查看↗2,337
  • kadenzipfel/smart-contract-vulnerabilitieskadenzipfel 的头像

    kadenzipfel/smart-contract-vulnerabilities

    2,466在 GitHub 上查看↗

    This project serves as a comprehensive knowledge base and technical reference for identifying and mitigating security vulnerabilities in smart contracts. It provides a structured catalog of common attack vectors, logic errors, and insecure coding patterns, offering developers and auditors a centralized resource for implementing secure decentralized applications. The repository distinguishes itself by covering the full lifecycle of contract security, from low-level arithmetic safety and compiler constraints to high-level architectural patterns. It details specific defensive strategies for mana

    This repository serves as a curated collection of smart contract vulnerabilities and mitigation strategies, functioning as a specialized intelligence resource for blockchain security research.

    Secure Decentralized Application DesignArithmetic Error MitigationsAuthorization Logic
    在 GitHub 上查看↗2,466
  • vxunderground/vxug-papersvxunderground 的头像

    vxunderground/VXUG-Papers

    1,393在 GitHub 上查看↗

    This project is a centralized repository and research database dedicated to the collection of technical documentation and source code concerning offensive security, malware development, and system exploitation. It serves as an archive for security professionals and researchers to study threat actor methodologies and historical security research. The repository functions as a static, version-controlled archive that organizes research papers and code samples into a flat-file directory structure. This approach ensures long-term availability and offline access to the materials, while a decentrali

    This repository serves as a curated collection of security research papers and malware-related source code, directly providing the specialized intelligence and research resources requested.

    CTechnical Research ArchivesMalware Research ArchivesSecurity Research Repositories
    在 GitHub 上查看↗1,393
  • microsoft/msrc-security-researchM

    Microsoft/MSRC-Security-Research

    0在 GitHub 上查看↗

    This project hosts security research from the Microsoft Security Response Center (MSRC).

    This repository serves as a direct collection of security research and vulnerability analysis published by Microsoft, aligning with the core intent of aggregating expert security findings.

    Hypervisor Security
    在 GitHub 上查看↗0
  • adalogics/software-security-paper-listAdaLogics 的头像

    AdaLogics/software-security-paper-list

    185在 GitHub 上查看↗

    This repository contains a curated list of papers relevant to: software security; program analysis; and systems security.

    This repository is a curated collection of academic and industry research papers focused on software and systems security, directly addressing the research-aggregation aspect of your search.

    PythonKnowledge Bases
    在 GitHub 上查看↗185
  • cyrusstoller/list-of-listscyrusstoller 的头像

    cyrusstoller/list-of-lists

    40在 GitHub 上查看↗

    list-of-lists

    This repository is a curated collection of lists covering various security domains, which directly aligns with your search for aggregated security research and resource directories.

    Curated List Directories
    在 GitHub 上查看↗40
  • feeicn/security-pptFeeiCN 的头像

    FeeiCN/Security-PPT

    3,607在 GitHub 上查看↗

    Security-related Slide Presentation & Security Research Report(大安全各领域各公司各会议分享的PPT以及各类安全研究报告)

    This repository serves as a curated collection of security research reports and conference presentations, directly addressing the need for aggregated security intelligence and research documentation.

    HTMLSecurity Intelligence
    在 GitHub 上查看↗3,607
  • nahamsec/resources-for-beginner-bug-bounty-huntersnahamsec 的头像

    nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters

    12,053在 GitHub 上查看↗

    This repository serves as a comprehensive educational guide and curriculum for individuals beginning their journey in web security and bug bounty hunting. It functions as a centralized hub that aggregates foundational knowledge, technical guides, and practical resources to assist newcomers in mastering the core principles of vulnerability research and ethical hacking. The project distinguishes itself through a community-driven curation model, where educational materials such as books, blogs, and labs are organized into structured learning paths. By leveraging a version-controlled, markdown-ba

    This repository acts as a curated collection of educational resources and methodologies for security research, fitting the category of a security resource aggregator even though it focuses on training rather than raw vulnerability intelligence feeds.

    Cybersecurity Training CollectionsSecurity GuidesTraining Curricula
    在 GitHub 上查看↗12,053
  • sundowndev/hacker-roadmapsundowndev 的头像

    sundowndev/hacker-roadmap

    15,081在 GitHub 上查看↗

    Hacker Roadmap is a community-driven repository that functions as a structured learning path and resource directory for cybersecurity and ethical hacking. It organizes complex security concepts into sequential modules, guiding users from fundamental knowledge to advanced technical exploitation skills through a curated collection of educational materials and professional development resources. The project distinguishes itself by acting as a centralized index that maps specialized third-party security software and isolated training environments to specific operational use cases. By aggregating

    This repository serves as a comprehensive, community-driven index that aggregates security research, learning paths, and links to various vulnerability and penetration testing tools, fitting the role of a curated resource platform.

    Awesome ListCurated Learning PathsLearning Roadmaps
    在 GitHub 上查看↗15,081
  • hacktricks-wiki/hacktricksHackTricks-wiki 的头像

    HackTricks-wiki/hacktricks

    11,700在 GitHub 上查看↗

    HackTricks is a comprehensive cybersecurity knowledge base and wiki designed to support ethical hacking, penetration testing, and infrastructure security auditing. It serves as a structured reference guide for security professionals, providing detailed documentation on common vulnerabilities, attack vectors, and remediation strategies across diverse software and network environments. The project distinguishes itself by offering actionable methodologies for identifying and analyzing security flaws. It functions as a centralized repository for security research, enabling practitioners to study

    This repository is a comprehensive, community-driven knowledge base that aggregates extensive security research, attack methodologies, and vulnerability documentation, serving as a central reference for security professionals.

    CSSPenetration Testing ResourcesSecurity VulnerabilitiesPenetration Testing and Ethical Hacking
    在 GitHub 上查看↗11,700
  • ignitetechnologies/mindmapIgnitetechnologies 的头像

    Ignitetechnologies/Mindmap

    8,656在 GitHub 上查看↗

    Mindmap is a cybersecurity knowledge base and reference library that organizes security tools, frameworks, and methodologies into a visual knowledge map. It functions as a curated directory of cheat sheets and command guides for offensive and defensive security operations, presented as a hierarchical interface with collapsible nodes. The project converts structured markdown files into navigable visual trees to facilitate the study of penetration testing workflows and DevOps learning roadmaps. It also serves as a security compliance framework, providing structured mappings of NIST and ISO 2700

    This repository serves as a curated knowledge base and reference library for security methodologies and tools, effectively acting as an organized directory for offensive and defensive security research.

    Knowledge Base VisualizersKnowledge MappingMarkdown-Based Knowledge Bases
    在 GitHub 上查看↗8,656
  • jaegeral/security-apisjaegeral 的头像

    jaegeral/security-apis

    982在 GitHub 上查看↗

    A collective list of public APIs for use in security. Contributions welcome

    This repository provides a curated collection of public security-focused APIs that serve as building blocks for vulnerability intelligence and security research workflows.

    General API Utilities
    在 GitHub 上查看↗982
  • lylemi/learn-web-hackingLyleMi 的头像

    LyleMi/Learn-Web-Hacking

    5,414在 GitHub 上查看↗

    Learn-Web-Hacking is a structured web security study guide and penetration testing knowledge base. It provides a collection of research notes focused on identifying and exploiting vulnerabilities in web applications and network protocols. The project includes specialized frameworks for evaluating security risks in large language models to prevent prompt injection, as well as guides for hardening cloud-native infrastructure, including container standards and orchestration tools. It also covers the analysis of identity standards and authentication protocols. The material spans a broad range of

    This repository serves as a structured knowledge base and study guide for security research, offering a curated collection of vulnerability analysis, penetration testing methodologies, and defensive hardening resources.

    PythonPenetration Testing ResourcesAttack Surface MappingCloud Infrastructure Security
    在 GitHub 上查看↗5,414
一览前 10 名对比
仓库Star 数语言许可证最后推送
offensive-security/exploitdb7.8K—gpl-2.02022年11月10日
offensive-security/exploit-database7.8K—GPL-2.02022年11月10日
opencti-platform/opencti8.8KTypeScriptother2026年2月19日
rshipp/awesome-malware-analysis13.9K—NOASSERTION2024年6月7日
hack-with-github/awesome-hacking114.5K—CC0-1.02026年5月7日
vxunderground/malwaresourcecode18.4KAssembly—2026年5月30日
google/osv.dev2.5KPythonapache-2.02026年2月19日
future-architect/vuls12.2KGoGPL-3.02026年6月17日
misp/misp6.4KPHPAGPL-3.02026年6月17日
trickest/cve7.9KHTMLMIT2026年6月16日

Related searches

  • 网络安全行业博客合集
  • a collection of security cheat sheets
  • 网络安全与分析
  • an open source network administration toolkit
  • a directory of open source software tools
  • an open source knowledge base platform
  • 特定主题的资源目录
  • Developer resource collections