vizzdoom's Stars
ctfs/write-ups-2016
Wiki-like CTF write-ups repository, maintained by the community. 2016
GrrrDog/ZeroNights-WebVillage-2017
GrrrDog/Java-Deserialization-Cheat-Sheet
The cheat sheet about Java Deserialization vulnerabilities
mbechler/marshalsec
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
cure53/H5SC
HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
enaqx/awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
ashishb/android-security-awesome
A collection of android security related resources
wtsxDev/Malware-Analysis
List of awesome malware analysis tools and resources
shieldfy/API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
infobyte/faraday
Open Source Vulnerability Management Platform
cldrn/macphish
Office for Mac Macro Payload Generator
sektioneins/pcc
PHP Secure Configuration Checker
SerpicoProject/Serpico
SimplE RePort wrIting and COllaboration tool
hoaproject/Websocket
The Hoa\Websocket library.
joaomatosf/JavaDeserH2HC
Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).
TheHackerDev/race-the-web
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
devsecops/awesome-devsecops
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
vanhoefm/krackattacks-scripts
cyberheartmi9/CVE-2017-12617
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
Bo0oM/CVE-2017-7089
Webkit uxss exploit (CVE-2017-7089)
sakurity/racer
One-click utility to test race conditions
cure53/browser-sec-whitepaper
Cure53 Browser Security White Paper
OWASP/owasp-mastg
The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
digininja/pipal
Pipal, THE password analyser
xerub/img4lib
image4 vfs
bugcrowd/HUNT
leostat/rtfm
A database of common, interesting or useful commands, in one handy referable form
TheRook/subbrute
A DNS meta-query spider that enumerates DNS records, and subdomains.