GitHub repo leaderboard by stars, growth rate and activity.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Gather and update all available and newest CVEs with their PoC.
All about bug bounty (bypasses, payloads, and etc)
Open Source Vulnerability Management Platform
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | A list of useful payloads and bypass for Web Application Security and Pentest/CTF | Python | 80,733 | — | last pushed 2 weeks ago |
| 2 | Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more | Go | 37,840 | — | last pushed 2 days ago |
| 3 | This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org | Jupyter Notebook | 29,338 | — | last pushed 4 days ago |
| 4 | SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits. | Go | 22,537 | — | last pushed 1 week ago |
| 5 | A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. | Java | 9,048 | — | last pushed 9 months ago |
| 6 | Gather and update all available and newest CVEs with their PoC. | HTML | 8,056 | — | last pushed 3 days ago |
| 7 | A list of web application security | — | 7,262 | — | last pushed 7 days ago |
| 8 | All about bug bounty (bypasses, payloads, and etc) | — | 6,851 | — | last pushed 3 years ago |
| 9 | Open Source Vulnerability Management Platform | Python | 6,713 | — | last pushed 6 days ago |
| 10 | Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis. | Python | 4,082 | — | last pushed 5 weeks ago |
All · 11,474