infoslack/awesome-web-hacking

A list of web application security

penetration-testingweb-hackingvulnerabilitiesscannerhackinghacking-toolsmetasploitweb-securityappsecowasppentestingsecurity
Croissance des étoiles
Étoiles
7.3k
Forks
1.4k
Croissance hebdomadaire
+7
Issues
5
2k4k6k
mai 2015févr. 2019nov. 2022sept. 2026
README

awesome-web-hacking

This list is for anyone wishing to learn about web application security but do not have a starting point.

You can help by sending Pull Requests to add more information.

If you're not inclined to make PRs you can tweet me at @infoslack

Table of Contents

Books

Documentation

Tools

  • SaaSFort - Free 60-second external NIS2 / security posture scan, A-F grade, no signup required.
  • ARS3NAL - Offline-first, searchable arsenal: ~1500 payloads, command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells and 70 checklists.
  • Mozilla - HTTP Observatory - Developed by Mozilla, the HTTP Observatory performs an in-depth assessment of a site’s HTTP headers and other key security configurations.
  • HTTP Security Report - Get an instant report of how your website measures up to the best practices.
  • ImmuniWeb CyberScore - free cybersecurity, privacy and AI security rating of your company, partners or suppliers
  • ImmuniWeb - Website Security Test - Checks for web security vulnerabilities, AI bot protection, HTTP security and privacy headers, DNSSEC configuration, CSP, and compliance with GDPR and PCI DSS. 10 free tests per month (without account)
  • Pentest Tools - Website Vulnerability Scanner - detects SQLi, XSS, command injection, XXE, and 75+ more web app vulnerabilities
  • Pentest Tools - Network Vulnerability Scanner - an online security tool designed to identify vulnerabilities, misconfigurations, outdated services, and exposed ports in network infrastructure

Cheat Sheets

Docker images for Penetration Testing

Vulnerabilities

Courses

Online Hacking Demonstration Sites

Labs

SSL

  • https://www.ssllabs.com/ssltest/index.html - This service performs a deep analysis of the configuration of any SSL web server on the public Internet.
  • http://certdb.com/ - SSL/TLS data provider service. Collect the data about digital certificates - issuers, organisation, whois, expiration dates, etc... Plus, has handy filters for convenience.
  • https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html - Strong SSL Security on nginx
  • https://weakdh.org/ - Weak Diffie-Hellman and the Logjam Attack
  • https://letsencrypt.org/ - Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open.
  • https://filippo.io/Heartbleed/ - A checker (site and tool) for CVE-2014-0160 (Heartbleed).
  • https://testssl.sh/ - A command line tool which checks a website's TLS/SSL ciphers, protocols and cryptographic flaws.
  • Scorifya - 0–100 security score for any website covering TLS, security headers (CSP, HSTS, X-Frame-Options), cookies, DNS, and email signals (SPF, DKIM, DMARC) with ranked fix steps.
  • ImmuniWeb SSL Security Test - a free online tool that checks the security of a website or email server’s SSL/TLS configuration. Сhecks compliance with security standards such as NIST, HIPAA, PCI DSS, and GDPR. 10 free tests per month (without account)

Security Ruby on Rails

Dépôts similaires
Hack-with-Github/Awesome-Hacking

A collection of various awesome lists for hackers, pentesters and security researchers

awesomeCreative Commons Zero v1.0 Universalhackingsecurity
120k10.7k
swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

PythonPyPItutorialMIT Licensepentestpayload
swisskyrepo.github.io/PayloadsAllTheThings/
80.7k17.4k
usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

PythonPyPIApache License 2.0agentsartificial-intelligence
strix.ai
61.4k6.7k
KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

TypeScriptnpmGNU Affero General Public License v3.0penetration-testingpentesting
keygraph.io
47.9k5.5k
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

PythonPyPIskillApache License 2.0ai-agentsclaude-code
mahipal.engineer/Anthropic-Cybersecurity-Skills/
32.4k3.9k
The-Art-of-Hacking/h4cker

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

Jupyter NotebookawesomeMIT Licensehackingpenetration-testing
hackerrepo.org
29.3k5.4k
vxcontrol/pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

GoGo ModulesMIT Licenseai-agentsai-security-tool
pentagi.com
22.6k3k
vitalysim/Awesome-Hacking-Resources

A collection of hacking / penetration testing resources to make you better!

awesomeGNU General Public License v3.0ctfhacking
17.4k2.2k
sundowndev/hacker-roadmap

A collection of hacking tools, resources and references to practice ethical hacking.

tutorialMIT Licensehackinghacking-tool
15.6k1.7k
GreyDGL/PentestGPT

Automated Penetration Testing Agentic Framework Powered by Large Language Models

PythonPyPIMIT Licensepenetration-testingpython
15.3k2.7k
maurosoria/dirsearch

Web path scanner

PythonPyPIfuzzerfuzzing
14.7k2.4k
Datalux/Osintgram

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

PythonPyPIGNU General Public License v3.0osintosint-python
14.3k3.1k