Skip to main content

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

771
GitHub Stars
248
Curated Resources
12
Categories
23 hours ago
Last Refreshed
PlatformsForensicsWebCryptographyExploiting / PwnMiscReversingSteganographyOnline PlatformsCollaborative ToolsWriteups RepositoriesCourses

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me online platforms resources from awesome-ctf-resources"

Installation instructions →

What's inside

Online Platforms

Exploiting / Pwn

  • afl

    Security-oriented fuzzer.

  • honggfuzz

    Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage.

  • libformatstr

    Simplify format string exploitation.

  • One_gadget

    Tool for finding one gadget RCE.

  • Pwntools

    CTF framework for writing exploits.

  • ROPgadget

    Framework for ROP exploitation.

Reversing

  • Androguard

    Androguard is a full python tool to play with Android files.

  • Angr

    A powerful and user-friendly binary analysis platform.

  • Apk2gold

    CLI tool for decompiling Android apps to Java.

  • ApkTool

    A tool for reverse engineering 3rd party, closed, binary Android apps.

  • Binary Ninja

    Binary Analysis Framework.

  • BinUtils

    Collection of binary tools.

Misc

  • Any.run

    Interactive malware hunting service.

  • boofuzz

    Network Protocol Fuzzing for Humans.

  • Brainfuck

    Brainfuck esoteric programming language IDE.

  • changeme

    A default credential scanner.

  • COW

    It is a Brainfuck variant designed humorously with Bovinae in mind.

  • Hashcat

    Advanced Password Recovery.

Forensics

Steganography

  • AperiSolve

    Platform which performs layer analysis on images.

  • BPStegano

    Python3 based LSB steganography.

  • DeepSound

    Freeware steganography tool and audio converter that hides secret data into audio files.

  • DTMF Detection

    Audio frequencies common to a phone button.

  • DTMF Tones

    Audio frequencies common to a phone button.

  • Exif

    Shows EXIF information in JPEG files.

Web

  • Arachni

    Web Application Security Scanner Framework.

  • Beautifier.io

    Online JavaScript Beautifier.

  • BurpSuite

    A graphical tool to testing website security.

  • Commix

    Automated All-in-One OS Command Injection Exploitation Tool.

  • debugHunter

    Discover hidden debugging parameters and uncover web application secrets.

  • Dirhunt

    Find web directories without bruteforce.

Showing a sample of 248 resources. View the full list on GitHub →