awesome-cyber-security
github.com/okhosting/awesome-cyber-security ↗A curated list of cyber security resources and tools.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me threat databases and alerts resources from awesome-cyber-security"
Installation instructions →What's inside
Threat databases and alerts
- 0day.today
0day.today - Biggest Exploits Database and 0day market - The Underground, is one of the world's most popular and comprehensive computer security web sites.
- AdversaryGraph
Self-hosted CTI-to-detection platform for ATT&CK/ATLAS mapping, IOC enrichment, TTP comparison, and analyst reporting.
- ATT&CK
ATT&CK is a knowledge base of cyber adversary behavior and taxonomy for adversarial actions across their lifecycle. ATT&CK has two parts: ATT&CK for Enterprise, which covers behavior against enterprise IT networks and cloud, and ATT&CK for Mobile, which focuses on behavior against mobile devices.
- China National Vulnerability Database (CNNVD)
Chinese government-run vulnerability database analoguous to the United States’s CVE database hosted by Mitre Corporation.
- CVE PoC Search
Search public GitHub proof-of-concept repositories by CVE identifier, with 30,000+ CVEs indexed and updated daily.
- cve-search
cve-search is accessible via a web interface and an HTTP API. cve-search is an interface to search publicly known information from security vulnerabilities in software and hardware along with their corresponding exposures.
Platforms to learn cyber security
- 1200km Lab Work
Security labs covering CTI, detection engineering, vulnerable cloud, AI agent security, Android, Active Directory, Windows, Linux, and malware analysis workflows.
- Active Directory Security
- APIsec University
- Blueteamlabs
- Bug Bounty Guide
- BugBountyHunting.com
Lists of cyber security resources
- 25 Free Cybersecurity Resources, Courses, and Tools
A plethora of free cybersecurity courses and resources on all topics related to the field.
- 50+ Cybersecurity Resources
Dark Cubed’s cybersecurity resources page provides links to dozens of 100% free resources you can use for your own business or for your customers.
- ARS3NAL
Offline-first, searchable arsenal of pentest & bug bounty resources: ~1500 payloads, command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells and 70 checklists.
- COMPUTER SECURITY RESOURCE CENTER
For 20 years, the Computer Security Resource Center (CSRC) has provided access to NIST's cybersecurity- and information security-related projects, publications, news and events. CSRC supports stakeholders in government, industry and academia—both in the U.S. and internationally.
- Cyber Security Education
This page is devoted to helping cyber security experts find the resources they need to grow and thrive.
- Cybersecurity Related Websites
The listing of related sites provide additional sources to pursue the topic of Cybersecurity. The sites include Government organizations, including federal agencies, Department of Defense and military service agencies, commercial organizations, and academic institutions.
Awesome lists
- Awesome Cyber Security
A collection of awesome software, libraries, documents, books, resources and cool stuff about security.
- Awesome Machine Learning for Cyber Security
A curated list of amazingly awesome tools and resources related to the use of machine learning for cyber security.
- Awesome Malware Analysis
A curated list of awesome malware analysis tools and resources.
- Awesome ML for CVE Analysis
A curated list of machine learning resources for automated CVE analysis
- awesome-mobile-security
Maintained by @vaib25vicky with contributions from the security and developer communities.
- Awesome Security
A collection of awesome software, libraries, documents, books, resources and cool stuff about security.
Check out also
- Awesome Storage
A curated list of storage open source tools. Backups, redundancy, sharing, distribution, encryption, etc.
Must Read
Secure Software Development (OWASP)
- CycloneDX
SBOM standard for software supply chain transparency.
- OopsSec Store (OSS)
An intentionally vulnerable e-commerce web application for CTF use.
- OWASP API Security Top 10
The top risks specific to API security.
- OWASP ASVS
Application Security Verification Standard for defining security requirements.
- OWASP Cheat Sheet Series
Pragmatic checklists and best practices for secure development.
- OWASP Dependency-Check
Software Composition Analysis (SCA) to find vulnerable dependencies.
Fundamental Books
- Darkmoon
Open source (GPL-3.0) autonomous AI penetration testing platform covering web, API, Active Directory and Kubernetes, orchestrating 80+ offensive tools as an MCP host with proof of exploitation and a local privacy gateway (the LLM never sees real IPs or credentials).
- Ethical Hacking
- Foundations of Information Security
- Metasploit
- Penetration Testing
- The Tangled Web: A Guide to Securing Modern Web Applications
Showing a sample of 139 resources. View the full list on GitHub →