Skip to main content

A curated list of cyber security resources and tools.

731
GitHub Stars
156
Curated Resources
14
Categories
1 hour ago
Last Refreshed
Awesome listsThreat databases and alertsSecurity advice and guidanceLists of cyber security resourcesMust ReadFundamental BooksWeb Hacking & Bug BountyAI-powered security toolsSecure web application toolsSecure Software Development (OWASP)Platforms to learn cyber securityCertificationsOperational Technology (OT) and ICS SecurityCheck out also

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me threat databases and alerts resources from awesome-cyber-security"

Installation instructions →

What's inside

Threat databases and alerts

  • 0day.today

    0day.today - Biggest Exploits Database and 0day market - The Underground, is one of the world's most popular and comprehensive computer security web sites.

  • AdversaryGraph

    Self-hosted CTI-to-detection platform for ATT&CK/ATLAS mapping, IOC enrichment, TTP comparison, and analyst reporting.

  • ATT&CK

    ATT&CK is a knowledge base of cyber adversary behavior and taxonomy for adversarial actions across their lifecycle. ATT&CK has two parts: ATT&CK for Enterprise, which covers behavior against enterprise IT networks and cloud, and ATT&CK for Mobile, which focuses on behavior against mobile devices.

  • China National Vulnerability Database (CNNVD)

    Chinese government-run vulnerability database analoguous to the United States’s CVE database hosted by Mitre Corporation.

  • CVE PoC Search

    Search public GitHub proof-of-concept repositories by CVE identifier, with 30,000+ CVEs indexed and updated daily.

  • cve-search

    cve-search is accessible via a web interface and an HTTP API. cve-search is an interface to search publicly known information from security vulnerabilities in software and hardware along with their corresponding exposures.

Platforms to learn cyber security

Lists of cyber security resources

  • 25 Free Cybersecurity Resources, Courses, and Tools

    A plethora of free cybersecurity courses and resources on all topics related to the field.

  • 50+ Cybersecurity Resources

    Dark Cubed’s cybersecurity resources page provides links to dozens of 100% free resources you can use for your own business or for your customers.

  • ARS3NAL

    Offline-first, searchable arsenal of pentest & bug bounty resources: ~1500 payloads, command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells and 70 checklists.

  • COMPUTER SECURITY RESOURCE CENTER

    For 20 years, the Computer Security Resource Center (CSRC) has provided access to NIST's cybersecurity- and information security-related projects, publications, news and events. CSRC supports stakeholders in government, industry and academia—both in the U.S. and internationally.

  • Cyber Security Education

    This page is devoted to helping cyber security experts find the resources they need to grow and thrive.

  • Cybersecurity Related Websites

    The listing of related sites provide additional sources to pursue the topic of Cybersecurity. The sites include Government organizations, including federal agencies, Department of Defense and military service agencies, commercial organizations, and academic institutions.

Awesome lists

Operational Technology (OT) and ICS Security

  • Awesome ICS Security

    A curated list of resources for Industrial Control System and OT security including tools, frameworks, threat intelligence and functional safety integration resources.

  • ICS Cybersecurity Audit Framework

    A structured 5-phase cybersecurity audit methodology for ICS/OT environments aligned with IEC 62443, NIST SP 800-82 and IEC 62061 for safety-critical systems.

  • IEC 62061

    International standard for functional safety of safety-related control systems for machinery. Essential for OT environments where PLCs and safety interlocks perform SIL-classified safety functions.

  • NCSC Cyber Assessment Framework

    The UK National Cyber Security Centre framework for operators of essential services and critical national infrastructure covering governance, protection, detection and response.

  • NIST SP 800-82 Rev 3

    NIST Guide to Operational Technology Security covering OT-specific network architecture, incident response and the challenges of securing systems that cannot use standard IT patching processes.

  • OWASP OT Top 10

    Official OWASP Foundation project mapping the top 10 security risks in operational technology environments, with compliance mappings to IEC 62443, NIST SP 800-82 and IEC 62061.

Check out also

  • Awesome Storage

    A curated list of storage open source tools. Backups, redundancy, sharing, distribution, encryption, etc.

Secure Software Development (OWASP)

  • CycloneDX

    SBOM standard for software supply chain transparency.

  • NuGuard

    Open-source CLI that generates an AI-SBOM (AIBOM) and red-teams agentic AI applications for supply-chain and behavioral risks, alongside tools like CycloneDX and OWASP Dependency-Check.

  • OopsSec Store (OSS)

    An intentionally vulnerable e-commerce web application for CTF use.

  • OWASP API Security Top 10

    The top risks specific to API security.

  • OWASP ASVS

    Application Security Verification Standard for defining security requirements.

  • OWASP Cheat Sheet Series

    Pragmatic checklists and best practices for secure development.

Showing a sample of 156 resources. View the full list on GitHub →