awesome-cyber-security
github.com/tzurilabs/awesome-cyber-security ↗A bunch of resources containing learning resources, certifications, security frameworks, bug bounties, podcasts and tools used for cyber security.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me web application pentesting resources from awesome-cyber-security"
Installation instructions →What's inside
Tools
- AcuneticsWeb Application Pentesting
An automated web application security scanner that checks for vulnerabilities like SQL injection, XSS, and more.
- Aircrack-ngNetwork Pentesting
A suite of tools for assessing Wi-Fi network security, including capturing packets and cracking WEP/WPA/WPA2 keys.
- Any RunNetwork Security
An interactive online malware analysis service that allows users to run and analyze malicious files in real time.
- BeEFWeb Application Pentesting
a powerful tool that can perform various tasks aimed at exploiting vulnerabilities in web browsers.
- Burpsuite (Intruder)Web Application Pentesting
Besides scanning, Burp's Intruder tool can be used for brute-forcing and payload injection.
- CCleanerNetwork Pentesting
A tool used to remove unnecessary files and clear logs to cover tracks after an attack.
Bug Bounties
- app.cyberarmy.id
An Indonesian bug bounty platform connecting security researchers with companies to help them identify and resolve vulnerabilities.
- Bugcrowd
A crowdsourced cybersecurity platform offering bug bounty programs to help organizations identify and fix vulnerabilities.
- Hackerone
A leading bug bounty platform that connects businesses with ethical hackers to find and report security vulnerabilities.
- Patchstack
A bug bounty platform focused on securing WordPress plugins and themes through vulnerability disclosure and patching.
- Redstorm.io
A bug bounty platform that allows hackers to report vulnerabilities in exchange for rewards, focusing on improving cybersecurity for businesses.
- Yeswehack
A global bug bounty platform providing opportunities for ethical hackers to find vulnerabilities in various organizations' systems.
Misc
- awesome-cyber-skillsMore Awesome Repos (actively maintained)
A curated list of hacking environments where you can train your cyber skills.
- awesome-osintMore Awesome Repos (actively maintained)
A curated list of amazingly awesome Open-Source Intelligence.
- awesome-threat-intelligenceMore Awesome Repos (actively maintained)
A curated list of Awesome Threat Intelligence resources.
- the-book-of-secret-knowledgeMore Awesome Repos (actively maintained)
A huge collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
Learning Resources
- Backend API fundamentals using Expressjs (Freecodecamp)Basic Concepts
A course focused on building backend APIs using Express.js, teaching how to handle HTTP requests and data.
- Black Hat Python, 2nd Edition: Python Programming for Hackers and PentestersBooks
A book that teaches Python programming techniques for writing security tools and scripts for penetration testing.
- BugCrowdCTFCTF Platforms
A bug bounty website that sometimes runs CTF challenges to help you practice finding security flaws.
- CompTIA Security+ SY0-701 Certification Guide: Master Cybersecurity Fundamentals and Pass the SY0-701 Exam on Your First AttemptBooks
A study guide that covers all the cybersecurity topics required to pass the Security+ certification exam.
- ComputerPhileYoutube Channels
Videos explaining computer science topics, cybersecurity, and cryptography.
- CrackmesCyber Security Learning Platforms
A community-driven platform where users can solve reverse engineering challenges (crackmes) to enhance their skills.
Certifications
- Certified Bug Bounty Hunter (CBBH)Red Team Certifications
A certification designed for individuals interested in participating in bug bounty programs and finding vulnerabilities.
- Certified Cybersecurity Analyst (CySA+)Blue Team Certifications
A certification that emphasizes security analytics, threat detection, and incident response.
- Certified Ethical Hacker (CEH)Red Team Certifications
A certification focusing on ethical hacking tools and techniques for assessing and securing systems.
- Certified Information Systems Security Professional (CISSP)Blue Team Certifications
A globally recognized certification validating expertise in information security management and practices.
- Certified Penetration Tester (CPT)Red Team Certifications
A certification designed to validate practical penetration testing skills and methodologies.
- Certified SOC Analyst (CSA)Blue Team Certifications
A certification tailored for SOC roles, focusing on skills required for effective security operations.
Podcasts
- Critical Thinking Bug Bounties Podcast
A podcast focusing on bug bounties, ethical hacking, and vulnerability disclosure, featuring discussions with security experts.
- Darknet Diaries
A storytelling podcast focused on true stories from the dark side of the internet, including hacking and cybercrime.
- David Bombal Podcast
A podcast hosted by David Bombal, covering cybersecurity topics, networking, and tech interviews with industry experts.
- Hacker Valley Media
A podcast exploring various cybersecurity topics, from hacking stories to mental health in the cybersecurity industry.
- Hack The Box Podcast
The official Hack The Box podcast that discusses ethical hacking, cybersecurity challenges, and interviews with security professionals.
- Langley Files
A podcast by the CIA offering a behind-the-scenes look at intelligence, cybersecurity, and national security issues.
Security Frameworks
- CWE (Common Weakness Enumeration)
A community-developed list of common software and hardware weaknesses that can lead to security vulnerabilities, serving as a guide for secure coding practices.
- Fortinet Security Fabric
A comprehensive cybersecurity framework designed by Fortinet, integrating various security solutions to protect network infrastructure from threats.
- ISO/IEC 27032
An international standard providing guidelines for cybersecurity, focusing on the protection of information in cyberspace and addressing network security considerations.
- MITRE ATT&CK
A knowledge base that provides a framework for understanding and defending against cyber adversaries, including tactics and techniques that can affect network security.
- NIST Cybersecurity Framework
A flexible framework that provides guidelines for managing and mitigating cybersecurity risks, including those related to network security.
- OWASP ASVS (Application Security Verification Standard)
A framework for designing, developing, and testing secure web applications, providing a basis for assessing security controls.
Showing a sample of 144 resources. View the full list on GitHub →