Skip to main content

A bunch of resources containing learning resources, certifications, security frameworks, bug bounties, podcasts and tools used for cyber security.

16
GitHub Stars
144
Curated Resources
7
Categories
39 min ago
Last Refreshed
Learning ResourcesCertificationsSecurity FrameworksBug BountiesPodcastsToolsMisc

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me web application pentesting resources from awesome-cyber-security"

Installation instructions →

What's inside

Tools

  • AcuneticsWeb Application Pentesting

    An automated web application security scanner that checks for vulnerabilities like SQL injection, XSS, and more.

  • Aircrack-ngNetwork Pentesting

    A suite of tools for assessing Wi-Fi network security, including capturing packets and cracking WEP/WPA/WPA2 keys.

  • Any RunNetwork Security

    An interactive online malware analysis service that allows users to run and analyze malicious files in real time.

  • BeEFWeb Application Pentesting

    a powerful tool that can perform various tasks aimed at exploiting vulnerabilities in web browsers.

  • Burpsuite (Intruder)Web Application Pentesting

    Besides scanning, Burp's Intruder tool can be used for brute-forcing and payload injection.

  • CCleanerNetwork Pentesting

    A tool used to remove unnecessary files and clear logs to cover tracks after an attack.

Bug Bounties

  • app.cyberarmy.id

    An Indonesian bug bounty platform connecting security researchers with companies to help them identify and resolve vulnerabilities.

  • Bugcrowd

    A crowdsourced cybersecurity platform offering bug bounty programs to help organizations identify and fix vulnerabilities.

  • Hackerone

    A leading bug bounty platform that connects businesses with ethical hackers to find and report security vulnerabilities.

  • Patchstack

    A bug bounty platform focused on securing WordPress plugins and themes through vulnerability disclosure and patching.

  • Redstorm.io

    A bug bounty platform that allows hackers to report vulnerabilities in exchange for rewards, focusing on improving cybersecurity for businesses.

  • Yeswehack

    A global bug bounty platform providing opportunities for ethical hackers to find vulnerabilities in various organizations' systems.

Misc

  • awesome-cyber-skillsMore Awesome Repos (actively maintained)

    A curated list of hacking environments where you can train your cyber skills.

  • awesome-osintMore Awesome Repos (actively maintained)

    A curated list of amazingly awesome Open-Source Intelligence.

  • awesome-threat-intelligenceMore Awesome Repos (actively maintained)

    A curated list of Awesome Threat Intelligence resources.

  • the-book-of-secret-knowledgeMore Awesome Repos (actively maintained)

    A huge collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

Learning Resources

Certifications

Podcasts

  • Critical Thinking Bug Bounties Podcast

    A podcast focusing on bug bounties, ethical hacking, and vulnerability disclosure, featuring discussions with security experts.

  • Darknet Diaries

    A storytelling podcast focused on true stories from the dark side of the internet, including hacking and cybercrime.

  • David Bombal Podcast

    A podcast hosted by David Bombal, covering cybersecurity topics, networking, and tech interviews with industry experts.

  • Hacker Valley Media

    A podcast exploring various cybersecurity topics, from hacking stories to mental health in the cybersecurity industry.

  • Hack The Box Podcast

    The official Hack The Box podcast that discusses ethical hacking, cybersecurity challenges, and interviews with security professionals.

  • Langley Files

    A podcast by the CIA offering a behind-the-scenes look at intelligence, cybersecurity, and national security issues.

Security Frameworks

  • CWE (Common Weakness Enumeration)

    A community-developed list of common software and hardware weaknesses that can lead to security vulnerabilities, serving as a guide for secure coding practices.

  • Fortinet Security Fabric

    A comprehensive cybersecurity framework designed by Fortinet, integrating various security solutions to protect network infrastructure from threats.

  • ISO/IEC 27032

    An international standard providing guidelines for cybersecurity, focusing on the protection of information in cyberspace and addressing network security considerations.

  • MITRE ATT&CK

    A knowledge base that provides a framework for understanding and defending against cyber adversaries, including tactics and techniques that can affect network security.

  • NIST Cybersecurity Framework

    A flexible framework that provides guidelines for managing and mitigating cybersecurity risks, including those related to network security.

  • OWASP ASVS (Application Security Verification Standard)

    A framework for designing, developing, and testing secure web applications, providing a basis for assessing security controls.

Showing a sample of 144 resources. View the full list on GitHub →