Awesome Cyber Security

May 11, 2026 · View on GitHub

Awesome

A collection of awesome software, libraries, documents, books, resources, and cool stuff about security.

Inspired by Awesome Security and Herman Slatman.

Thanks to all contributors. You're awesome. This wouldn't be possible without you! The goal is to build a categorized, community-driven collection of very well-known resources.

List links and description

CERT and alerts

LinkDescription
CERT-EU - Latest News(Latest News) Computer emergency response Tean for the EU (Europe Union) institutions, bodies, and agencies
CERT-US - ALERTS(Alerts) US-CERT United States Computer Emergency Readiness Team
ICS-CERT-US - AlertsAn ICS-CERT Alert is intended to provide timely notification to critical infrastructure owners and operators concerning threats or activity with the potential to impact critical infrastructure computing networks.

Certification

LinkDescription
CEH - Certified Ethical HackerA Certified Ethical Hacker is a skilled professional who understands and knows how to look for weaknesses and vulnerabilities in target systems and uses the same knowledge and tools as a malicious hacker, but in a lawful and legitimate manner to assess the security posture of a target system(s). The CEH credential certifies individuals in the specific network security discipline of Ethical Hacking from a vendor-neutral perspective.
CISSP - CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONALThe Certified Information Systems Security Professional (CISSP) is an information security certification for security analysts.
CompTIA Security +CompTIA Security+ is a global certification that validates the baseline skills you need to perform core security functions and pursue an IT security career.
GPEN - GIAC Penetration TesterThe GPEN certification is for security personnel whose job duties involve assessing target networks and systems to find security vulnerabilities. Certification objectives include penetration-testing methodologies, the legal issues surrounding penetration testing and how to properly conduct a penetration test as well as best practice technical and non-technical techniques specific to conduct a penetration test.
PWK - Penetration Testing Training with Kali LinuxPenetration Testing with Kali (PWK) is a self-paced, online course that introduces students to the latest ethical hacking tools and techniques.
PNPT - Practical Network Penetration TesterPNPT certification is an intermediate-level penetration testing exam experience. Students will have five (5) full days to complete the assessment and an additional two (2) days to write a professional report.
PENT - Professional Penetration TesterPENT is a zero to hero style instructor-led cybersecurity course to equip students to learn professional penetration testing & vulnerability assessment skills by building lab networks to practice network and application enumeration scanning, exploitation, privilege escalation, and lateral movement skills.
OSCP - Offensive Security Certified ProfessionalThe Offensive Security Certified Professional (OSCP) is the companion certification for our Penetration Testing with Kali Linux training course and is the world’s first completely hands-on offensive information security certification. The OSCP challenges the students to prove they have a clear and practical understanding of the penetration testing process and life-cycle through an arduous twenty-four (24) hour certification exam.

Organizations

LinkDescription
CIS Center for Internet SecurityCIS® (Center for Internet Security, Inc.) is a forward-thinking, non-profit entity that harnesses the power of a global IT community to safeguard private and public organizations against cyber threats.
CVE - Common Vulnerabilities and ExposuresCVE® is a list of entries—each containing an identification number, a description, and at least one public reference—for publicly known cybersecurity vulnerabilities.
No more ransomwareNeed Help unlocking your digital life without paying your attackers?
OWASPOpen Web Application Security Project
ZeroDayInitiative(Alerts) Zero Day Initiative
National Vulnerability DatabaseU.S. government repository of standards-based vulnerability management data.
MITRE ATT&CKGlobally accessible knowledge base of adversary tactics and techniques based on real-world observations of cybersecurity threats.
Electronic Frontier FoundationNonprofit organization defending civil liberties in the digital world.

Informatives and blogs

LinkDescription
Mandiant Research BlogsAdvesary and threat Research oriented cybersecurity blogs
Elastic Security Labs BlogsCybersecurity Research oriented blogs
DarkRelay Security Labs BlogsCybersecurity blogs
EffectHackingBlog
ICS SansSans Industrial Control Systems blog
GBHackers on SecuritySecurity blog
Google Security BlogGoogle Security Blog
g0tmi1k BlogHacker blog
Hacker SecurityHacker security News and Blog
HelpNetSecurityHelp Net Security
Security FocusSecurity Focus
SecurityWeekInternet and Enterprise Security News, Insights e Analysis
Security art WorkSecurity art Work
Security AffairsCopyright 2015 Security Affairs by Pierluigi Paganini All Right Reserved.
The Hacker NewsThe Hacker News Security in a Serius Way
Virus GuidesPowered by Knowledge
MalwaretechNews about Malware
WeLiveSecurityNews, Views, and insight from the ESET security community
Virtual Dispersive NetworkingVirtual Dispersive Networking for Cyber Security Blog
Advisory WeekSecurity Advisories published by major vendors this week
InfoStealers by Hudson RockThe all-around Infostealer malware hub with recent news and publications
SecOps Bit By Bit: Roadmap for First-Time CTOs and Startup FoundersThis book is a compilation of best practices for evaluating weak spots in a product and company, and fostering a robust security culture

CTF, Training L3g@l and G@mes

LinkDescription
BetterMotherFucking CTFMotherfuckingCTF inspired platform. But better.
CTF365CTF Practicing
FBCTFFacebook Capture the Flag
Hacker ExperienceGame of Hacker Experience
HackflagBrazilian Hackflag
Hacking-LABHacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents.
HackTheBoxPen-testing Labs
Over The WireThe wargames offered by the OverTheWire community can help you to learn and practice security concepts in the form of fun-filled games.
Open Security TrainingOpenSecurityTraining.info is dedicated to sharing training material for computer security classes, on any topic, that are at least one day long.
Pwnable.kr'pwnable.kr' is a non-commercial wargame site which provides various pwn challenges regarding system exploitation.
Trailofbits GithubCTF Field Guide
ShellterSocial Network focused on information security
CyberPythonPractical cyber security challenges with own research
OSS – OopsSec StoreSelf-hosted CTF platform with intentionally vulnerable e-commerce application. Quick setup with npx create-oss-store.
LinkDescription
Zone-HList of sites attacked by unethical Hackers
WikiLeaksWikiLeaks is a multi-national media organization and associated library.

IT Hacking DB list

LinkDescription
Google Hacking DatabaseGoogle Hacking Database (GHDB)

AT Hacking list

LinkDescription
ShodanOpen ports in A.T
CritifenceDefault Password database of A.T

Courses and Guides Sites

LinkDescription
CybraryFree and Open Source Cyber Security Learning
O Tao do Desenvolvimento Seguro[PT-BR] Safe Development Guide
Guru99Website with guides and a Free Ethical Hacking Course
PortSwigger LabsFree learning resources focused on web and API security only
DarkRelay Security LabsFree & paid cybersecurity trainings with certifications
LabExFree & paid cybersecurity hands-on labs
Offensive CyberSec Cheat SheetA comprehensive and accessible cheat sheet for offensive cybersecurity commands and tools.

OS - Operation Systens

LinkDescription
BackBoxLinuxBackBox Linux is a penetration testing and security assessment-oriented Linux distro.
BlackArchLinuxBlackArch Linux is an Arch Linux-based penetration testing distribution for penetration testers and security researchers. The repository contains 1925 tools. You can install tools individually or in groups. BlackArch Linux is compatible with existing Arch installs.
KaliPenetration Testing Distribution OS
Kali PurpleKali OS but for Defense
ParrotSecParrot Security Operating System is a Penetration Testing & Forensics Distro dedicated to Ethical Hackers & Cyber Security Professionals.
QubesOSQubes OS is a security-oriented operating system (OS). The OS is the software that runs all the other programs on a computer. Some examples of popular OSes are Microsoft Windows, Mac OS X, Android, and iOS. Qubes is free and open-source software (FOSS).
Samurai Web Tester FrameworkWeb Tester OS
PENTOOSPentoo is a security-focused livecd based on Gentoo
VulnhubOS with vulnerabilities for pentests

Tools

LinkDescription
BeelzebubA secure low code honeypot framework, leveraging AI for System Virtualization.
CrackStationUses lookup tables to crack password hashes.
CrowdSecCollaborative IPS/IDS, analyzes visitor behavior & adapts responses.
Find Sec BugsSecurity audits plugin for Java Web Applications.
GhidraNSA reverse engineering tool.
ghidraMCPAutonomous reverse engineering with Ghidra using Model Context Protocol.
Hudson RockInfostealer malware exposure checker.
Metasploit FrameworkPentesting framework used by Kali Linux.
NetcatNetworking utility for TCP/IP protocol.
NMapNetwork discovery and security auditing tool.
OSSECMultiplatform open-source HIDS.
OWASP ZAPOpen-source MITM proxy for security testing.
Pareto SecurityOpen-source systray app for basic security hygiene on Linux/Mac/Wins desktops.
PixeeFinds security & performance issues in code and creates merge-ready pull requests.
PunkSPIDERWeb application vulnerability search engine.
VulertVulert secures software by detecting vulnerabilities in open-source dependencies—without accessing your code. It supports Js, PHP, Java, Python, and more.
renginereNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process
SonarqubeStatic code reviewer.
StellastraEmail authentication and security issues scanner.
TCPDumpNetwork packet analysis tool.
UUSEC WAFIndustry-leading free, high-performance, AI and semantic technology Web Application Firewall.
w3afWeb Application Attack and Audit Framework.
WazuhSecurity monitoring solution for threat detection and compliance.
WiresharkNetwork protocol analyzer.
ZeekNetwork security monitoring tool.
zeek2esConverts Zeek logs to Elastic/OpenSearch.
subdomainradarAll-in-one recon platform: 50+ data sources for subdomain discovery, port & vulnerability scans, screenshots, and API access
leakradarInstant search across 2 B+ plain-text info-stealer credentials; email, domain, metadata queries, monitoring & API
AzureFoxAzure attack-path and privilege-chaining CLI for surfacing high-impact paths, usable pivots, and trust boundaries to break.

Books

LinkDescription
The Security Engineer Handbooka small book on how to make it in a security team, as part of a broader organization