A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Jan 3, 2026 - Python
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Low code web framework for real world applications, in Python and Javascript
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
The Rogue Access Point Framework
Main Sigma Rule Repository
Web path scanner
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
Exploitation Framework for Embedded Devices
Set up a personal VPN in the cloud
Scapy: the Python-based interactive packet manipulation program & library.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Daemon to ban hosts that cause multiple authentication errors
The authentication glue you need.
People tracker on the Internet: OSINT analysis and research tool by Jose Pino
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
w3af: web application attack and audit framework, the open source web vulnerability scanner.
Backup repositories, metadata and LFS into AWS, Azure, OneDrive, GCP. SOC2 Type II compliant. Pay per repositories, not seats
Code scanning at ludicrous speed. Find bugs and reachable dependency vulnerabilities. Enforce standards on every commit
Developer-first security platform that protects your code from both vulnerable and malicious dependencies
We help developers write clean code
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
Find, fix (and prevent!) known vulnerabilities in your code
GuardRails provides continuous security feedback for modern development teams
Dependency Automation service by Mend.io
World's most tech-savvy GitHub backup, recovery, restore, migration & config management trusted by Fortune 500
Runtime Code Review
Automated GitHub backups so you can recover fast, stay compliant, and never lose a line of code