Minimalist cheat sheet for developpers to write secure code
☆54Jul 17, 2020Updated 6 years ago
Alternatives and similar repositories for security-cheat-sheet
Users that are interested in security-cheat-sheet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Accompanying material needed for the workshop☆11Jun 14, 2023Updated 3 years ago
- Material from presentations done by GoSecure researchers☆34Oct 10, 2023Updated 2 years ago
- It contain google dork to find the wsdl file.☆13May 27, 2020Updated 6 years ago
- ☆20Jan 12, 2022Updated 4 years ago
- Workshop given at Hack in Paris 2019☆126Jun 8, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Identify vulnerable libraries in Maven dependencies☆45Dec 14, 2022Updated 3 years ago
- source code audit tool☆48May 9, 2021Updated 5 years ago
- Vulnerable Node.js Web Application to pratice with your pentesting skills☆21Apr 29, 2017Updated 9 years ago
- ☆18Oct 30, 2022Updated 3 years ago
- FxCop rules that aim to help security audit on .NET applications.☆14Nov 10, 2017Updated 8 years ago
- Carve Windows Prefetch files from arbitrary binary data☆16Jun 11, 2017Updated 9 years ago
- psychoPATH - hunting file uploads & LFI in the dark. This tool is a customisable payload generator designed for blindly detecting LFI & w…☆19Jun 28, 2018Updated 8 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Mar 27, 2017Updated 9 years ago
- splunk_pentest_app☆49Apr 22, 2016Updated 10 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Collection of my slide decks, conference videos and research white papers☆27Sep 23, 2025Updated 10 months ago
- 一个爬取国内技术站点的技术文章☆32Dec 24, 2017Updated 8 years ago
- A Collection of Proof of Concepts for non-published Web Exploits and Common CVEs☆10Nov 29, 2020Updated 5 years ago
- V1.0☆14Aug 8, 2016Updated 10 years ago
- ☆90Sep 7, 2018Updated 7 years ago
- VM escape (QEMU, VirtualBox, VMware)☆16Mar 21, 2022Updated 4 years ago
- ☆13Mar 31, 2021Updated 5 years ago
- Discord bot to display events and information about a CTFd instance (https://ctfd.io/)☆11Jul 9, 2024Updated 2 years ago
- A collection of XSS Attack vectors☆10Jul 31, 2026Updated last week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- PrOfESSOS is our open source implementation for fully automated Evaluation-as-a-Service for SSO. PrOfESSOS introduces a generic approach …☆29Jan 8, 2023Updated 3 years ago
- Automated Reverse TCP tunneling using a digitalocean instance and aploium's shootback repo (https://github.com/aploium/shootback)☆13Oct 30, 2018Updated 7 years ago
- Contains all my research and content produced regarding the log4shell vulnerability☆31Jan 22, 2022Updated 4 years ago
- A CLI that utilizes Okta IdP via SAML to acquire temporary AWS credentials☆10Jun 30, 2021Updated 5 years ago
- Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website☆141Apr 29, 2020Updated 6 years ago
- Web interface and APIs for Assemblyline 4☆21Updated this week
- P2P Encrypted File Sharing In Your Browser via WebRTC☆37Dec 31, 2017Updated 8 years ago
- Easily create index of your SANS books☆18Oct 28, 2022Updated 3 years ago
- Docker Pentest Lists are collection of Dockerfiles or Links to Dockerfiles for containers used in Penetration Tests☆21May 1, 2017Updated 9 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆23May 21, 2019Updated 7 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆34May 19, 2019Updated 7 years ago
- Burp extension to decode NTLM SSP headers and extract domain/host information☆31Mar 11, 2021Updated 5 years ago
- Automated Security Assessment Reporting Tool☆37Dec 23, 2017Updated 8 years ago
- Fuzzing for LFI using Burpsuite☆69Oct 4, 2016Updated 9 years ago
- 自己ctf比赛的writeup☆20May 27, 2019Updated 7 years ago
- An AWS Lambda vulnerable application written in flask.☆51Oct 9, 2017Updated 8 years ago