A curated list of awesome browser security learning material.
☆155Nov 20, 2022Updated 3 years ago
Alternatives and similar repositories for awesome-browser-security
Users that are interested in awesome-browser-security are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources for Browser Security Research☆61Sep 17, 2022Updated 3 years ago
- rShellZ s a linux reverse-shell & exploitation assistance framework. With lots of payload and post exploitation modules.☆13Dec 13, 2023Updated 2 years ago
- Security test tool for Blind XSS☆28Mar 5, 2020Updated 6 years ago
- Awesome information for WebSockets security research☆314Jan 10, 2022Updated 4 years ago
- ☆66May 21, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆17Jan 31, 2023Updated 3 years ago
- Simple Kernel Extension to read and write Kernel Memory☆15Aug 18, 2022Updated 4 years ago
- An updated collection of resources targeting browser-exploitation.☆830Mar 8, 2021Updated 5 years ago
- An extension to use Semgrep inside Burp Suite.☆90May 23, 2025Updated last year
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆22Jun 14, 2026Updated 2 months ago
- ☆11Dec 26, 2023Updated 2 years ago
- QUESTER is a Web Pentesting & Bug Bounty Recon tool which queries URLs / Subdomains from the given list of URLs or subdomains.☆15Aug 2, 2021Updated 5 years ago
- awesome list of browser exploitation tutorials☆2,296Sep 18, 2023Updated 2 years ago
- Electron-Probe leverages the Node variant of the Chrome Debugging Protocol to execute JavaScript payloads inside of target Electron appli…☆29Jan 13, 2026Updated 7 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- React Suspended is an educational frontend application riddled with security vulnerabilities☆10Jun 14, 2026Updated 2 months ago
- Provides an overview of the inner file structure of a PDF☆24Sep 26, 2022Updated 3 years ago
- Semgrep-based Policy Controller for Kubernetes☆47Apr 4, 2025Updated last year
- ☆45Nov 18, 2022Updated 3 years ago
- This repository provides examples of Vulnerable and Mitigated code as per CWE Categorization.☆23May 4, 2024Updated 2 years ago
- A collection of curated resources and CVEs I use for research.☆110Aug 8, 2021Updated 5 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Sep 14, 2021Updated 4 years ago
- ☆12Jul 19, 2026Updated last month
- oauth security guidelines☆231Jun 25, 2019Updated 7 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- POC for CLFS CVE-2022-24481☆14May 14, 2023Updated 3 years ago
- ☆35Apr 14, 2025Updated last year
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Aug 11, 2023Updated 3 years ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,337Jan 26, 2024Updated 2 years ago
- CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224☆37Jan 7, 2023Updated 3 years ago
- ☆61May 19, 2022Updated 4 years ago
- Exploit for the [pwn] just-in-time challenge from google ctf 2018's finals (TurboFan bug)☆60Jan 26, 2019Updated 7 years ago
- WebGL fuzzer☆39Mar 13, 2023Updated 3 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A mini bytecode Interpreter for v8.☆23Nov 14, 2022Updated 3 years ago
- A collection of widely-fuzzed targets☆45Aug 4, 2019Updated 7 years ago
- Collection of browser challenges☆139May 3, 2021Updated 5 years ago
- Security issues I've reported in Edge☆46Oct 19, 2022Updated 3 years ago
- Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)☆13Oct 21, 2024Updated last year
- Proof of Concept code for CVE-2020-0728☆46Feb 12, 2020Updated 6 years ago
- 🖇️ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.☆76Aug 22, 2024Updated 2 years ago