A curated list of awesome browser security learning material.
☆154Nov 20, 2022Updated 3 years ago
Alternatives and similar repositories for awesome-browser-security
Users that are interested in awesome-browser-security are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources for Browser Security Research☆60Sep 17, 2022Updated 3 years ago
- rShellZ s a linux reverse-shell & exploitation assistance framework. With lots of payload and post exploitation modules.☆13Dec 13, 2023Updated 2 years ago
- Security test tool for Blind XSS☆27Mar 5, 2020Updated 6 years ago
- Awesome information for WebSockets security research☆313Jan 10, 2022Updated 4 years ago
- ☆66May 21, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆17Jan 31, 2023Updated 3 years ago
- 2019年天融信阿尔法实验室在微信公众号发布的所有安全资讯汇总☆37Jan 11, 2021Updated 5 years ago
- An updated collection of resources targeting browser-exploitation.☆831Mar 8, 2021Updated 5 years ago
- An extension to use Semgrep inside Burp Suite.☆90May 23, 2025Updated last year
- Top 2025 Vulnerabilities You Shouldn’t Accept in a Pentest Report☆14Feb 6, 2025Updated last year
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆22Jun 14, 2026Updated 2 months ago
- ☆11Dec 26, 2023Updated 2 years ago
- awesome list of browser exploitation tutorials☆2,292Sep 18, 2023Updated 2 years ago
- QUESTER is a Web Pentesting & Bug Bounty Recon tool which queries URLs / Subdomains from the given list of URLs or subdomains.☆15Aug 2, 2021Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A GitHub Actions Supply Chain CTF / Goat☆28Apr 13, 2026Updated 4 months ago
- Electron-Probe leverages the Node variant of the Chrome Debugging Protocol to execute JavaScript payloads inside of target Electron appli…☆29Jan 13, 2026Updated 7 months ago
- React Suspended is an educational frontend application riddled with security vulnerabilities☆10Jun 14, 2026Updated 2 months ago
- Provides an overview of the inner file structure of a PDF☆24Sep 26, 2022Updated 3 years ago
- Semgrep-based Policy Controller for Kubernetes☆47Apr 4, 2025Updated last year
- This repository provides examples of Vulnerable and Mitigated code as per CWE Categorization.☆23May 4, 2024Updated 2 years ago
- A collection of curated resources and CVEs I use for research.☆109Aug 8, 2021Updated 5 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Sep 14, 2021Updated 4 years ago
- ☆12Jul 19, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- oauth security guidelines☆231Jun 25, 2019Updated 7 years ago
- Automate bug bounty recon using bash alias☆15Aug 6, 2024Updated 2 years ago
- POC for CLFS CVE-2022-24481☆14May 14, 2023Updated 3 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Aug 11, 2023Updated 3 years ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,333Jan 26, 2024Updated 2 years ago
- CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224☆37Jan 7, 2023Updated 3 years ago
- ☆61May 19, 2022Updated 4 years ago
- WebGL fuzzer☆39Mar 13, 2023Updated 3 years ago
- ☆19Dec 9, 2022Updated 3 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- A mini bytecode Interpreter for v8.☆23Nov 14, 2022Updated 3 years ago
- A collection of widely-fuzzed targets☆45Aug 4, 2019Updated 7 years ago
- Collection of browser challenges☆139May 3, 2021Updated 5 years ago
- Security issues I've reported in Edge☆47Oct 19, 2022Updated 3 years ago
- ☆32Sep 6, 2021Updated 4 years ago
- 🖇️ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.☆76Aug 22, 2024Updated last year