CISA's catalog of bad practices that are exceptionally risky.
☆209Apr 27, 2026Updated last month
Alternatives and similar repositories for bad-practices
Users that are interested in bad-practices are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Cybersecurity Evaluation Tool☆1,833Updated this week
- We borrow the concept of 'personas' from UX/service design and apply it to threat actors to improve understanding between security, techn…☆11Jun 17, 2020Updated 5 years ago
- A set of guidelines and best practices for an awesome engineering team☆277May 11, 2026Updated 3 weeks ago
- A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development☆12May 29, 2017Updated 9 years ago
- A collection of awesome penetration testing resources, tools and other shiny things☆17Feb 11, 2017Updated 9 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- CISA CSAF Security Advisories☆108Updated this week
- A site for CISA directives☆173Jun 5, 2024Updated 2 years ago
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆22Nov 7, 2024Updated last year
- USENIX 2023 Artifacts☆12Nov 25, 2022Updated 3 years ago
- Integrate IBM QRadar and RPA to automate security L1 tasks.☆14May 20, 2022Updated 4 years ago
- Virtual machines that are set up with a variety of known vulnerabilities.☆17Mar 1, 2022Updated 4 years ago
- AWS Quick Start Team☆17Oct 3, 2024Updated last year
- Automation to assess the state of your M365 tenant against CISA's baselines☆2,587Updated this week
- 🚗 A curated list of resources for learning about vehicle security and car hacking☆15Oct 4, 2021Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- DevSecOps Guide, located devsecops.pagerduty.com☆14Apr 1, 2026Updated 2 months ago
- ☆16Dec 16, 2020Updated 5 years ago
- Vulnerability Assessment Module - OpenVas with Elastic stack using VulnWhisperer☆20Jun 11, 2019Updated 7 years ago
- Repository for AsBuiltReport Microsoft DHCP module☆15Jan 31, 2026Updated 4 months ago
- A skeleton project for quickly getting a new cisagov Python library started.☆32May 11, 2026Updated 3 weeks ago
- Use Terraform to Provision Your Own Cloud-Based Remote Browsing Workstation☆26Apr 28, 2024Updated 2 years ago
- This project can be used to create AMIs based on Kali Linux, a penetration testing distribution.☆21Jun 3, 2026Updated last week
- ☆16May 13, 2021Updated 5 years ago
- A curated list of tools for incident response☆21Sep 24, 2019Updated 6 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Purple Team Strategies, Published by Packt☆16Apr 22, 2026Updated last month
- Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 en…☆1,430Dec 27, 2022Updated 3 years ago
- Sightings Ecosystem gives cyber defenders visibility into what adversaries actually do in the wild. With your help, we are tracking MITRE…☆38May 28, 2025Updated last year
- CyHy Dashboard☆27Jun 3, 2026Updated last week
- This repository contains generated contextual data utilized by pyattck.☆19Mar 3, 2025Updated last year
- A curated list of CTF frameworks, libraries, resources and softwares☆10Nov 11, 2015Updated 10 years ago
- CISA is hiring! We’re looking for candidates passionate about our mission to lead the national effort to understand and manage cyber and …☆75Nov 20, 2024Updated last year
- ☆19Dec 31, 2022Updated 3 years ago
- Documentation on the Cyber Defense Matrix☆27Apr 19, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- These are open source rules that can be utilized with QRadar to detect various types of threats in the environment.☆60Jun 11, 2019Updated 6 years ago
- A PowerShell module for incident response and threat hunting.☆38May 23, 2024Updated 2 years ago
- Zoho ManageEngine Desktop Central CVEs☆15Oct 5, 2020Updated 5 years ago
- Create machine images containing the Nessus vulnerability scanner☆13Updated this week
- Machine Learning Security Principles, published by Packt☆23Apr 22, 2026Updated last month
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆14May 28, 2026Updated last week
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆54Apr 25, 2023Updated 3 years ago