Hack-with-Github/Awesome-Hacking
GitHub: Hack-with-Github/Awesome-Hacking
面向安全研究者的精选资源导航库,汇总各类黑客与渗透测试学习与实践清单。
Stars: 116669 | Forks: 10545

# [Awesome Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) [](https://twitter.com/intent/tweet?text=Awesome%20Hacking%20-%20a%20collection%20of%20awesome%20lists%20for%20hackers%20and%20pentesters%20by%20@HackwithGithub&url=https://github.com/Hack-with-Github/Awesome-Hacking&hashtags=security,hacking)
**为黑客、渗透测试人员和安全研究人员精心整理的 Awesome 列表合集。**
## Awesome 仓库
仓库 | 描述
---- | ----
[Android 安全](https://github.com/ashishb/android-security-awesome) | Android 安全相关资源合集
[应用安全](https://github.com/paragonie/awesome-appsec) | 学习应用安全的资源
[资产发现](https://github.com/redhuntlabs/Awesome-Asset-Discovery) | 在安全评估项目的资产发现阶段提供帮助的资源列表
[Bug Bounty](https://github.com/djadmin/awesome-bug-bounty) | Bug Bounty 项目列表及来自 Bug Bounty 猎手的文章分享
[蜂窝网络黑客攻击](https://github.com/W00t3k/Awesome-Cellular-Hacking) | 这是一个关于 3G/4G/5G 蜂窝安全领域的黑客研究列表。
[CI/CD 攻击](https://github.com/TupleType/awesome-cicd-attacks) | 针对 CI/CD 系统和部署流程的攻击性研究
[CTF](https://github.com/apsdehal/awesome-ctf) | CTF 框架、库、资源和软件列表
[网络安全大学](https://github.com/brootware/awesome-cyber-security-university) | 专注于通过实践学习网络安全的免费教育资源
[网络技能](https://github.com/joe-shenouda/awesome-cyber-skills) | 精心整理的黑客环境列表,你可以在其中合法、安全地训练你的网络技能
[网络资源](https://github.com/bst04/CyberSources) | 各类网络安全工具和资源的合集
[检测工程](https://github.com/infosecB/awesome-detection-engineering) | 用于设计、构建和运行检测性网络安全控制的资源
[DevSecOps](https://github.com/devsecops/awesome-devsecops) | 在社区实验和贡献的帮助下整理的 awesome DevSecOps 工具列表
[无人机黑客攻击](https://github.com/nicholasaleks/Awesome-Drone-Hacking) | 无人机黑客攻击工具和资源列表
[嵌入式和物联网安全](https://github.com/fkie-cad/awesome-embedded-and-iot-security) | 关于嵌入式和 IoT 安全的精选 awesome 资源列表
[Fuzzing](https://github.com/secfigo/Awesome-Fuzzing) | 用于学习 Fuzzing 以及漏洞开发初始阶段(如根本原因分析)的 Fuzzing 资源列表
[黑客攻击](https://github.com/carpedm20/awesome-hacking) | awesome 的黑客攻击教程、工具和资源列表
[蜜罐](https://github.com/paralax/awesome-honeypots) | 蜜罐资源列表
[应急响应](https://github.com/meirwah/awesome-incident-response) | 应急响应工具列表
[工业控制系统安全](https://github.com/hslatman/awesome-industrial-control-system-security) | 与工业控制系统 (ICS) 安全相关的资源列表
[信息安全](https://github.com/onlurking/awesome-infosec) | awesome 的信息安全课程和培训资源列表
[IoT 和硬件安全](https://github.com/kayranfatih/awesome-iot-and-hardware-security) | 关于 IoT 和硬件安全的工具、书籍、资源和软件合集
[大型机黑客攻击](https://github.com/samanL33T/Awesome-Mainframe-Hacking) | Awesome 大型机黑客攻击/渗透测试资源列表
[恶意软件分析](https://github.com/rshipp/awesome-malware-analysis) | awesome 的恶意软件分析工具和资源列表
[恶意软件持久化](https://github.com/Karneades/awesome-malware-persistence) | 攻击者用于在系统重启后维持访问权限的技术
[Node.js 安全](https://github.com/lirantal/awesome-nodejs-security) | 围绕 Node.js 安全精选的工具、安全事件和其他资源列表
[OSINT](https://github.com/jivoi/awesome-osint) | 惊艳的 awesome 开源情报 (OSINT) 工具和资源列表
[OSX 和 iOS 安全](https://github.com/ashishb/osx-and-ios-security-awesome) | OSX 和 iOS 相关的安全工具
[密码破解](https://github.com/n0kovo/awesome-password-cracking) | 用于恢复密码的工具和资源
[Pcap 工具](https://github.com/caesar0301/awesome-pcaptools) | 由计算机科学领域研究人员开发用于处理网络轨迹的工具合集
[渗透测试](https://github.com/enaqx/awesome-pentest) | awesome 的渗透测试资源、工具及其他闪光点的列表
[PHP 安全](https://github.com/ziadoz/awesome-php#security) | 用于生成安全随机数、加密数据和扫描漏洞的库
[提示词注入](https://github.com/Joe-B-Security/awesome-prompt-injection) | 针对 AI 和 LLM 系统的提示词注入漏洞
[实时通信黑客攻击与渗透测试资源](https://github.com/EnableSecurity/awesome-rtc-hacking) | 涵盖 VoIP、WebRTC 和 VoLTE 安全相关主题
[红队工具包](https://github.com/infosecn1nja/Red-Teaming-Toolkit) | 专为红队和威胁猎人提供的尖端开源安全工具 (OST)
[网络安全强化学习](https://github.com/Kim-Hammar/awesome-rl-for-cybersecurity) | awesome 的安全强化学习资源列表
[逆向工程](https://github.com/HACKE-RC/awesome-reversing) | 从零开始学习逆向工程的资源合集
[安全演讲](https://github.com/PaulSec/awesome-sec-talks) | awesome 的安全演讲列表
[SecLists](https://github.com/danielmiessler/SecLists) | 安全评估期间使用的多种类型列表的合集
[安全](https://github.com/sbilly/awesome-security) | 关于安全的 awesome 软件、库、文档、书籍、资源和酷炫内容合集
[社会工程学](https://github.com/giuliacassara/awesome-social-engineering) | awesome 的社会工程学资源列表
[静态分析](https://github.com/analysis-tools-dev/static-analysis) | 用于各种编程语言的静态分析工具、linter 和代码质量检查器列表
[黑客攻击的艺术系列](https://github.com/The-Art-of-Hacking/h4cker) | 包含数千个网络安全相关参考资料和资源的列表
[威胁情报](https://github.com/hslatman/awesome-threat-intelligence) | awesome 的威胁情报资源列表
[车辆安全](https://github.com/jaredthecoder/awesome-vehicle-security) | 学习车辆安全和汽车黑客攻击的资源列表
[Web 黑客攻击](https://github.com/infoslack/awesome-web-hacking) | Web 应用安全列表
[Web3 安全](https://github.com/Anugrahsr/Awesome-web3-Security) | 为渗透测试人员和 Bug Bounty 猎人精选的 Web3 安全材料和资源。
[YARA](https://github.com/InQuest/awesome-yara) | awesome 的 YARA 规则、工具和人物列表
## 其他实用仓库
仓库 | 描述
---- | ----
[AI 安全](https://github.com/DeepSpaceHarbor/Awesome-AI-Security) | 精选的 AI 安全资源
[年度安全报告](https://github.com/jacobdjwilson/awesome-annual-security-reports) | 来自年度报告的网络安全趋势、洞察和挑战
[API 安全清单](https://github.com/shieldfy/API-Security-Checklist) | 在设计、测试和发布你的 API 时最重要的安全对策清单
[APT 笔记](https://github.com/kbandla/APTnotes) | 关于 APT 活动的各类公开文档、白皮书和文章
[Bug Bounty 参考](https://github.com/ngalongc/bug-bounty-reference) | 根据 Bug 性质分类的 Bug Bounty 文章列表
[Capsulecorp 渗透测试](https://github.com/r3dy/capsulecorp-pentest) | Vagrant + Ansible 虚拟网络渗透测试实验室。Royce Davis 所著《The Art of Network Penetration Testing》的配套资源
[密码学](https://github.com/sobolevn/awesome-cryptography) | 密码学资源和工具
[CVE PoC](https://github.com/trickest/cve) | 由 Trickest 每日更新的 CVE 概念验证 列表
[CyberChef](https://gchq.github.io/CyberChef/) | 一个简单、直观的 Web 应用,用于分析和解码数据,无需处理复杂的工具或编程语言。
[检测实验室](https://github.com/clong/DetectionLab) | 用于构建配备安全工具和日志记录最佳实践的实验室环境的 Vagrant 和 Packer 脚本
[可执行文件加壳](https://github.com/packing-box/awesome-executable-packing) | 关于可执行文件加壳和脱壳的资源
[取证](https://github.com/Cugu/awesome-forensics) | awesome 的取证分析工具和资源列表
[免费编程书籍](https://github.com/EbookFoundation/free-programming-books) | 为开发者提供的免费编程书籍
[GTFOBins](https://gtfobins.github.io) | 精选的 Unix 二进制文件列表,攻击者可以利用它们绕过本地安全限制
[Hacker101](https://github.com/Hacker0x01/hacker101) | 由 HackerOne 提供的免费 Web 安全课程
[信息安全入门](https://github.com/gradiuscypher/infosec_getting_started) | 帮助人们学习信息安全的资源、文档、链接等合集
[信息安全参考](https://github.com/rmusser01/Infosec_Reference) | 不那么枯燥的信息安全参考
[IOC](https://github.com/sroberts/awesome-iocs) | 妥协指标 的来源合集
[Linux 内核漏洞利用](https://github.com/xairy/linux-kernel-exploitation) | 大量与 Linux 内核 Fuzzing 和漏洞利用相关的链接
[用于网络安全的机器学习](https://github.com/jivoi/awesome-ml-for-cybersecurity) | 与在网络安全中使用机器学习相关的精选工具和资源
[攻击载荷](https://github.com/foospidy/payloads) | Web 攻击载荷合集
[PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) | 用于 Web 应用安全和渗透测试/CTF 的实用攻击载荷和绕过方法列表
[渗透测试 Wiki](https://github.com/nixawk/pentest-wiki) | 为渗透测试人员/研究人员提供的免费在线安全知识库
[概率词表](https://github.com/berzerk0/Probable-Wordlists) | 最初为密码生成和测试而创建的按概率排序的词表
[红队物理工具](https://github.com/DavidProbinsky/RedTeam-Physical-Tools) | 精选的用于物理安全、红队演练和战术隐蔽入侵的工具列表
[逆向工程](https://github.com/onethawt/reverseengineering-reading-list) | 逆向工程文章、书籍和论文列表
[RFSec-ToolKit](https://github.com/cn0xroot/RFSec-ToolKit) | 射频通信协议黑客工具合集
[安全备忘单](https://github.com/OWASP/CheatSheetSeries) | 用于应用安全的 OWASP 备忘单系列
[Shell](https://github.com/alebcay/awesome-shell) | awesome 的命令行框架、工具包、指南和小工具列表,以充分利用 shell
[Suricata](https://github.com/satta/awesome-suricata) | Suricata IDS/IPS 和网络安全监控资源
[ThreatHunter-Playbook](https://github.com/OTRF/ThreatHunter-Playbook) | 一本威胁猎人的 Playbook,旨在帮助开发用于狩猎活动的技术和假设
[Tor](https://github.com/polycarbohydrate/awesome-tor) | 关于 Tor 网络和匿名通信的资源
[Vulhub](https://github.com/vulhub/vulhub) | 基于 Docker-Compose 预先构建的易受攻击环境
[Web 安全](https://github.com/qazbnm456/awesome-web-security) | 精选的 Web 安全材料和资源
## 需要更多?
在您最喜欢的社交媒体上关注 **Hack with GitHub**,以获取与安全相关的有趣 GitHub 仓库的每日更新。
- Twitter : [@HackwithGithub](https://twitter.com/HackwithGithub)
- Facebook : [HackwithGithub](https://www.facebook.com/HackwithGithub)
## 贡献
请查阅 [contributing.md](contributing.md)
标签:CTF, 安全研究, 数据展示, 渗透测试, 红队, 资源合集, 黑客