Security list for fun and profit

My initial idea came from this list : http://www.nothink.org/utilities.php

I wanted to update it with my sources, I will probably continue to update and reorganize it in the future.

Table of Contents


Awesome lists 👍

Name URL
Androidhttps://github.com/ashishb/android-security-awesome
Collection of awesome listshttps://github.com/Hack-with-Github/Awesome-Hacking 🏆
Honeypotshttps://github.com/paralax/awesome-honeypots 🏆
Incident responsehttps://github.com/meirwah/awesome-incident-response/ 🏆
Indicators of compromisehttps://github.com/sroberts/awesome-iocs
Lists of lists of listshttps://github.com/t3chnoboy/awesome-awesome-awesome
Malware analysishttps://github.com/rshipp/awesome-malware-analysis/ 🏆
Reversinghttps://github.com/fdivrp/awesome-reversing
Security listhttps://github.com/sbilly/awesome-security
Threat intelligencehttps://github.com/hslatman/awesome-threat-intelligence
Webhttps://github.com/infoslack/awesome-web-hacking

Books 📚

Name URL
Free programming bookshttps://github.com/vhf/free-programming-books
Recommended Readinghttp://dfir.org/?q=node/8

Bug bounty 🍫

Name URL
Programs and write-upshttps://github.com/djadmin/awesome-bug-bounty
Write-upshttps://github.com/ngalongc/bug-bounty-reference
HackerOnehttps://hackerone.com 👍
BugCrowd.comhttps://bugcrowd.com/programs
Zerodiumhttps://www.zerodium.com/
Vul boxhttps://www.vulbox.com/
Open bug bountyhttps://www.openbugbounty.org/
BountyFactoryhttps://bountyfactory.io
Firebountyhttps://firebounty.com
Bugsheethttp://www.bugsheet.com/
BountySourcehttps://www.bountysource.com/
NewsLetter about bug bountyhttp://bugbountyweekly.com
Hunter eduhttp://www.bountyhunteredu.org/careers/
Googlehttps://www.google.com/about/appsecurity/reward-program/
Microsofthttps://technet.microsoft.com/en-us/security/dn425036
More bug bountyhttps://bugcrowd.com/list-of-bug-bounty-programs#

Cheat sheets 👍

Name URL
General cheat sheetshttp://www.cheat-sheets.org/
LFIhttps://highon.coffee/blog/lfi-cheat-sheet/
Owasp serieshttps://www.owasp.org/index.php/OWASP_Cheat_Sheet_Series 👍
Packet lifehttp://packetlife.net/library/cheat-sheets/
Penetration testhttps://github.com/jshaw87/Cheatsheets
Penetration testhttps://highon.coffee/blog/penetration-testing-tools-cheat-sheet/
Pentest monkeyhttp://pentestmonkey.net
SANS Forensichttps://digital-forensics.sans.org/community/cheat-sheets
Security Onionhttps://github.com/Security-Onion-Solutions/security-onion/wiki/Cheat-Sheet
SQL injectionhttp://websec.ca/kb/sql_injection
Reversehttp://r00ted.com/cheat%20sheet%20reverse%20v5.png
Web applicationhttps://www.owasp.org/index.php/Web_Application_Security_Testing_Cheat_Sheet
Zeltser's cheat sheets listhttps://zeltser.com/cheat-sheets/

CTF 🚩

Name URL
CTFTIMEhttps://ctftime.org/
Write-upshttps://github.com/ctfs
Reddithttps://www.reddit.com/r/securityctf
Tools listhttps://github.com/Laxa/HackingTools
Tools listhttps://github.com/zardus/ctf-tools
Tools listhttps://github.com/apsdehal/awesome-ctf
Mellivora platformhttps://github.com/Nakiami/mellivora 👍
Tinyctf platformhttps://github.com/balidani/tinyctf-platform
Isislab platformhttps://github.com/isislab/CTFd
Facebook platformhttps://github.com/facebook/fbctf

Decoder/Packer/Unpacker :hurtrealbad:

Name URL
Code beautifierhttp://codebeautify.org/
VB code beautifierhttp://www.vbindent.com/
PHP formatterhttp://beta.phpformatter.com/
PHPdecoderhttp://ddecode.com/phpdecoder/
PHP encodinghttp://yehg.net/encoding/
XML formatterhttp://chris.photobooks.com/xml/default.htm
JSDetoxhttp://www.relentless-coding.com/projects/jsdetox/
JSNicehttp://www.jsnice.org/
JSUnpackhttps://github.com/urule99/jsunpack-n
JSBeautifierhttp://jsbeautifier.org/
JavaScript Compressorhttp://dean.edwards.name/packer/
Jjencodehttp://utf-8.jp/public/jjencode.html
JSFuckhttp://www.jsfuck.com/
Js obfuscatehttp://www.jsobfuscate.com/
JS deobfuscatehttps://github.com/sevzero/honeybadger
Colour higlighterhttp://quickhighlighter.com/
URLhttp://meyerweb.com/eric/tools/dencoder/
HEXdecoderhttp://ddecode.com/hexdecoder/
Hackvertor (Tag based decoder/encoder)https://hackvertor.co.uk/public

Domain name Research / Analysis / Reputation 📉

Name URL
Archivehttp://archive.is/
Archivehttps://web.archive.org/ 👍
Archive a pagehttps://archive.fo/
BGP Toolkithttp://bgp.he.net/ 👍👍
Biggest DNS historyhttp://server9.rscott.org/tools/lookup.htm?ip=xxx.xxx.xxx.xxx 🏆
Cache pagehttp://www.cachedpages.com/
Cache viewhttp://cachedview.com/
Checking multiple blocklistshttp://rbls.org/ 👍
DGA introhttps://en.wikipedia.org/wiki/Domain_generation_algorithm
DNS Blacklistshttps://raw.githubusercontent.com/zbetcheckin/DNSBLs/master/active_dnsbls.txt
DNS dumpsterhttps://dnsdumpster.com/
DNS Propagation Checkerhttps://www.whatsmydns.net/
DNS stuffhttp://www.dnsstuff.com/
Domain analysis listhttps://github.com/rshipp/awesome-malware-analysis/#domain-analysis
Domain hijacking introhttps://en.wikipedia.org/wiki/Domain_hijacking
Expired domainhttps://www.expireddomains.net/backorder-expired-domains/
Googlehttps://www.google.com/transparencyreport/safebrowsing/diagnostic/
Into dnshttp://www.intodns.com/
Multi RBLhttp://multirbl.valli.org/lookup/ 🏆
MXToolBoxhttps://mxtoolbox.com/SuperTool.aspx#
Netcrafthttp://www.netcraft.com/
Reverse Whoishttps://reversewhois.domaintools.com/
Robtexhttps://www.robtex.com/dns/
Sucurihttp://sitecheck.sucuri.net/scanner/
TCP utilshttp://www.tcpiputils.com/
Threat loghttp://www.threatlog.com/
Threat minerhttps://www.threatminer.org/
Top-Level Domains listhttps://data.iana.org/TLD/tlds-alpha-by-domain.txt 👍
Trusted sourcehttp://www.trustedsource.org/
URL Queryhttp://urlquery.net/ 🏆
URL scanhttps://urlscan.io/
URL shorter listhttps://mirror1.malwaredomains.com/files/url_shorteners.txt
URL Voidhttp://www.urlvoid.com/ 👍
Virus totalhttps://www.virustotal.com/#url
Whois - ARINhttps://whois.arin.net/
Whois - LACNIChttp://lacnic.net/cgi-bin/lacnic/whois
Whois - RIPE NCChttps://apps.db.ripe.net/search/query.html
Whois - AFRINIChttp://www.afrinic.net/fr/services/whois-query
Whois - APNIChttp://wq.apnic.net/apnic-bin/whois.pl
Whois by registrant namehttp://viewdns.info/reversewhois/
Zeltser's listhttps://zeltser.com/lookup-malicious-websites/

Exploits and vulnerabilities 🚪

Name URL
CVEdetailshttp://www.cvedetails.com/ 👍
CVE.mitrehttps://cve.mitre.org/
Full disclosurehttp://seclists.org/fulldisclosure/
See bughttps://www.seebug.org/ 👍
CXSecurityhttps://cxsecurity.com/ 👍
Inj3ct0rhttp://0day.today/
Packet Stormhttps://packetstormsecurity.com/files/tags/exploit/
Exploit-dbhttp://www.exploit-db.com
Vulnerability-labhttp://www.vulnerability-lab.com/
Vulndbhttps://vuldb.com/?archive.2016
Vulnershttps://vulners.com/search?query=order:published
Backdoor - TCP-32764https://github.com/elvanderb/TCP-32764
Rapid7 DBhttps://www.rapid7.com/db/modules/
Intelligent Exploithttp://www.intelligentexploit.com
NISThttp://web.nvd.nist.gov/
Security focushttp://www.securityfocus.com/vulnerabilities
Country compatibilityhttps://cve.mitre.org/compatible/country.html
Mailing listhttps://nmap.org/mailman/listinfo/fulldisclosure
Mail receivedhttp://lists.openwall.net/full-disclosure/2016/
Mailing listhttp://seclists.org/
Mailing listhttps://lists.debian.org/debian-security-announce/
CVSS FIRSThttps://www.first.org/cvss/calculator/3.0
CVSS NISThttps://nvd.nist.gov/cvss/v3-calculator

Forensic 🔍

Name URL
Aldeid listhttps://www.aldeid.com/wiki/Category:Digital-Forensics
Awesome forensichttps://github.com/Cugu/awesome-forensics
CFReDShttp://www.cfreds.nist.gov/ 👍
DFRWS challengehttp://www.dfrws.org/dfrws-forensic-challenge-2016
File signatureshttps://en.wikipedia.org/wiki/List_of_file_signatures
File signatureshttp://www.filesignatures.net/index.php?page=all
File signatureshttp://www.garykessler.net/library/file_sigs.html
Forensic controlhttps://forensiccontrol.com/resources/free-software/
Forensic kb practicalhttp://www.forensickb.com/2008/01/forensic-practical.html
Forensic toolshttps://forensics.cert.org/
Forensic - Technical graphhttp://www.amanhardikar.com/mindmaps/ForensicChallenges.html
Package - DEFThttp://www.deftlinux.net/package-list/
Package - forensic-allhttps://packages.debian.org/jessie-backports/forensics-all 👍
Testing Imageshttp://dftt.sourceforge.net/
Tools - DFIRhttp://www.dfir.training/index.php/tools/ 👍
Tools - Forensics wikihttp://forensicswiki.org/wiki/Tools
Tools - NISThttp://toolcatalog.nist.gov/populated_taxonomy/index.php
Windows toolshttps://ericzimmerman.github.io/
Windows tools listhttp://forensic-proof.com/tools
Windows Artifacthttps://blogs.sans.org/computer-forensics/
Write blockerhttp://www.cftt.nist.gov/software_write_block.htm
Write blockerhttps://github.com/msuhanov/Linux-write-blocker
Zythom list - FRhttps://zythom.blogspot.se/2007/02/les-outils-dun-expert-judiciaire.html

Free shell 🐚

Name URL
FreeShells listhttp://www.freeshells.info/
Devio.us OpenBSDhttp://devio.us/
Red-pillhttp://shells.red-pill.eu/

Fun :trollface:

Name URL
Pwnie Awardshttp://pwnies.com/nominations/ 🐴
Dead dropshttps://deaddrops.com/db/
Mozilla location service maphttps://location.services.mozilla.com/map - Thx rawger
The cyber shark maphttps://lab.thecybershark.com/ 🌎
Norse maphttp://map.norsecorp.com/ 🌎
Fire eye maphttps://www.fireeye.com/cyber-map/threat-map.html 🌎
Kaspersky AV maphttps://cybermap.kaspersky.com/ 🌎
Kaspersky maphttps://apt.securelist.com/ 🌎
Eset maphttp://www.virusradar.com/ 🌎
Fortinet maphttps://threatmap.fortiguard.com/ 🌎
Blueliv maphttps://community.blueliv.com/map/ 🌎
Tor flow maphttps://torflow.uncharted.software 🌎
Cymon maphttps://cymon.io/map 🌎
HE mapshttps://he.net/3d-map/ 🌎
DDoS attackshttp://www.digitalattackmap.com/
Sub marine cablehttp://www.submarinecablemap.com/
Sub marine cablehttp://submarine-cable-map-2016.telegeography.com/
Sub marine cablehttp://lifewinning.com/submarine-cable-taps/
Flight radarhttps://www.flightradar24.com ✈️
Fligh awarehttps://flightaware.com/ ✈️
Live maphttps://www.livemap24.com/ 🚋
World of VNChttps://worldofvnc.net/

Generic utilities 📁

Will be reorganized

Name URL
CERT teamshttps://www.first.org/about/organization/teams
Citizen labhttps://citizenlab.org/
Code analysiseshttps://en.wikipedia.org/wiki/List_of_tools_for_static_code_analysis
Codepadhttp://codepad.org/
Cracking forumhttp://crackingforum.com/
Cracking sealhttps://crackingseal.io/
Crypto currencyhttps://coinmarketcap.com
Darknet statshttps://dnstats.net/
Deepwebhttps://www.reddit.com/r/deepweb/
Electronic Frontier Foundationhttps://www.eff.org/
Fake IDhttp://www.fakenamegenerator.com/
GZinflatehttp://www.tareeinternet.com/scripts/decrypt.php
Hackforumhttp://hackforums.net/
Hashes examplehttps://hashcat.net/wiki/doku.php?id=example_hashes
Hurlhttp://www.hurl.it/
Mibbithttp://www.mibbit.com/
Microsoft threathttp://www.microsoft.com/security
MIME typeshttps://www.iana.org/assignments/media-types/media-types.xhtml
MIME typeshttps://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Complete_list_of_MIME_types
Mindmapshttp://www.amanhardikar.com/mindmaps.html 🏆
Random data generatorhttp://www.mockaroo.com/
Sandspritehttp://sandsprite.com/shellcode_2_exe.php
Sanshttp://isc.sans.edu/diary/
Security wikihttp://oss-security.openwall.org/wiki/
Skimmershttps://krebsonsecurity.com/all-about-skimmers/
Toolshttp://seclist.us/
Understand your commandshttp://explainshell.com

GNU/Linux

Name URL
Chkrootkithttps://packages.debian.org/en/jessie/chkrootkit
Command collectionhttps://github.com/tuwid/GNU-Linux-OpsWiki
Debsecanhttps://packages.debian.org/en/jessie/debsecan
GNU/Linux containershttps://github.com/Friz-zy/awesome-linux-containers#security
GNU/Linux executable walkthroughhttps://i.imgur.com/q5nyHp7.png
GNU/Linux post exploitationhttps://github.com/mubix/post-exploitation/wiki/Linux-Post-Exploitation-Command-List 👍
GNU/Linux workstationhttps://github.com/lfit/itpol/blob/master/linux-workstation-security.md 👍👍
Kernel exploitationhttps://github.com/xairy/linux-kernel-exploitation
Lynishttps://packages.debian.org/en/jessie/lynis
RKhunterhttps://packages.debian.org/en/jessie/rkhunter 👍
Securing debianhttps://www.debian.org/doc/manuals/securing-debian-howto/ch10.en.html 👍
Vulnerability scannerhttps://github.com/future-architect/vuls

Honeypots 🍯

Name URL
Awesome list - All of them !https://github.com/paralax/awesome-honeypots#honeypots 🏆
Honeynethttps://honeynet.org/project
Live nothinkhttp://www.nothink.org/honeypots.php

IP Research / Analysis / Investigation

Name URL
BGP Toolkithttp://bgp.he.net/ 🏆
Bing dorkip:xxx.xxx.xxx.xxx
Black List Alerthttp://www.blacklistalert.org/
Black List Checkhttp://whatismyipaddress.com/blacklist-check/
Check hosthttp://check-host.net/
FireHOL IP blacklisthttps://github.com/firehol/blocklist-ipsets 🏆
Google dork"xxx.xxx.xxx.xxx" (replace xxx.xxx.xxx.xxx with the ip you are looking for)
Host filehttps://hosts-file.net/
Host trackerhttps://www.host-tracker.com/
IP in detailhttp://ipindetail.com/ip-blacklist-checker
IP voidhttp://www.ipvoid.com/ 👍
IPv4 infohttp://ipv4info.com/ 👍
Multi RBLhttp://multirbl.valli.org/lookup/ 👍👍
Nirsoft country IPhttp://www.nirsoft.net/countryip/
Project Honeypothttps://www.projecthoneypot.org/search_ip.php
Spamhaushttps://www.spamhaus.org/lookup/
TCP utilshttp://www.tcpiputils.com/
Virus totalhttps://www.virustotal.com/en/ip-address/xxx.xxx.xxx.xxx/information/
Whatch Guardhttp://www.reputationauthority.org/

Leak / Defaced 🚑

Name URL
Breach alarmhttps://breachalarm.com/
Camhttp://www.insecam.org/
Hacked emailshttps://hacked-emails.com/
Have I been pwnedhttps://haveibeenpwned.com/
Isithackedhttp://www.isithacked.com
Leakedinhttp://www.leakedin.com/
Siph0nhttps://twitter.com/datasiph0n
Zone-Hhttps://zone-h.org/

Learning / Exercises 🎓

Name URL
Awesome traininghttp://opensecuritytraining.info/Training.html 🏆 🏆
Cybrary traininghttps://www.cybrary.it/
Essential basicshttps://github.com/alex/what-happens-when 🏆 🏆
Exploitshttps://exploit-exercises.com/
Exploitshttps://thesprawl.org/research/
F-Secure traininghttp://mooc.fi/courses/2016/cybersecurity/
Malware Analysis coursehttps://github.com/RPISEC/Malware 🏆
Malware traffic traininghttp://www.malware-traffic-analysis.net/training-exercises.html 👍
Network - Forensichttps://www.honeynet.org/node/504
Practical analysishttps://practicalmalwareanalysis.com/labs/
Reverse - Malwarehttp://fumalwareanalysis.blogspot.se/p/malware-analysis-tutorials-reverse.html
Security courseshttps://bitvijays.github.io/ 👍
Security talkshttps://github.com/PaulSec/awesome-sec-talks 👍

Lock picking 🔐

Name URL
Lock pick guidehttp://lockpickguide.com 👍
Bosnianbill videohttps://www.youtube.com/user/bosnianbill/videos :1:
Lock labhttps://lock-lab.com/
Lock wikihttp://www.lockwiki.com/

Mail utilities 📬

Name URL
10 Minute Mailhttp://10minutemail.com
DNSBLhttps://en.wikipedia.org/wiki/DNSBL
DKIM validatorhttp://dkimvalidator.com/
Email reconhttps://github.com/laramies/theHarvester
Get air mailhttp://en.getairmail.com/
Gophishhttps://github.com/gophish/gophish
Mailinatorhttps://www.mailinator.com/ # https://gist.github.com/nocturnalgeek/1b8fa44283314544c487
Mailnesiahttp://mailnesia.com/
Mailcatchhttp://mailcatch.com/
Mxtoolboxhttp://www.mxtoolbox.com/
Open phishhttps://openphish.com/
Open relayhttp://www.mailradar.com
Openresolver JPhttp://www.openresolver.jp/en/
Phishing Frameworkhttps://github.com/pentestgeek/phishing-frenzy
Phish tankhttp://www.phishtank.com/ 👍
SimplyEmailhttps://github.com/killswitch-GUI/SimplyEmail
Spam DBhttp://www.dnsbl.info/dnsbl-database-check.php
Spam encode secrethttp://spammimic.com/encode.cgi
SpeedPhish Frameworkhttps://github.com/tatanus/SPF
Yop mailhttp://www.yopmail.com/

Malicious traffic detection 🚦

Name URL
Maltrailhttps://github.com/stamparm/maltrail 👍
Tsusenhttps://github.com/stamparm/tsusen
Packetbeathttps://www.elastic.co/products/beats/packetbeat
p0fhttp://lcamtuf.coredump.cx/p0f3/

Malware / Botnet sources 👼

Name URL
Cybercrime trackerhttp://cybercrime-tracker.net/
Malc0dehttp://malc0de.com/database/
Malekalhttp://malwaredb.malekal.com/
Abuse CHhttps://www.abuse.ch/
Trackerhttp://tracker.h3x.eu/
Kernel modehttp://www.kernelmode.info
Malware domain listhttp://www.malwaredomainlist.com
Botnet.frhttps://www.botnets.fr/wiki/Main_Page
Exposed Botnetshttp://www.exposedbotnets.com/
Dont need coffeehttp://malware.dontneedcoffee.com/
VX Vaulthttp://vxvault.net/
Malware binarieshttps://github.com/ytisf/theZoo/tree/master/malwares/Binaries
Total hashhttps://totalhash.cymru.com/
ZeuS Trackerhttps://zeustracker.abuse.ch
Contagiohttp://contagiodump.blogspot.se/
MW sharehttps://mwshare.boredhackerblog.info/samples/ infected:infected
Yararuleshttps://github.com/Yara-Rules/rules
Custom Google search enginehttps://cse.google.com/cse/home?cx=011750002002865445766%3Apc60zx1rliu (from Corey Harrell)
Ransomware trackerhttps://ransomwaretracker.abuse.ch/tracker/
Ransomware overviewhttps://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml#
Ransomware simulatorhttps://shinolocker.com/
No more ransomhttps://www.nomoreransom.org/
VirusSharehttp://virusshare.com/
Malware.luhttps://malware.lu/
SafeGrouphttp://www.malware.pl/ - https://www.scumware.org/
NovCon Minotaurhttp://minotauranalysis.com
Clean MXhttp://support.clean-mx.de/clean-mx/viruses.php
Offensive computinghttp://www.offensivecomputing.net/
Malware domain blocklisthttp://www.malwaredomains.com
Structured Threat Information eXpressionhttps://stixproject.github.io/
The Zoo aka Malware DBhttps://ytisf.github.io/theZoo/
MISPhttps://github.com/MISP/MISP
Maltrieve crawlerhttps://github.com/technoskald/maltrieve
Malware museumhttps://archive.org/details/malwaremuseum 👍

Malware analysis - Sandbox 😷

Name URL
Zeltser's listhttps://zeltser.com/automated-malware-analysis/
Cuckoo Sandboxhttps://www.cuckoosandbox.org/ 👍
Mastiffhttps://github.com/KoreLogicSecurity/mastiff
Fastirhttps://github.com/SekoiaLab/Fastir_Collector
SysAnalyserhttps://github.com/dzzie/SysAnalyzer
Viperhttps://github.com/viper-framework/viper
REMnuxhttp://zeltser.com/remnux/
Zeltser analysishttp://zeltser.com/reverse-malware/automated-malware-analysis.html
Manalyzehttps://github.com/JusticeRage/Manalyze
Quarkslab IRMAhttp://irma.quarkslab.com/
Dorothy2https://github.com/m4rco-/dorothy2
F-Secure seehttps://github.com/F-Secure/see
Noribenhttps://github.com/Rurik/Noriben
Malheurhttps://github.com/rieck/malheur
Drakvufhttps://github.com/tklengyel/drakvuf
Zero Wine Tryoutshttp://zerowine-tryout.sourceforge.net/
CWSandboxhttp://www.cwsandbox.org
RFI sandboxhttps://monkey.org/~jose/software/rfi-sandbox/
Malwasmhttps://github.com/malwarelu/malwasm

Malware analysis - Sandbox - Online 😷

Name URL
Malwr - Cuckoohttps://malwr.com/ 👍
Hybrid analysishttps://www.hybrid-analysis.com/ 👍
PE dumphttps://github.com/zed-0xff/pedump - http://pedump.me/
Yararuleshttps://analysis.yararules.com/
GUN/Linux - Cuckoohttps://linux.huntingmalware.com/
Virscanhttp://www.virscan.org/
Virusadehttp://virusade.com/
VirusTotalhttp://www.virustotal.com/
Malwareconfighttp://malwareconfig.com/
AVcaesarhttps://avcaesar.malware.lu/
Detux GNU/Linux sandboxhttp://detux.org/
Mastiff onlinehttps://mastiff-online.korelogic.com/
AndroTotalhttps://andrototal.org/
Comodohttps://cit.valkyrie.comodo.com/
VirScanhttp://r.virscan.org/
Manalyzerhttps://manalyzer.org/
ID Ransomwarehttps://id-ransomware.malwarehunterteam.com/
Document Analyzerhttp://www.document-analyzer.net/
Malware trackerhttp://www.cryptam.com/
Metascanhttps://www.metadefender.com/#!/scan-file
Jottihttp://virusscan.jotti.org/it
ViCheckhttps://www.vicheck.ca/
PDF examinerhttp://www.pdfexaminer.com/
Malware trackerhttps://www.malwaretracker.com
ThreadExperthttp://www.threatexpert.com/submit.aspx
Randomly changes Win32/64 PE Fileshttps://github.com/secretsquirrel/recomposer
Virus Total Notifierhttps://github.com/mubix/vt-notify
Other listhttp://cleanbytes.net/malware-online-scanners
Sand droidhttp://sanddroid.xjtu.edu.cn

Mobile 📱

Name URL
APK Analzyerhttp://www.apk-analyzer.net/
Droid Sec wikihttp://www.droidsec.org/wiki/
Joebox Cloudhttps://jbxcloud.joesecurity.org/login
Mobi sec labhttp://akana.mobiseclab.org/
Mobile security wikihttps://mobilesecuritywiki.com/ 👍
OWASP Goat Droidhttps://www.owasp.org/index.php/Projects/OWASP_GoatDroid_Project
Tracedroidhttp://tracedroid.few.vu.nl
Wiki secmobihttps://github.com/secmobi/wiki.secmobi.com 🏆

Network

Name URL
Awesome PCAPhttps://github.com/caesar0301/awesome-pcaptools 👍
BGPlayhttps://stat.ripe.net/widget/bgplay 👍
GNU/Linux monitoringhttps://blog.serverdensity.com/80-linux-monitoring-tools-know/
MAC address blockhttp://standards-oui.ieee.org/oui/oui.txt
MAC findhttp://www.coffer.com/mac_find/
MAC findhttp://hwaddress.com
Packet totalhttp://www.packettotal.com/
Ping.euhttp://ping.eu/
Project honeypothttps://www.projecthoneypot.org/
Protocol Numbershttp://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml
Publicly PCAP fileshttp://www.netresec.com/?page=PcapFiles
Service Port Number Registryhttps://www.iana.org/assignments/service-names-port-numbers/ 👍👍
Service Port Number Registryhttps://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Subnet calculatorhttp://www.subnet-calculator.com/cidr.php
Subnet calculatorhttp://www.subnetonline.com/pages/subnet-calculators.php
Security Onion toolshttps://github.com/Security-Onion-Solutions/security-onion/wiki/Tools
Wireshark extentionshttps://www.honeynet.org/project/WiresharkExtensions

OSINT

Name URL
Osint listhttps://github.com/jivoi/awesome-osint 👍
List of social networkhttps://en.wikipedia.org/wiki/List_of_social_networking_websites 👍
Reddithttps://www.reddit.com/r/SocialEngineering/
Maltegohttps://www.paterva.com/
Hunterhttps://hunter.io/
Piplhttps://pipl.com/
Peek you http://www.peekyou.com/
Yatedohttp://www.yatedo.com/
Lullarhttp://com.lullar.com/
Lakakohttp://www.lakako.com/
Yasnihttp://www.yasni.com/
User searchhttps://usersearch.org/
Googlehttps://www.google.com/advanced_search
Google dorksintext:lastName firstName
Google dorksinsubject:lastName firstName
Google dorks`intext:lastName firstName filetype:pdf
Google Scraperhttps://github.com/NikolaiT/GoogleScraper
Binghttps://www.bing.com/
Bing dorkslastName firstName (filetype:doc OR filetype:ppt OR filetype:pps OR filetype:xls OR filetype:docx OR filetype:pptx OR filetype:ppsx OR filetype:xlsx OR filetype:sxw OR filetype:sxc OR filetype:sxi OR filetype:odt OR filetype:ods OR filetype:odg OR filetype:odp OR filetype:pdf OR filetype:wpd OR filetype:svg OR filetype:svgz OR filetype:indd OR filetype:rdp OR filetype:ica)
Yahoohttps://search.yahoo.com/
Duck duck gohttps://duckduckgo.com/
Yandexhttps://www.yandex.com/
Exa leadhttp://www.exalead.com
Osint stalkerhttps://github.com/milo2012/osintstalker
Speed phish frameworkhttps://github.com/tatanus/SPF
Browser exploitation frameworkhttps://github.com/beefproject/beef
The harvesterhttps://github.com/laramies/theHarvester
Meta goofilhttps://github.com/laramies/metagoofil

OS X

Name URL
Awesome OSX & IOS sec listhttps://github.com/ashishb/osx-and-ios-security-awesome
OSX auditorhttps://github.com/jipegit/OSXAuditor
OWASP iGoat Projecthttps://www.owasp.org/index.php/OWASP_iGoat_Project
Security and privacy guidehttps://github.com/drduh/OS-X-Security-and-Privacy-Guide

Passwords 🔑

Name URL
Cotsehttp://www.cotse.com/tools/wordlists.htm
CrackStationhttps://crackstation.net/buy-crackstation-wordlist-password-cracking-dictionary.htm
Default passwordhttps://default-password.info/
Default passwordhttps://cirt.net/passwords
Default passwordhttp://www.defaultpassword.com/
Default passwordhttp://www.defaultpassword.us/
Default cameras passwordhttps://github.com/jeanphorn/wordlist/blob/master/README.md
Default password thc-hydrahttps://github.com/vanhauser-thc/thc-hydra/blob/master/dpl4hydra_full.csv
Default router Passwordhttp://portforward.com/default_username_password/
Dafault router passwordhttp://www.cleancss.com/router-default/
Default router passwordhttps://github.com/jeanphorn/wordlist/blob/master/router_default_password.md
Default wireless Redhat passwordhttp://people.redhat.com/rprice/notes/wireless_passlist.txt
Default VoIP passwordhttps://github.com/netbiosX/Default-Credentials/blob/master/VoIP-Default-Password-List.mdown
Fun secure password checkerhttps://password.kaspersky.com/
Hashcat WIKIhttps://hashcat.net/wiki/
Multiple dictionaryhttps://github.com/danielmiessler/SecLists/tree/master/Passwords
Multiple dictionaryhttps://github.com/duyetdev/bruteforce-database
Online CrackStationhttps://crackstation.net
Online Hask Killerhttps://hashkiller.co.uk
Online Hash crackhttp://www.onlinehashcrack.com/
Online MD5 and SHA1 dbhttp://hashtoolkit.com/
OpenWallhttp://www.openwall.com/passwords/wordlists/ or ftp://ftp.openwall.com/pub/wordlists/
Outpost9http://www.outpost9.com/files/WordLists.html
Packets stormhttps://packetstormsecurity.com/Crackers/wordlists/
Password researchhttp://www.passwordresearch.com/
Programming - Secure Password Storagehttps://paragonie.com/blog/2016/02/how-safely-store-password-in-2016
SecListshttps://github.com/danielmiessler/SecLists/tree/master/Passwords
Skull securityhttps://wiki.skullsecurity.org/Passwords
SSH dictionaryhttps://github.com/droope/pwlist

Penetration testing 🔧

Name URL
Awesome pentesthttps://github.com/enaqx/awesome-pentest
Footprinting - Procedure & toolshttp://www.0daysecurity.com/penetration-testing/network-footprinting.html
GNU/Linux privilege escalationhttps://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/ 👍
Informaion gathering - Toolshttp://www.w4rri0r.com/hacking-tools-windows-os-x-linux-android-solaris-unixware/information-gathering.html
Organization of the Standardhttp://www.pentest-standard.org/index.php/Main_Page 👍
Owasp - Check listhttps://www.owasp.org/index.php/Testing_Checklist
Owasp testing guidehttps://www.owasp.org/images/5/52/OWASP_Testing_Guide_v4.pdf 🏆
Owasp - toolshttps://www.owasp.org/index.php/Category:OWASP_Tool
Public pentest reportshttps://github.com/juliocesarfort/public-pentesting-reports 👍
Python tools for pentesthttps://github.com/dloss/python-pentest-tools
Report samplehttps://www.offensive-security.com/reports/sample-penetration-testing-report.pdf
Reverse engineeringhttp://wiki.yobi.be/wiki/Reverse-Engineering
SANS Penetration Testinghttp://pen-testing.sans.org
Services enumerationhttp://www.0daysecurity.com/penetration-testing/enumeration.html 👍 Thx rawger
Tools - BlackArch listhttps://blackarch.org/tools.html
Tools - Cotsehttp://www.cotse.com/tools/
Tools - Great listhttp://wiki.yobi.be/wiki/Table_of_contents#Security
Tools - Kali listhttp://tools.kali.org/tools-listing
Webhttp://www.w4rri0r.com/hacking-tools-windows-os-x-linux-android-solaris-unixware/web-application-analysis.html
Web vulnerabilitieshttp://www.w4rri0r.com/hacking-tools-windows-os-x-linux-android-solaris-unixware/vulnerability-assessment.html

Port scanners 🎯

Name URL
Masscanhttps://github.com/robertdavidgraham/masscan
Nmaphttps://nmap.org/7/
Zmaphttps://zmap.io/
Zgrabhttps://github.com/zmap/zgrab (Banner Grabber)
Nscanhttps://github.com/OffensivePython/Nscan
Scanrandhttps://www.sans.org/security-resources/idfaq/scanrand.php
PFRinghttps://github.com/ntop/PF_RING - High-speed packet processing framework

Search engines 📡

Name URL
ZoomEyehttps://zoomeye.org/ 👍
Shodanhttps://www.shodan.io/
Censyshttps://censys.io/
Gegerekahttp://gegereka.com/ (not always up)
Googlehttps://www.google.com/advanced_search
Google dorkshttps://gist.github.com/zbetcheckin/04e6a5d7f2d5ef8cfa3c298701f47f9c
List of search engineshttps://en.wikipedia.org/wiki/List_of_search_engines
Threat crowdhttps://www.threatcrowd.org/

Security challenges / WarGames 🚩

Name URL
Zenk-Securityhttps://www.zenk-security.com/
Root-Mehttp://www.root-me.org/
Overthewirehttp://overthewire.org/wargames/
CrackMe.dehttp://crackmes.de/
Reversinghttp://reversing.kr/
Pwnablehttp://pwnable.kr/
Newbiecontesthttps://www.newbiecontest.org/
OWASP VWAD listhttps://github.com/OWASP/OWASP-VWAD/blob/master/src/online.tsv
WeChallhttps://www.wechall.net/
Vulnhubhttps://www.vulnhub.com/
Net Garagehttp://io.netgarage.org/
SmashTheStackhttp://smashthestack.org/
Hackthissitehttp://www.hackthissite.org/
Hack.mehttps://hack.me
HackThis!http://www.hackthis.co.uk/
PenTestLabshttps://lab.thecybershark.com/pentestlabs/5
Backdoor.Sdslabshttps://backdoor.sdslabs.co/
Bright-shadowshttp://www.bright-shadows.net/
SmashTheStackhttp://smashthestack.org/
Ringzer0teamhttps://ringzer0team.com/challenges
Forensic contesthttp://forensicscontest.com/puzzles
Dareyourmindhttp://www.dareyourmind.net
Lost challhttp://www.lost-chall.org/
Rankkhttp://www.rankk.org/
Happy Securityhttp://www.happy-security.de/
Net forcehttps://www.net-force.nl/challenges/
CanYouHack.ithttp://canyouhack.it/
Hellboundhackershttps://www.hellboundhackers.org/
Microcorruptionhttps://microcorruption.com/
More challengeshttp://captf.com/practice-ctf/

Skimmer 🃏

Name URL
Skimmer source from Krebshttps://krebsonsecurity.com/all-about-skimmers/
Great reverse engineering on skimmerhttps://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/

SSH

Name URL
Bruteforce know hostshttps://github.com/Churro/bruteforce-known-hosts
OpenSSH guidelineshttps://wiki.mozilla.org/Security/Guidelines/OpenSSH
SSH audithttps://github.com/arthepsy/ssh-audit.git
SSH audit onlinehttps://sshcheck.com
Who's therehttps://github.com/FiloSottile/whosthere

SSL

Name URL
Certificate searchhttps://crt.sh
Bad SSLhttps://github.com/chromium/badssl.com
Htbridge - Online analysishttps://www.htbridge.com/ssl/
Mozilla SSL Configuration Generatorhttps://mozilla.github.io/server-side-tls/ssl-config-generator/
Observatory by Mozilla - Online analysishttps://observatory.mozilla.org/ 🏆🏆
O-Saft - Toolshttps://www.owasp.org/index.php/O-Saft
OWASP tests - Procedurehttps://www.owasp.org/index.php/Testing_for_Weak_SSL/TLS_Ciphers
Qualys SSL Labs - Online analysishttps://www.ssllabs.com/ssltest/
SSLscan - Toolshttps://github.com/rbsec/sslscan
SSLyze - Toolshttps://github.com/iSECPartners/sslyze
Symantec report - Online analysishttps://cryptoreport.websecurity.symantec.com/checker/
Testssl.sh - Toolshttps://github.com/drwetter/testssl.sh 👍

TOR

Name URL
Hidden serviceshttps://www.torproject.org/docs/hidden-services.html.en
Hidden services scannerhttps://github.com/superp00t/sadonion
Reddithttps://www.reddit.com/r/onions/
Scan Onion Serviceshttps://github.com/s-rah/onionscan
Search engine - Gramshttp://grams7enufi7jmdl.onion/
Search engine - Ahmiahttps://ahmia.fi/
Search engine - TORCHhttp://xmh57jrzrnw6insl.onion/
Search engine - DuckDuckGohttp://3g2upl4pq6kufc4m.onion/
Tailshttps://blog.torproject.org/blogs/tails
The hidden wikihttps://thehiddenwiki.org/
Tolerant ISP for exit nodehttps://trac.torproject.org/projects/tor/wiki/doc/GoodBadISPs
Tor Browser Fingerprinthttps://github.com/jonaslejon/tor-fingerprint
Tor Bulk exit listhttps://check.torproject.org/cgi-bin/TorBulkExitList.py
Tor IP historyhttps://exonerator.torproject.org/
Tor Know exit nodeshttps://check.torproject.org/exit-addresses
Tor Projecthttps://www.torproject.org/
Tor Relays bandwidthhttps://github.com/TheTorProject/bwscanner
Tor Sockshttps://gitweb.torproject.org/torsocks.git
Tor Statushttps://torstatus.blutmagie.de/
URL onion inspectorhttps://github.com/k4m4/onioff

VOIP ☎️

Name URL
Penetration testhttp://0daysecurity.com/penetration-testing/VoIP-security.html
Penetration testhttp://www.backtrack-linux.org/wiki/index.php/Pentesting_VOIP

VPN

Name URL
Open VPNhttps://github.com/OpenVPN
Comparisonhttps://thatoneprivacysite.net/vpn-comparison-chart/
Location testhttps://www.dnsleaktest.com/
Location testhttps://ipleak.net/

Vulnerable environments 🔓

Name URL
Owasp listhttps://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Offline
Owasp BWAhttps://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project
DVWAhttp://www.dvwa.co.uk/
WebGoathttp://code.google.com/p/webgoat
Metasploitable 3https://github.com/rapid7/metasploitable3/wiki
Vulnerable systems listhttps://www.amanhardikar.com/mindmaps/Practice.html 👍
VulnHubhttp://vulnhub.com/
LampSecurityhttp://sourceforge.net/projects/lampsecurity/
Dragonhttps://www.dragonresearchgroup.org/challenges/
Hackademic-RTB1http://www.aldeid.com/wiki/Hackademic-RTB1
Mothhttp://www.bonsai-sec.com
Peruggiahttp://sourceforge.net/projects/peruggia/
XSS play groundhttp://xssplayground.net23.net/

Web browser

Name URL
Amiunique projecthttps://github.com/DIVERSIFY-project/amiunique
Browser exploithttps://github.com/julienbedard/browsersploit
Browser infohttp://www.browser-info.net/
Browser leakshttps://www.browserleaks.com/
Browser recommendationshttps://gist.github.com/atcuno/3425484ac5cce5298932 👍
Browserlinghttps://www.browserling.com/
Fingerprinthttps://amiunique.org/
Fingerprinthttps://panopticlick.eff.org/
Flashhttp://isflashinstalled.com/
Refererhttps://www.whatismyreferer.com/
SSLhttps://www.ssllabs.com/ssltest/viewMyClient.html
URL Shorter Listhttps://bit.do/list-of-url-shorteners.php
User agenthttp://useragentstring.com/pages/useragentstring.php
User agenthttp://whatsmyuseragent.com/
User agenthttps://www.projecthoneypot.org/robot_useragents.php
User agenthttps://www.whatismybrowser.com/developers/tools/user-agent-parser/browse

Windows

Name URL
Anti forensic Windowshttps://www.reddit.com/r/security/comments/32fb1l/open_guide_to_scrubbing_windows_oss_from_forensic/
Windows executable walkthroughhttps://i.imgur.com/pHjcI.png
Windows exploitationhttps://github.com/enddo/awesome-windows-exploitation
Windows hardeninghttps://github.com/PaulSec/awesome-windows-domain-hardening

Wide Scans 🌎

Name URL
Scans.iohttps://scans.io/
Rapid7 Sonar Labshttps://sonar.labs.rapid7.com/
Similar projectshttps://github.com/rapid7/sonar/wiki/Similar-Projects
Defcon conferencehttps://defcon.org/
Blackhat conferencehttps://www.blackhat.com/

Wireless / Radio 📶

Name URL
Awesome wifi tools listhttps://github.com/0x90/wifi-arsenal
Penetration testhttp://0daysecurity.com/penetration-testing/wireless-penetration.html
Great wifi maphttps://wigle.net/
RFSec-ToolKithttps://github.com/cn0xroot/RFSec-ToolKit
RTL-SDRhttp://www.rtl-sdr.com/
Wireless in airportshttps://www.google.com/maps/d/viewer?mid=1Z1dI8hoBZSJNWFx2xr_MMxSxSxY