Top 50 Awesome List

apsdehal/awesome-ctf

Security  2 years ago  7k
A curated list of CTF frameworks, libraries, resources and softwares
View byDAY/WEEK/README
View on Github

May 18th - May 24th, 2020

Create

  • Kali Linux CTF Blueprints - Online book on building, testing, and customizing your own Capture the Flag challenges.
  • Tutorials

  • IppSec - Video tutorials and walkthroughs of popular CTF platforms.
  • May 11th - May 17th, 2020

    Tutorials

  • Intro. to CTF Course - A free course that teaches beginners the basics of forensics, crypto, and web-ex.
  • Platforms

  • MotherFucking-CTFstars42 - Badass lightweight plaform to host CTFs. No JS involved.
  • Websites

  • Awesome CTF Cheatsheet - CTF Cheatsheet.
  • Steganography

  • StegOnline - Conduct a wide range of image steganography operations, such as concealing/revealing files hidden within bits (open-source).
  • Apr 27th - May 3rd, 2020

    Bruteforcers

  • Turbo Intruder - Burp Suite extension for sending large numbers of HTTP requests
  • Wargames

  • Hacker101 - CTF from HackerOne
  • echoCTF.RED - Online CTF with a variety of targets to attack.
  • CryptoHack - Fun cryptography challenges.
  • Platforms

  • echoCTF.REDstars33 - Develop, deploy and maintain your own CTF infrastructure.
  • Jan 13th - Jan 19th, 2020

    Forensics

  • Kroll Artifact Parser and Extractor (KAPE) - Triage program.
  • Magnet AXIOM - Artifact-centric DFIR tool.
  • Wireshark - Used to analyze pcap or pcapng files
  • Networking

  • Monit - A linux tool to check a host on the network (and other non-network activities).
  • Reversing

  • Pwndbgstars4.7k - A GDB plugin that provides a suite of utilities to hack around GDB easily.
  • Boomerangstars311 - Decompile x86/SPARC/PowerPC/ST-20 binaries to C.
  • Web

  • BurpSuite - A graphical tool to testing website security.
  • Steganography

  • SteganographyOnline - Online steganography encoder and decoder.
  • Wargames

  • PicoCTF - All year round ctf game. Questions from the yearly picoCTF competition.
  • Crypto

  • QuipQuip - An online tool for breaking substitution ciphers or vigenere ciphers (without key).
  • Wikis

  • CTF Cheatsheet - CTF tips and tricks.
  • Oct 14th - Oct 20th, 2019

    Forensics

  • Snow - A Whitespace Steganography Tool.
  • Writeups Collections

  • HackThisSitestars216 - CTF write-ups repo maintained by HackThisSite team.
  • Wargames

  • PentesterLab - Variety of VM and online challenges (paid).
  • SANS HHC - Challenges with a holiday theme released annually and maintained by SANS.
  • Oct 7th - Oct 13th, 2019

    Forensics

  • Pngcheck - Verifies the integrity of PNG and dump all of the chunk-level information in human-readable form.
    • apt-get install pngcheck
  • Dnscat2stars2.7k - Hosts communication through DNS.
  • Registry Dumper - Dump your registry.
  • Aircrack-Ng - Crack 802.11 WEP and WPA-PSK keys.
    • apt-get install aircrack-ng
  • Audacity - Analyze sound files (mp3, m4a, whatever).
    • apt-get install audacity
  • Bkhive and Samdump2 - Dump SYSTEM and SAM files.
    • apt-get install samdump2 bkhive
  • CFF Explorer - PE Editor.
  • Creddumpstars210 - Dump windows credentials.
  • DVCS Ripperstars1.4k - Rips web accessible (distributed) version control systems.
  • Exif Tool - Read, write and edit file metadata.
  • Extundelete - Used for recovering lost data from mountable images.
  • Fibratusstars1.6k - Tool for exploration and tracing of the Windows kernel.
  • Foremost - Extract particular kind of files using headers.
    • apt-get install foremost
  • Fsck.ext4 - Used to fix corrupt filesystems.
  • Malzilla - Malware hunting tool.
  • NetworkMiner - Network Forensic Analysis Tool.
  • PDF Streams Inflater - Find and extract zlib files compressed in PDF files.
  • ResourcesExtract - Extract various filetypes from exes.
  • Shellbagsstars136 - Investigate NT_USER.dat files.
  • USBRipstars1k - Simple CLI forensics tool for tracking USB device artifacts (history of USB events) on GNU/Linux.
  • Volatilitystars5.4k - To investigate memory dumps.
  • Bruteforcers

  • Hydra - A parallelized login cracker which supports numerous protocols to attack
  • John The Jumbostars6.4k - Community enhanced version of John the Ripper.
  • John The Ripper - Password Cracker.
  • Steganography

  • Image Steganography - Embeds text and files in images with optional encryption. Easy-to-use UI.
  • Image Steganography Online - This is a client-side Javascript tool to steganographically hide images inside the lower "bits" of other images
  • AperiSolve - Aperi'Solve is a platform which performs layer analysis on image (open-source).
  • Convert - Convert images b/w formats and apply filters.
  • Exif - Shows EXIF information in JPEG files.
  • Exiftool - Read and write meta information in files.
  • Exiv2 - Image metadata manipulation tool.
  • ImageMagick - Tool for manipulating images.
  • Outguess - Universal steganographic tool.
  • Pngtools - For various analysis related to PNGs.
    • apt-get install pngtools
  • SmartDeblurstars2.2k - Used to deblur and fix defocused images.
  • Steganabara - Tool for stegano analysis written in Java.
  • Stegbreak - Launches brute-force dictionary attacks on JPG image.
  • StegCrackerstars456 - Steganography brute-force utility to uncover hidden data inside files.
  • stegextractstars97 - Detect hidden files and text in images.
  • Steghide - Hide data in various kind of images.
  • Stegsolve - Apply various steganography techniques to images.
  • Zstegstars884 - PNG/BMP analysis.
  • Writeups Collections

  • 0e85dc6eafstars75 - Write-ups for CTF challenges by 0e85dc6eaf
  • Mzfrstars107 - CTF competition write-ups by mzfr
  • SababaSecstars15 - A collection of CTF write-ups by the SababaSec team
  • Captf - Dumped CTF challenges and materials by psifertex.
  • CTF write-ups (community) - CTF challenges + write-ups archive maintained by the community.
  • CTFTime Scrapperstars26 - Scraps all writeup from CTF Time and organize which to read first.
  • pwntools writeupsstars446 - A collection of CTF write-ups all using pwntools.
  • Shell Storm - CTF challenge archive maintained by Jonathan Salwan.
  • Wargames

  • PWN Challenge - Binary Exploitation Wargame.
  • Crackmes - Reverse Engineering Challenges.
  • Microcorruption - Embedded security CTF.
  • Over The Wire - Wargame maintained by OvertheWire Community.
  • Pwnable.kr - Pwn Game.
  • Pwnable.tw - Binary wargame.
  • Pwnable.xyz - Binary Exploitation Wargame.
  • Reversin.kr - Reversing challenge.
  • Ringzer0Team - Ringzer0 Team Online CTF.
  • ROP Wargamesstars18 - ROP Wargames.
  • Exploit Exercises - Variety of VMs to learn variety of computer security issues.
  • Exploit.Education - Variety of VMs to learn variety of computer security issues.
  • Grackerstars4 - Binary challenges having a slow learning curve, and write-ups for each level.
  • Viblo CTF - Various amazing CTF challenges, in many different categories. Has both Practice mode and Contest mode.
  • Crypto

  • CyberChef - Web app for analysing and decoding data.
  • FeatherDusterstars973 - An automated, modular cryptanalysis tool.
  • Hash Extenderstars843 - A utility tool for performing hash length extension attacks.
  • padding-oracle-attackerstars152 - A CLI tool to execute padding oracle attacks.
  • PkCrack - A tool for Breaking PkZip-encryption.
  • RSACTFToolstars3.6k - A tool for recovering RSA private key with various attack.
  • RSAToolstars794 - Generate private key with knowledge of p and q.
  • XORToolstars1.1k - A tool to analyze multi-byte xor cipher.
  • Reversing

  • PINCEstars1.3k - GDB front-end/reverse engineering tool, focused on game-hacking and automation.
  • Androguardstars4k - Reverse engineer Android applications.
  • Angrstars5.9k - platform-agnostic binary analysis framework.
  • Apk2Goldstars610 - Yet another Android decompiler.
  • ApkTool - Android Decompiler.
  • Barfstars1.3k - Binary Analysis and Reverse engineering Framework.
  • Binary Ninja - Binary analysis framework.
  • BinUtils - Collection of binary tools.
  • ctf_importstars99 – run basic functions from stripped binaries cross platform.
  • cwe_checkerstars676 - cwe_checker finds vulnerable patterns in binary executables.
  • demovfuscatorstars583 - A work-in-progress deobfuscator for movfuscated binaries.
  • Frida - Dynamic Code Injection.
  • GDB - The GNU project debugger.
  • GEFstars4.6k - GDB plugin.
  • Hopper - Reverse engineering tool (disassembler) for OSX and Linux.
  • IDA Pro - Most used Reversing software.
  • Jadxstars30.6k - Decompile Android files.
  • Java Decompilers - An online decompiler for Java and Android APKs.
  • Krakataustars1.6k - Java decompiler and disassembler.
  • Objectionstars5k - Runtime Mobile Exploration.
  • PEDAstars5.1k - GDB plugin (only python2.7).
  • Pin - A dynamic binary instrumentaion tool by Intel.
  • PinCTFstars442 - A tool which uses intel pin for Side Channel Analysis.
  • radare2stars16.4k - A portable reversing framework.
  • Tritonstars2.4k - Dynamic Binary Analysis (DBA) framework.
  • Uncompylestars409 - Decompile Python 2.7 binaries (.pyc).
  • WinDbg - Windows debugger distributed by Microsoft.
  • Xocopy - Program that can copy executables with execute, but no read permission.
  • Z3stars7.6k - A theorem prover from Microsoft Research.
  • Platforms

  • CTFdstars4.1k - Platform to host jeopardy style CTFs from ISISLab, NYU Tandon.
  • FBCTFstars6.4k - Platform to host Capture the Flag competitions from Facebook.
  • Haaukinsstars139- A Highly Accessible and Automated Virtualization Platform for Security Education.
  • HackTheArchstars62 - CTF scoring platform.
  • Mellivorastars398 - A CTF engine written in PHP.
  • NightShadestars101 - A simple security CTF framework.
  • OpenCTFstars77 - CTF in a box. Minimal setup required.
  • PyChallFactorystars81 - Small framework to create/manage/package jeopardy CTF challenges.
  • RootTheBoxstars667 - A Game of Hackers (CTF Scoreboard & Game Manager).
  • Scorebotstars46 - Platform for CTFs by Legitbs (Defcon).
  • SecGenstars2.3k - Security Scenario Generator. Creates randomly vulnerable virtual machines.
  • PicoCTFstars264 - The platform used to run picoCTF. A great framework to host any CTF.
  • Attacks

  • Yersiniastars523 - Attack various protocols on layer 2.
  • Exploits

  • DLLInjectorstars440 - Inject dlls in processes.
  • Metasploit - Penetration testing software.
  • one_gadgetstars1.6k - A tool to find the one gadget execve('/bin/sh', NULL, NULL) call.
    • gem install one_gadget
  • Pwntoolsstars9.2k - CTF Framework for writing exploits.
  • Qirastars3.5k - QEMU Interactive Runtime Analyser.
  • ROP Gadgetstars3.1k - Framework for ROP exploitation.
  • V0ltstars358 - Security CTF Toolkit.
  • Services

  • CSWSH - Cross-Site WebSocket Hijacking Tester.
  • Request Bin - Lets you inspect http requests to a particular url.
  • Web

  • Hackbar - Firefox addon for easy web exploitation.
  • Postman - Add on for chrome for debugging network requests.
  • Raccoonstars2.5k - A high performance offensive security tool for reconnaissance and vulnerability scanning.
  • SQLMapstars23.8k - Automatic SQL injection and database takeover tool. pip install sqlmap
  • XSSer - Automated XSS testor.
  • Uglifystars12.1k
  • Operating Systems

  • Android Tamer - Based on Debian.
  • BackBox - Based on Ubuntu.
  • BlackArch Linux - Based on Arch Linux.
  • Fedora Security Lab - Based on Fedora.
  • Kali Linux - Based on Debian.
  • Parrot Security OS - Based on Debian.
  • Pentoo - Based on Gentoo.
  • URIX OS - Based on openSUSE.
  • Wifislax - Based on Slackware.
  • Tutorials

  • CTF Field Guide - Field Guide by Trails of Bits.
  • CTF Resources - Start Guide maintained by community.
  • LiveOverFlow - Video tutorials on Exploitation.
  • MIPT CTFstars245 - A small course for beginners in CTFs (in Russian).
  • Websites

  • CTF Time - General information on CTF occuring around the worlds.
  • Reddit Security CTF - Reddit CTF category.
  • Wikis

  • Bamboofox - Chinese resources to learn CTF.
  • bi0s Wiki - Wiki from team bi0s.
  • ISIS Lab - CTF Wiki by Isis lab.
  • OpenToAllstars120 - CTF tips by OTA CTF team members.
  • Networking

  • Zeek - An open-source network security monitor.
  • Apr 15th - Apr 21st, 2019

    Reversing

  • Ghidra - Open Source suite of reverse engineering tools. Similar to IDA Pro.
  • Oct 8th - Oct 14th, 2018

    Jun 18th - Jun 24th, 2018

    Wargames

  • Hacking-Lab - Ethical hacking, computer network and security challenge platform.
  • Jun 11th - Jun 17th, 2018

    Wargames

  • Hone Your Ninja Skills - Web challenges starting from basic ones.
  • Mar 5th - Mar 11th, 2018

    Attacks

  • Bettercapstars11.4k - Framework to perform MITM (Man in the Middle) attacks.
  • Feb 5th - Feb 11th, 2018

    Wargames

  • Root-Me - Hacking and Information Security learning platform.
  • Dec 11th - Dec 17th, 2017

    Networking

  • Nmap - An open source utility for network discovery and security auditing.
  • Zmap - An open-source network scanner.
  • Masscanstars19.2k - Mass IP port scanner, TCP port scanner.
  • Wireshark - Analyze the network dumps.
    • apt-get install wireshark
  • Nov 13th - Nov 19th, 2017

    Wargames

  • W3Challs - A penetration testing training platform, which offers various computer challenges, in various categories.
  • Oct 9th - Oct 15th, 2017

    Wargames

  • Hack The Box - Weekly CTFs for all types of security enthusiasts.
  • Mar 20th - Mar 26th, 2017

    Bruteforcers

  • Nozzlrstars61 - Nozzlr is a bruteforce framework, trully modular and script-friendly.
  • Patatorstars2.9k - Patator is a multi-purpose brute-forcer, with a modular design.
  • Feb 13th - Feb 19th, 2017

    Exploits

  • libformatstrstars330 - Simplify format string exploitation.
  • Bruteforcers

  • Hashcat - Password Cracker
  • Web

  • OWASP ZAP - Intercepting proxy to replay, debug, and fuzz HTTP requests and responses
  • Dec 19th - Dec 25th, 2016

    Networking

  • Nipestars1.4k - Nipe is a script to make Tor Network your default gateway.
  • Nov 28th - Dec 4th, 2016

    Reversing

  • Plasmastars3k - An interactive disassembler for x86/ARM/MIPS which can generate indented pseudo-code with colored syntax.
  • Nov 14th - Nov 20th, 2016

    Web

  • Commixstars3.3k - Automated All-in-One OS Command Injection and Exploitation Tool.
  • Oct 31st - Nov 6th, 2016

    Starter Packs

  • LazyKalistars39 - A 2016 refresh of LazyKali which simplifies install of tools and configuration.
  • Sep 26th - Oct 2nd, 2016

    Web

  • W3afstars4k - Web Application Attack and Audit Framework.
  • Jun 6th - Jun 12th, 2016

    Wargames

  • IO - Wargame for binary challenges.
  • May 9th - May 15th, 2016

    Wargames

  • WebHacking - Hacking challenges for web.
  • Oct 26th - Nov 1st, 2015

    Wargames

  • SmashTheStack - A variety of wargames maintained by the SmashTheStack Community.
  • Backdoor - Security Platform by SDSLabs.
  • Sep 7th - Sep 13th, 2015

    Starter Packs

  • CTF Toolsstars6.6k - Collection of setup scripts to install various security research tools.
  • Jul 13th - Jul 19th, 2015

    Wargames

  • VulnHub - VM-based for practical in digital security, computer application & network administration.
  • Jun 29th - Jul 5th, 2015

    Tutorials

  • How to Get Started in CTF - Short guideline for CTF beginners by Endgame
  • Apr 27th - May 3rd, 2015

    Writeups Collections

  • Smoke Leet Everydaystars178 - CTF write-ups repo maintained by SmokeLeetEveryday team.
  • Wargames

  • Hack This Site - Training ground for hackers.
  • Apr 20th - Apr 26th, 2015

    Bruteforcers

  • Ophcrack - Windows password cracker based on rainbow tables.
  • Reversing

  • BinWalkstars8.3k - Analyze, reverse engineer, and extract firmware images.
  • Last Checked At: 2022-06-24T18:39:02.789Z
    Previous
    sbilly/awesome-security
    Next
    rshipp/awesome-malware-analysis

    About

    Track your favorite github awesome repo, not just star it. trackawesomelist.com provides website, newsletter, RSS for tracking the popular awesome list by daily and weekly.
    Contact us: [email protected]
    Track Awesome List - Track your favorite Github awesome repos, not just star them | Product Hunt

    Subscribe

    Subscribe to our weekly newsletter to receive the awesome updates! We never send spam and you can unsubscribe instantly with one click. Here's past issues.

    Links

    Follow us on TwitterSubscribe us on TelegramSubmit awesome list repoNewsletterDonateSitemap