Kali Linux CTF Blueprints
Online book on building, testing, and customizing your own Capture the Flag challenges.
A curated list of CTF frameworks, libraries, resources and softwares
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Online book on building, testing, and customizing your own Capture the Flag challenges.
Hosts communication through DNS.
Triage program.
Artifact-centric DFIR tool.
Dump your registry.
Platform to host jeopardy style CTFs from ISISLab, NYU Tandon.
Develop, deploy and maintain your own CTF infrastructure.
Platform to host Capture the Flag competitions from Facebook.
A Highly Accessible and Automated Virtualization Platform for Security Education.
CTF scoring platform.
A CTF engine written in PHP.
Badass lightweight plaform to host CTFs. No JS involved.
A simple security CTF framework.
CTF in a box. Minimal setup required.
The platform used to run picoCTF. A great framework to host any CTF.
Small framework to create/manage/package jeopardy CTF challenges.
A Game of Hackers (CTF Scoreboard & Game Manager).
Platform for CTFs by Legitbs (Defcon).
Security Scenario Generator. Creates randomly vulnerable virtual machines.
A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.
An automated, modular cryptanalysis tool.
A utility tool for performing hash length extension attacks.
A CLI tool to execute padding oracle attacks.
A tool for Breaking PkZip-encryption.
An online tool for breaking substitution ciphers or vigenere ciphers (without key).
A tool for recovering RSA private key with various attack.
Generate private key with knowledge of p and q.
A tool to analyze multi-byte xor cipher.
Password Cracker
A parallelized login cracker which supports numerous protocols to attack
Community enhanced version of John the Ripper.
Password Cracker.
Nozzlr is a bruteforce framework, trully modular and script-friendly.
Windows password cracker based on rainbow tables.
Patator is a multi-purpose brute-forcer, with a modular design.
Burp Suite extension for sending large numbers of HTTP requests
Inject dlls in processes.
Simplify format string exploitation.
Penetration testing software.
A tool to find the one gadget execve('/bin/sh', NULL, NULL) call.; gem install one_gadget
CTF Framework for writing exploits.
QEMU Interactive Runtime Analyser.
Framework for ROP exploitation.
Security CTF Toolkit.
Crack 802.11 WEP and WPA-PSK keys.; apt-get install aircrack-ng
Analyze sound files (mp3, m4a, whatever).; apt-get install audacity
Dump SYSTEM and SAM files.; apt-get install samdump2 bkhive
PE Editor.
Dump windows credentials.
Rips web accessible (distributed) version control systems.
Read, write and edit file metadata.
Used for recovering lost data from mountable images.
Extract particular kind of files using headers.; apt-get install foremost
Used to fix corrupt filesystems.
Malware hunting tool.
Network Forensic Analysis Tool.
Find and extract zlib files compressed in PDF files.
Verifies the integrity of PNG and dump all of the chunk-level information in human-readable form.; apt-get install pngcheck
Extract various filetypes from exes.
Investigate NT_USER.dat files.
A Whitespace Steganography Tool.
Simple CLI forensics tool for tracking USB device artifacts (history of USB events) on GNU/Linux.
To investigate memory dumps.
Simple tool for Windows that allows you to read offline Registry files from external drive and view the desired Registry key in .reg file format.
Used to view Windows registries.
Reverse engineer Android applications.
Yet another Android decompiler.
Android Decompiler.
Binary Analysis and Reverse engineering Framework.
Binary analysis framework.
Collection of binary tools.
Analyze, reverse engineer, and extract firmware images.
Decompile x86/SPARC/PowerPC/ST-20 binaries to C.
run basic functions from stripped binaries cross platform.
cwe_checker finds vulnerable patterns in binary executables.
A work-in-progress deobfuscator for movfuscated binaries.
Dynamic Code Injection.
GDB plugin.
Reverse engineering tool (disassembler) for OSX and Linux.
Most used Reversing software.
An online decompiler for Java and Android APKs.
A dynamic binary instrumentaion tool by Intel.
GDB front-end/reverse engineering tool, focused on game-hacking and automation.
A tool which uses intel pin for Side Channel Analysis.
An interactive disassembler for x86/ARM/MIPS which can generate indented pseudo-code with colored syntax.
A GDB plugin that provides a suite of utilities to hack around GDB easily.
Decompile Python 2.7 binaries (.pyc).
Windows debugger distributed by Microsoft.
Program that can copy executables with execute, but no read permission.
A theorem prover from Microsoft Research.
A Javascript malware analysis tool.
Analyze obfuscated Javascript code.
Collection of utilities including an ActionScript 3 assembler/disassembler.
Collection of utilities to work with SWF files.
A Python script for analyzing Flash files.
Cross-Site WebSocket Hijacking Tester.
Lets you inspect http requests to a particular url.
Aperi'Solve is a platform which performs layer analysis on image (open-source).
Convert images b/w formats and apply filters.
Shows EXIF information in JPEG files.
Read and write meta information in files.
Image metadata manipulation tool.
Embeds text and files in images with optional encryption. Easy-to-use UI.
This is a client-side Javascript tool to steganographically hide images inside the lower "bits" of other images
Tool for manipulating images.
Universal steganographic tool.
For various analysis related to PNGs.; apt-get install pngtools
Used to deblur and fix defocused images.
Tool for stegano analysis written in Java.
Online steganography encoder and decoder.
Launches brute-force dictionary attacks on JPG image.
Steganography brute-force utility to uncover hidden data inside files.
Detect hidden files and text in images.
Hide data in various kind of images.
Conduct a wide range of image steganography operations, such as concealing/revealing files hidden within bits (open-source).
Apply various steganography techniques to images.
PNG/BMP analysis.
Firefox addon for easy web exploitation.
Intercepting proxy to replay, debug, and fuzz HTTP requests and responses
Add on for chrome for debugging network requests.
A high performance offensive security tool for reconnaissance and vulnerability scanning.
Web Application Attack and Audit Framework.
Automated XSS testor.
Based on Debian.
Based on Ubuntu.
Based on Arch Linux.
Based on Fedora.
Based on Debian.
Based on Debian.
Based on Gentoo.
Based on openSUSE.
Based on Slackware.
Based on Windows.
Field Guide by Trails of Bits.
Start Guide maintained by community.
Short guideline for CTF beginners by Endgame
A free course that teaches beginners the basics of forensics, crypto, and web-ex.
Video tutorials and walkthroughs of popular CTF platforms.
Video tutorials on Exploitation.
A small course for beginners in CTFs (in Russian).
Security Platform by SDSLabs.
Reverse Engineering Challenges.
Fun cryptography challenges.
Online CTF with a variety of targets to attack.
Variety of VMs to learn variety of computer security issues.
Variety of VMs to learn variety of computer security issues.
Binary challenges having a slow learning curve, and write-ups for each level.
Weekly CTFs for all types of security enthusiasts.
Training ground for hackers.
CTF from HackerOne
Ethical hacking, computer network and security challenge platform.
Web challenges starting from basic ones.
Wargame for binary challenges.
Embedded security CTF.
Wargame maintained by OvertheWire Community.
Variety of VM and online challenges (paid).
All year round ctf game. Questions from the yearly picoCTF competition.
Binary Exploitation Wargame.
Pwn Game.
Binary wargame.
Binary Exploitation Wargame.
Reversing challenge.
Ringzer0 Team Online CTF.
ROP Wargames.
Challenges with a holiday theme released annually and maintained by SANS.
A variety of wargames maintained by the SmashTheStack Community.
Various amazing CTF challenges, in many different categories. Has both Practice mode and Contest mode.
VM-based for practical in digital security, computer application & network administration.
A penetration testing training platform, which offers various computer challenges, in various categories.
Hacking challenges for web.
PHP/MySQL web application that is damn vulnerable.
Scripts and tools for hosting a CTF on OWASP Juice Shop easily.
CTF Cheatsheet.
Reddit CTF category.
Chinese resources to learn CTF.
Wiki from team bi0s.
CTF tips and tricks.
CTF Wiki by Isis lab.
CTF tips by OTA CTF team members.
Write-ups for CTF challenges by 0e85dc6eaf
Dumped CTF challenges and materials by psifertex.
CTF challenges + write-ups archive maintained by the community.
Scraps all writeup from CTF Time and organize which to read first.
CTF write-ups repo maintained by HackThisSite team.
CTF competition write-ups by mzfr
A collection of CTF write-ups all using pwntools.
A collection of CTF write-ups by the SababaSec team
CTF challenge archive maintained by Jonathan Salwan.
CTF write-ups repo maintained by SmokeLeetEveryday team.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.