OWASP Top 10 for LLM Applications
genai.owasp.org
the reference list.
Topic
Offensive and defensive security, vulnerability research, threat intelligence, and compliance.
security
Curated resources grouped by category.
genai.owasp.org
the reference list.
atlas.mitre.org
adversarial threat landscape for AI systems.
www.nist.gov
NIST AI Risk Management Framework resource in AI Security & Red-Teaming.
incidentdatabase.ai
searchable real-world incidents.
github.com
NVIDIA's LLM vulnerability scanner.
github.com
Microsoft's Python Risk Identification Toolkit for AI.
www.promptfoo.dev
eval + red-team framework, CI-friendly.
www.giskard.ai
open-source LLM testing.
github.com
pytest-style LLM evals.
inspect.aisi.org.uk
UK AISI's eval framework.
www.lakera.ai
prompt-injection/PII firewall.
protectai.com
ML supply-chain security.
hiddenlayer.com
model security platform.
github.com
NVIDIA, programmable rails.
llm-guard.com
open-source input/output guard.
www.anthropic.com
Anthropic alignment & red-team research resource in AI Security & Red-Teaming.
www.apolloresearch.ai
deceptive-alignment evals.
metr.org
autonomy/capability evaluations.
www.aisi.gov.uk
UK AI Safety Institute (AISI) resource in AI Security & Red-Teaming.
www.nist.gov
US AISI (at NIST) resource in AI Security & Red-Teaming.
simonwillison.net
best running coverage.
embracethered.com
Johann Rehberger, AI red-team blog.
www.learnprompting.org
Learn Prompting.
aivillage.org
DEF CON AI Village resource in AI Security & Red-Teaming.
owasp.org
Open community producing free resources, tools, and standards for improving software security worldwide.
portswigger.net
Free, world-class web security training with hands-on labs covering every major vulnerability class.
cwe.mitre.org
MITRE's community-developed list of software and hardware weakness types used in vulnerability classification.
book.hacktricks.xyz
Continuously updated hacking and pentesting reference covering techniques, tools, and CTF tricks.
semgrep.dev
Static analysis tool for finding bugs and security issues in source code with a large rule registry.
zaproxy.org
Open-source DAST scanner and proxy for automatically finding security vulnerabilities in web applications.
snyk.io
Developer security platform for scanning code, dependencies, containers, and IaC for vulnerabilities.
sonarqube.org
Continuous code quality and security inspection platform supporting 30+ languages.
trivy.dev
Comprehensive open-source security scanner for containers, filesystems, IaC, and git repositories.
csp-evaluator.withgoogle.com
Google tool for analysing CSP header configurations and identifying common misconfigurations and bypasses.
cloudsecurityalliance.org
Non-profit defining cloud security best practices through research, certifications (CCSK), and the CCM framework.
prowler.com
Open-source cloud security tool for auditing, hardening, and continuous compliance across AWS, Azure, and GCP.
github.com
NCC Group's multi-cloud security auditing tool that produces an HTML report of misconfigurations.
trivy.dev
Comprehensive scanner for container images, IaC files, git repos, and Kubernetes clusters.
checkov.io
Static analysis tool for Terraform, Kubernetes, Dockerfile, and CloudFormation to catch misconfigurations pre-deploy.
falco.org
CNCF runtime security tool for detecting anomalous behaviour in containers and Kubernetes workloads.
aws.amazon.com
Centralised AWS security posture management aggregating findings from GuardDuty, Inspector, Macie, and third-party tools.
steampipe.io
Query cloud APIs with SQL; includes prebuilt compliance benchmarks for AWS, Azure, GCP, and Kubernetes.
tag-security.cncf.io
CNCF's Security Technical Advisory Group producing white papers, assessments, and guidance on cloud-native security.
nist.gov
Voluntary framework of standards, guidelines, and practices for managing cybersecurity risk, now at version 2.0.
cisecurity.org
Prioritised set of 18 defensive security controls developed by the Center for Internet Security.
www.iso.org
International standard for information security management systems (ISMS) and its certification framework.
gdpr-info.eu
Full text of the EU General Data Protection Regulation with recitals and cross-references.
pcisecuritystandards.org
Governing body for PCI DSS, the payment card industry data security standard.
enisa.europa.eu
EU Agency for Cybersecurity publishing threat landscapes, guidelines, and policy recommendations across the EU.
www.aicpa-cima.com
AICPA's Service Organization Control 2 framework for auditing security, availability, and confidentiality of cloud services.
eur-lex.europa.eu
EU Network and Information Security Directive 2 expanding cybersecurity obligations to more sectors.
bsi.bund.de
German federal authority for information security, publishing technical guidelines and IT-Grundschutz.
cryptopals.com
Series of cryptography challenges teaching practical breaks of real-world crypto constructions.
ssl-config.mozilla.org
Generates secure TLS configurations for nginx, Apache, HAProxy, and other servers based on Mozilla guidelines.
letsencrypt.org
Free, automated, and open certificate authority providing TLS certificates to the public.
openssl.org
The widely-used open-source toolkit for SSL/TLS and general-purpose cryptography.
doc.libsodium.org
Modern, easy-to-use cryptographic library with opinionated, hard-to-misuse APIs for encryption, signing, and hashing.
age-encryption.org
Simple, modern, and secure file encryption tool and library with a clean format specification.
sigstore.dev
Open-source project for signing, verifying, and protecting software supply chains with keyless code signing.
haveibeenpwned.com
Check if email addresses or passwords have appeared in known data breaches; free API for developers.
rfc-editor.org
Authoritative source for Internet Standards and RFCs, including foundational security protocol specifications.
d3fend.mitre.org
Complementary framework to ATT&CK mapping defensive techniques to the offensive tactics they counter.
github.com
Generic signature format for SIEM rules enabling detection content to be shared and converted across platforms.
virustotal.github.io
Pattern-matching tool for identifying and classifying malware samples based on textual or binary patterns.
wazuh.com
Open-source security platform combining SIEM, XDR, and CSPM for endpoint detection and log analysis.
elastic.co
SIEM and endpoint security built on the Elastic Stack, with free detection rules and prebuilt dashboards.
thehive-project.org
Scalable, open-source security incident response platform with case management and MISP integration.
velocidex.com
Advanced DFIR and endpoint monitoring tool for fast artifact collection and threat hunting at scale.
greenbone.net
Open-source vulnerability scanning and management solution with a large continuously updated feed of tests.
zeek.org
Powerful network analysis framework that generates rich, structured logs for security monitoring and forensics.
atomicredteam.io
Library of tests mapped to MITRE ATT&CK for validating defensive controls and detection coverage.
keycloak.org
Open-source identity and access management with SSO, OIDC, SAML, and fine-grained authorisation.
goauthentik.io
Self-hosted identity provider supporting OIDC, SAML, LDAP, and Radius with a modern UI.
authelia.com
Open-source authentication and authorisation server providing 2FA and SSO for reverse proxies.
vaultproject.io
Secrets management, encryption-as-a-service, and dynamic credentials for any infrastructure.
pages.nist.gov
NIST's authoritative guidelines for digital identity, authentication levels, and federation.
openid.net
Identity layer built on top of OAuth 2.0 enabling client applications to verify end-user identity.
fidoalliance.org
Industry consortium behind FIDO2, WebAuthn, and passkeys — the standard for passwordless authentication.
zitadel.com
Cloud-native, open-source IAM solution with multi-tenancy, passkeys, and audit log out of the box.
oauth.net
The authorisation framework spec and resources — RFCs, security BCP, and implementation guides.
thehive-project.org
Scalable, open-source security incident response platform with case and alert management and MISP integration.
velocidex.com
Advanced endpoint visibility and DFIR tool for collecting artifacts and hunting at scale across thousands of hosts.
www.autopsy.com
Open-source digital forensics platform with a GUI front-end to The Sleuth Kit for disk image analysis.
volatilityfoundation.org
Leading open-source memory forensics framework for analysing RAM dumps from Windows, Linux, and macOS.
ericzimmerman.github.io
Collection of free Windows forensic tools for registry analysis, prefetch, event logs, shellbags, and more.
gchq.github.io
GCHQ's browser-based data analysis "Cyber Swiss Army Knife" for encoding, encryption, and data transformation.
dfir.training
Curated directory of DFIR tools, training, and resources maintained by the community.
www.sans.org
SANS guide to the six phases of incident response — preparation, identification, containment, eradication, recovery, lessons learned.
www.exterro.com
Free disk imaging and preview tool from Exterro for acquiring forensic images of drives and memory.
ghidra-sre.org
NSA-developed free and open-source reverse engineering tool suite with a decompiler for major architectures.
rada.re
Portable reverse engineering framework and disassembler with scripting, debugging, and binary patching capabilities.
x64dbg.com
Open-source x64/x32 debugger for Windows focused on malware analysis and reverse engineering.
binary.ninja
Commercial binary analysis platform with a powerful API and collaborative features for reverse engineering.
any.run
Interactive online malware sandbox for analysing suspicious files and URLs with real-time process monitoring.
hybrid-analysis.com
Free malware analysis service powered by CrowdStrike Falcon with YARA rule matching and network indicators.
unpac.me
Automated malware unpacking service supporting 100+ packers and protectors.
remnux.org
Linux distribution curated for reverse engineering and malware analysis, with 150+ pre-installed tools.
github.com
Curated list of malware analysis tools, resources, and guides maintained by the community.
wireshark.org
The world's most widely-used network protocol analyser for packet capture and deep inspection.
suricata.io
High-performance, open-source network IDS, IPS, and network security monitoring engine.
snort.org
Pioneering open-source network intrusion detection and prevention system maintained by Cisco.
pfsense.org
Open-source firewall and router platform based on FreeBSD with enterprise-grade features.
opnsense.org
FreeBSD-based open-source firewall and routing platform with modern UI and active development community.
pi-hole.net
Network-wide DNS sinkhole that blocks ads and tracking domains before they reach any device on the LAN.
mxtoolbox.com
Suite of DNS, MX, DMARC, SPF, and blacklist lookup tools for diagnosing email and domain security.
ssllabs.com
Qualys free tool for deep analysis of SSL/TLS server configurations, graded A to F.
cloudflare.com
Global network providing DDoS protection, WAF, CDN, Zero Trust access, and DNS security at scale.
netbird.io
Open-source, WireGuard-based overlay network for zero-config secure peer-to-peer connectivity.
krebsonsecurity.com
Brian Krebs's investigative security blog known for deep reporting on cybercrime and breach investigations.
schneier.com
Bruce Schneier's blog on security, privacy, and technology policy — one of the most respected voices in security.
darkreading.com
Enterprise security news covering vulnerabilities, threats, and security strategy for IT professionals.
securityweek.com
Security industry news covering breaches, vulnerabilities, malware, and enterprise security market.
thehackernews.com
High-volume cybersecurity news site covering CVEs, breaches, hacking campaigns, and security tools.
risky.biz
Weekly information security podcast and news site with high-quality interviews and briefings.
isc.sans.edu
Daily threat intelligence updates and diary posts from SANS handlers tracking live internet threats.
reddit.com
Reddit community for technical information security content — high quality signal, minimal noise.
defcon.org
The world's largest underground hacking conference, with talks published free and a year-round community.
blackhat.com
Technical security conference series focused on advanced research, with free Briefings archives.
kali.org
Debian-based Linux distribution maintained by Offensive Security and pre-loaded with hundreds of pentesting tools.
metasploit.com
World's most used penetration testing framework; exploit modules, payloads, and post-exploitation tools.
portswigger.net
Industry-standard web application security testing platform with proxy, scanner, and intruder modules.
hackthebox.com
Online platform with intentionally vulnerable machines, labs, and Pro Labs for practising real-world attack techniques.
tryhackme.com
Browser-based learning platform with guided pentesting labs covering beginner to advanced topics.
offsec.com
Training and certification provider behind OSCP, OSEP, and other hands-on security certifications.
github.com
Comprehensive collection of payloads and bypasses for web app security, useful during CTFs and penetration tests.
github.com
Curated collection of wordlists for usernames, passwords, URLs, fuzzing payloads, and more.
pentesterlab.com
Hands-on web pentesting training with real exercises, from SQL injection to deserialization.
nmap.org
Network discovery and security auditing tool — port scanning, OS fingerprinting, and service version detection.
attack.mitre.org
Globally-accessible knowledge base of adversary tactics, techniques, and procedures based on real observations.
virustotal.com
Multi-engine file and URL scanner aggregating results from 70+ antivirus engines and threat intelligence feeds.
shodan.io
Search engine for internet-connected devices — servers, IoT, industrial systems — with banner and vulnerability data.
censys.io
Internet-wide scanning service for attack surface management; maps exposed services, certs, and misconfigurations.
greynoise.io
Filters internet background noise from real threats by categorising mass-scanning and exploit-broadcasting IPs.
otx.alienvault.com
Open Threat Exchange — community-driven threat intelligence sharing platform with millions of indicators.
abuse.ch
Non-profit running MalwareBazaar, URLhaus, Feodo Tracker, and ThreatFox for free threat intelligence feeds.
circl.lu
Computer Incident Response Center Luxembourg — publishes free threat intelligence feeds, MISP, and CVE tools.
www.cisa.gov
US CISA's authoritative catalog of CVEs actively exploited in the wild, with required remediation dates for federal agencies.
misp-project.org
Open-source threat intelligence sharing platform and format standard used by hundreds of organisations globally.
nvd.nist.gov
NIST's authoritative CVE database with CVSS scores, references, and patch advisories.
cvedetails.com
CVE browsing interface with per-vendor and per-product statistics and trend charts.
Google's open database for vulnerabilities in open-source software, queryable by package.
github.com
Security advisories for packages on npm, PyPI, Maven, RubyGems, and more, curated by GitHub.
exploit-db.com
Offensive Security's archive of public exploits and shellcode, searchable by CVE or platform.
packetstormsecurity.com
Long-running archive of exploits, advisories, tools, and whitepapers.
hackerone.com
Leading bug bounty platform connecting security researchers with program-running companies.
bugcrowd.com
Crowdsourced security platform for bug bounty programs and vulnerability disclosure.
security.snyk.io
Developer-focused database of open-source package vulnerabilities with fix guidance.
vulnhub.com
Downloadable intentionally vulnerable VMs for hands-on vulnerability practice.
Security
Generated digest items for this topic.
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA syste
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS)
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of ot
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two
Good report : Executive Summary: Let's say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don't actually work for measuring AI capabilities (even when they ar
A group used Anthropic's Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple's M5. News article .
Crazy story : Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of inter
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of th
The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Blog moderation policy
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA syste
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS)
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of ot