Awesome Hacking: Curated Security Resource Lists
Awesome Hacking is a link table pointing to other security awesome-lists, not a course or a toolset of its own. Reach for it when you already know your niche - fuzzing, OSINT, red teaming - and just want the known list for it without a web search. Skip it if you want one vetted, annotated resource: nothing here is graded, and each linked list's quality is out of Hack-with-Github's hands.
What is the Awesome Hacking collection?
Awesome Hacking is a GitHub repository maintained by the Hack-with-Github organization that links out to other curated security lists rather than hosting original content. Entries sit in two tables - primary 'Awesome Repositories' covering full niches like fuzzing or OSINT, and 'Other Useful Repositories' for standalone tools like GTFOBins or SecLists - each with a one-line description.
Key Security Topics Covered
- ✓Dedicated entries for major niches - Android Security, Bug Bounty, Fuzzing, OSINT, Reversing, Web Hacking - each linking to a separate, deeper awesome-list repo.
- ✓Covers verticals most generalist lists skip: Cellular Hacking (3G/4G/5G research), Mainframe Hacking, Vehicle Security, and Industrial Control System Security.
- ✓A Prompt Injection entry links out to a list tracking vulnerabilities in AI and LLM systems, alongside long-standing categories like malware analysis.
- ✓The 'Other Useful Repositories' table holds standalone tools instead of more lists - GTFOBins, CyberChef, SecLists, and PayloadsAllTheThings among them.
- ✓CI/CD Attacks and DevSecOps entries point to software-supply-chain security resources, not just classic host or network pentesting.
- ✓Cross-references let you move between adjacent categories - Bug Bounty, Pentest, Reversing, Web Hacking - inside the same table.
Who benefits from this resource?
Awesome Hacking suits someone who already has a security niche in mind - a pentester who wants the current OSINT list, a red teamer building out a CI/CD attack chain, a researcher checking what exists on vehicle security - and just needs the fastest route to the right repo. It's a weak fit for total beginners: there's no glossary, no ordering, and no 'start here' path, so a structured course or bootcamp list serves that reader better.
Strengths
- ✓Splits entries into a primary list-of-lists table and a secondary table of standalone tools, so GTFOBins and CyberChef aren't buried inside meta-lists.
- ✓Covers niches that rarely sit in one place - cellular hacking, mainframe pentesting, and vehicle security next to mainstream OSINT and web hacking.
- ✓CC0-1.0 licensing means you can drop the table into an internal wiki or training deck with no attribution required.
- ✓Current enough to include a Prompt Injection entry for AI-targeted attacks alongside decades-old categories like fuzzing.
- ✓Every row links straight to the source repo - one click, not a summary of one.
What are the limitations of this curated list?
- △No annotation beyond a one-line description per entry - Awesome Hacking alone can't tell you whether a linked list is current or stale.
- △Both tables are flat, with no tags or subcategories inside them, so finding your niche means scanning row by row.
- △No suggested reading order. A beginner to reverse engineering gets a link, not a starting point.
- △Coverage quality depends entirely on each external repo's own maintainer, not on Hack-with-Github, since nothing here gets re-checked.
Other comprehensive security resource lists
Frequently Asked Questions
Awesome Hacking covers dozens of security niches - Android security, bug bounty hunting, fuzzing, OSINT, reverse engineering, malware analysis, ICS security, vehicle hacking, and a newer Prompt Injection entry for AI systems.
Awesome Hacking works best as a reference once you already know a topic's vocabulary. It has no learning order or explanations, so total beginners should start with a structured course first.
Awesome Hacking accepts contributions through pull requests, following the guidelines laid out in the repository's contributing.md file.
Awesome Hacking links to other GitHub awesome-lists plus standalone tools - wordlist collections like SecLists, payload references like PayloadsAllTheThings, and the OWASP Cheat Sheet Series.
Awesome Hacking is released under the CC0-1.0 license, which places it in the public domain with no attribution required.
Best use cases
- •Starting a reading list for a niche you're moving into, like ICS or cellular security, without hunting for the right repo name first.
- •Building an internal team wiki of further-reading links without doing the original curation yourself.
- •Checking whether a niche awesome-list already exists before starting your own from scratch.
- •Pulling up practitioner references fast - PayloadsAllTheThings, GTFOBins, SecLists - during an actual engagement.
