Security Testing
Resources & Payloads
A comprehensive collection of security testing resources and payloads for authorized penetration testing, bug bounty research, and security education. Documentation for the OWASP Hunting project.
Vulnerability Categories
32 payload classes organized by attack category
What’s inside
Organized payload collections across 30+ vulnerability classes, with testing context and methodology.
Testing methodology, tooling guidance, and structured approaches to web application security.
Attack vectors, indicators, detection guidance, and mitigation strategies for each vulnerability.
Search across payloads, documentation, and methodology with keyboard-first navigation.
Contributing is encouraged. Content lives in the upstream OWASP Hunting repository.
All content oriented toward authorized testing, responsible disclosure, and defense.
Source Repositories
This documentation covers the OWASP Hunting project. Payloads and content originate from the upstream repository.
Who this is for
- Penetration testers conducting authorized assessments
- Bug bounty hunters working in-scope programs
- Security engineers building defensive tooling
- Students learning web application security
- Researchers studying vulnerability classes
- Open-source security contributors
Responsible Use
All content is intended for authorized testing only. Use these resources responsibly.
- Systems you own or have explicit written permission to test
- Authorized bug bounty programs with defined scope
- Educational labs and controlled environments