I ran a full link check across the 339 links in the README. Summary:
|
count |
| Dead links (404/410) |
12 |
| Deleted repositories |
5 |
| Archived repositories |
17 |
| No activity in 2+ years |
54 |
On false positives. Only hard 404/410 are reported. Anything returning 403/412 (bot protection), 429 (rate limiting) or 000 (DNS/TLS failure) is excluded - on a list this size those are overwhelmingly false alarms, and a report that is half wrong is worse than no report. Every link below returned 404/410 on two separate passes, with redirects followed to the final destination. GitHub entries go through the API rather than HTTP, so a renamed or transferred repository is not mistaken for a deleted one.
Dead links (12)
Most of these cluster on a few hosts that went away wholesale:
Deleted repositories (5)
Confirmed through the GitHub API, so these are genuinely gone rather than renamed.
- curiefense/curiefense
- dtag-dev-sec/t-pot-autoinstall
- jery0843/torforge
- marcinguy/scanmycode-ce
- rozgo/anevicon
Archived repositories (17)
Still reachable, but marked read-only by their owners.
- MutableSecurity/mutablesecurity (last push 2023-02-12)
- StackExchange/blackbox (last push 2025-11-05)
- apache/incubator-spot (last push 2023-04-21)
- cloudflare/redoctober (last push 2026-05-04)
- coreb1t/awesome-pentest-cheat-sheets (last push 2024-02-16)
- csirtgadgets/massive-octo-spice (last push 2018-01-16)
- deepfence/PacketStreamer (last push 2024-07-01)
- docbleach/DocBleach (last push 2023-09-18)
- foospidy/HoneyPy (last push 2024-03-21)
- google/google-authenticator (last push 2020-09-28)
- google/rekall (last push 2020-10-18)
- google/stenographer (last push 2021-07-26)
- lyft/confidant (last push 2025-02-14)
- nbs-system/naxsi (last push 2023-11-08)
- ptswarm/reFlutter (last push 2022-04-11)
- tnich/honssh (last push 2022-01-02)
- volatilityfoundation/volatility (last push 2025-05-16)
No activity in 2+ years (54)
Not removal candidates on their own - listed so you can judge.
Show all 54
- bayandin/awesome-awesomeness (last push 2024-06-02, 33679 stars)
- carpedm20/awesome-hacking (last push 2024-06-02, 17108 stars)
- rshipp/awesome-malware-analysis (last push 2024-06-07, 14209 stars)
- k4m4/movies-for-hackers (last push 2024-08-01, 11913 stars)
- apsdehal/awesome-ctf (last push 2024-07-22, 11860 stars)
- aboul3la/Sublist3r (last push 2024-08-02, 11044 stars)
- jakejarvis/awesome-shodan-queries (last push 2024-05-27, 7746 stars)
- USArmyResearchLab/Dshell (last push 2024-05-07, 5495 stars)
- nil0x42/phpsploit (last push 2024-05-06, 2492 stars)
- cider-security-research/cicd-goat (last push 2024-07-14, 2304 stars)
- Friz-zy/awesome-linux-containers (last push 2024-04-09, 2102 stars)
- owasp/nodegoat (last push 2024-06-15, 2067 stars)
- fugue/credstash (last push 2022-02-09, 2063 stars)
- gamelinux/passivedns (last push 2024-05-28, 1735 stars)
- desaster/kippo (last push 2023-11-19, 1714 stars)
- lunasec-io/lunasec (last push 2024-05-02, 1469 stars)
- khast3x/Redcloud (last push 2022-08-24, 1278 stars)
- rfunix/Pompem (last push 2022-08-30, 1037 stars)
- correlatedsecurity/Awesome-SOAR (last push 2024-08-26, 1005 stars)
- Storyyeller/enjarify (last push 2021-11-07, 952 stars)
- marcwebbie/passpie (last push 2024-03-28, 916 stars)
- OpenSOC/opensoc (last push 2020-02-19, 585 stars)
- insidersec/insider (last push 2022-04-10, 555 stars)
- selefra/selefra (last push 2023-08-30, 545 stars)
- pfq/PFQ (last push 2019-05-02, 519 stars)
- diogo-fernan/ir-rescue (last push 2021-02-21, 488 stars)
- rafael-santiago/pig (last push 2020-11-02, 478 stars)
- spectralops/netz (last push 2021-05-11, 399 stars)
- HenryHoggard/awesome-arm-exploitation (last push 2024-01-04, 366 stars)
- tijme/angularjs-csti-scanner (last push 2021-10-20, 326 stars)
- PalindromeLabs/awesome-websocket-security (last push 2022-01-10, 314 stars)
- ironbee/ironbee (last push 2016-01-07, 303 stars)
- rusty-ferris-club/shellclear (last push 2023-05-15, 229 stars)
- dogoncouch/LogESP (last push 2023-08-24, 223 stars)
- KishanBagaria/padding-oracle-attacker (last push 2023-02-03, 219 stars)
- RIPE-NCC/hadoop-pcap (last push 2023-06-14, 216 stars)
- uptimejp/sql_firewall (last push 2015-09-23, 176 stars)
- redshiftzero/awesome-threat-modeling (last push 2024-06-28, 174 stars)
- ConradIrwin/dotgpg (last push 2018-04-04, 169 stars)
- dogoncouch/logdissect (last push 2024-08-07, 161 stars)
- spectralops/preflight (last push 2022-11-27, 156 stars)
- endgameinc/binarypig (last push 2014-07-14, 144 stars)
- v8blink/Chromium-based-XSS-Taint-Tracking (last push 2024-06-30, 127 stars)
- padok-team/cognito-scanner (last push 2024-02-16, 113 stars)
- zeroq/amun (last push 2024-05-16, 63 stars)
- marshyski/sshwatch (last push 2013-07-21, 55 stars)
- UDcide/udcide (last push 2021-06-02, 41 stars)
- corelight/zeek2es (last push 2022-08-18, 40 stars)
- rusty-ferris-club/recon (last push 2022-12-18, 37 stars)
- isgasho/finshir (last push 2019-05-08, 36 stars)
- 51j0/Android-Storage-Extractor (last push 2018-12-08, 22 stars)
- kai5263499/container-security-awesome (last push 2019-03-07, 19 stars)
- ir193/AMExtractor (last push 2016-01-10, 13 stars)
- baalmor/cve-ape (last push 2022-05-10, 4 stars)
Happy to open a PR fixing these if useful - and to re-run the check periodically, since at 339 links keeping up with rot by hand is a real burden.
Checked with link-rot-scanner, a tool I wrote for this; the methodology above is documented there.
I ran a full link check across the 339 links in the README. Summary:
On false positives. Only hard 404/410 are reported. Anything returning 403/412 (bot protection), 429 (rate limiting) or 000 (DNS/TLS failure) is excluded - on a list this size those are overwhelmingly false alarms, and a report that is half wrong is worse than no report. Every link below returned 404/410 on two separate passes, with redirects followed to the final destination. GitHub entries go through the API rather than HTTP, so a renamed or transferred repository is not mistaken for a deleted one.
Dead links (12)
Most of these cluster on a few hosts that went away wholesale:
hub.docker.com- 3 linkshttp://www.fail2ban.org/wiki/index.php/Main_Page
http://www.ntop.org/products/packet-capture/pf_ring/pf_ring-zc-zero-copy/
http://www.openvas.org/openvas-nvt-feed.html
https://cyware.com/community/ctix-feeds
https://hub.docker.com/r/kalilinux/kali-linux-docker/
https://hub.docker.com/r/remnux/metasploit/
https://hub.docker.com/r/wpscanteam/vulnerablewordpress/
https://owasp.org/www-project-application-security-verification-standard/
https://www.enisa.europa.eu/activities/cert/support/incident-handling-automation
https://www.manning.com/books/edge-computing-technology-and-applications
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
https://www.owasp.org/index.php/Testing_Checklist
Deleted repositories (5)
Confirmed through the GitHub API, so these are genuinely gone rather than renamed.
Archived repositories (17)
Still reachable, but marked read-only by their owners.
No activity in 2+ years (54)
Not removal candidates on their own - listed so you can judge.
Show all 54
Happy to open a PR fixing these if useful - and to re-run the check periodically, since at 339 links keeping up with rot by hand is a real burden.
Checked with link-rot-scanner, a tool I wrote for this; the methodology above is documented there.