Skip to content
🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Bookmark This: The Web Hacking Techniques Index — Two Decades of Research, Preserved

October 11, 2026 · PlayCISO
TL;DR

webhacklist.com — the Web Hacking Techniques Index — is a free, open research archive that catalogues 1,100+ web-hacking techniques from 2006 to the present. It grew out of the long-running community tradition of nominating and voting on the year’s most innovative web-hacking research: Jeremiah Grossman started and curated the annual "Top 10 Web Hacking Techniques" from 2006 to 2015, and James Kettle with PortSwigger have curated it since 2016. The archive (maintained by Soroush Dalili, @irsdl, and hosted on GitHub) was rebuilt after some of the original blog posts went offline — its tagline is "Two decades of web hacking research, preserved before its hosts disappear." Each technique has a catalogue record with a preserved Markdown and PDF copy plus links to the original source, and a large share were recovered from the Wayback Machine because the original page no longer answers. The site presents the archive through several views: an Investigation Board (a corkboard per year), a Museum of themed "exhibition rooms", a Library ("reading stacks"), a Time Machine (research through time), Signals (a trend observatory), a Constellation (a relationship map between techniques), and a Hacker Terminal query console, plus search, submissions and personal save/read tracking. It is free and stays free; browsing needs no account, and a GitHub account is only needed to submit a technique or report an inaccuracy. For AppSec engineers, pentesters and security leaders it is both a learning spine (study how a class of bug — SSRF, request smuggling, prompt injection on the web — actually evolved) and a defence checklist (map the techniques to what your own stack exposes). We have added it to the PlayCISO Learn library under Application Security, and recommend it alongside PortSwigger’s Web Security Academy and the OWASP Top 10. This is someone else’s excellent work — PlayCISO is simply pointing you to it.

This post references: https://webhacklist.com
A preserved archive of two decades of web-hacking research techniques

Every so often a resource is good enough that the most useful thing we can do is point you straight at it. webhacklist.com — the Web Hacking Techniques Index — is one of those: a free, open archive of 1,100+ web-hacking techniques from 2006 to today, each one preserved so the research doesn’t vanish when the blog that published it goes dark.

To be clear up front: PlayCISO didn’t build this. We’re recommending someone else’s excellent work, and we’ve added it to our Learn library so it’s easy to find later.

What it is

For years the web-security community has nominated the year’s most innovative research and voted on a Top 10 Web Hacking Techniques. Jeremiah Grossman started and curated that list from 2006 to 2015; James Kettle and PortSwigger have curated it since 2016. The problem: a lot of that research lived on personal blogs and company sites that have since gone offline. webhacklist.com (maintained by Soroush Dalili, @irsdl, on GitHub) rebuilt the whole thing as a preserved archive. Its tagline says it plainly: “Two decades of web hacking research, preserved before its hosts disappear.”

Each technique gets a catalogue record with a Markdown and PDF copy and a link to the original source — and a large share were pulled back from the Wayback Machine because the original page no longer answers. That preservation is the quiet, valuable part: link rot eats security research faster than almost any other field.

How to get around it

The archive is presented through several views, which is where the #museum anchor you may have landed on comes in:

  • Investigation Board — a corkboard per year, good for seeing a single year’s standout research at a glance.
  • Museum — themed “exhibition rooms” that group techniques for browsing rather than searching.
  • Library — the “reading stacks” view for working through the catalogue.
  • Time Machine — research through time, ideal for watching a bug class evolve.
  • Signals & Constellation — a trend observatory and a relationship map that connects related techniques.
  • Hacker Terminal — a query console for people who’d rather search than browse.

It’s free, it stays free, and browsing needs no account — a GitHub login is only needed to submit a technique or flag an inaccuracy.

How a security team should actually use it

As a learning spine. Pick a bug class — SSRF, HTTP request smuggling, deserialization, or the newer web-layer prompt-injection work — and read how it actually evolved year over year. You come away understanding the shape of a vulnerability class, not just one CVE.

As a defence checklist. Map the notable techniques to what your own stack exposes, then feed the ones that apply into your threat model and your test plan. “Has anyone checked whether this class applies to us?” is a far better review question than “are we patched?”

That second use is exactly where it plugs into the work we build here: take a technique that worries you, drop your system into the Threat Model Studio to see where it would land, and — if it’s an AI-adjacent web surface — run the injection patterns through PromptScan. The archive tells you what attackers have figured out; the point is to check it against what you ship. For more free, curated resources like this one, the full Learn library is the place to browse.

Credit where it’s due: the Web Hacking Techniques Index is the work of its curators and maintainer, not PlayCISO. Details here reflect the site as of October 2026; visit webhacklist.com for the current archive.

Related articles
OWASP AI Security Verification Standard (AISVS), Explained
The OWASP AI Security Verification Standard gives teams a checklist of verifiable requirements for securing AI and LLM applications. What AISVS covers, how it relates to ASVS and the LLM Top 10, and how to use it.
Reverse Engineer Anything (REA): The Trending Agent Tool, and What It Means for Defenders
REA ("Reverse Engineer Anything", github.com/morluto/rea) is an open-source MCP server that lets an AI agent reverse-engineer binaries, Electron/.NET/Android apps, websites and runtime behavior — and it is one of the most-starred repos on GitHub right now. It is a genuinely useful dual-use tool, but its pitch ("copy a feature from an app you don’t own") crosses into IP and licensing risk. Here is what it actually does, the legal line to stay on, and the part that matters whether or not you ever run it: your own software is now this easy to take apart.
Hacking Moves to the Factory: An Open-Weights Offensive-Security Model and the Economics of the Breach
A lab has released apex-flash-1, an open-weights model post-trained for cybersecurity, and framed offensive security as an economics problem: cheap capable models plus harnesses plus compute make finding and exploiting vulnerabilities a scaling exercise. The self-reported claims ($1M in bounties, #1 on the HackerOne US leaderboard, trillions of tokens a month) are the team’s own, but the trend they describe is corroborated by Anthropic’s own threat reports of largely-automated intrusion campaigns. What is claim vs. signal, why the cost-to-breach is falling, and the concrete playbook for a security leader when attack becomes industrialised.

Ready to practise the decisions these articles describe?

Run a free War Room →
Bookmark This: The Web Hacking Techniques Index — Two Decades of Research, Preserved | PlayCISO Blog · PlayCISO