# Bookmark This: The Web Hacking Techniques Index — Two Decades of Research, Preserved > A resource worth knowing about: webhacklist.com, the Web Hacking Techniques Index. It is a free, open archive of 1,100+ web-hacking techniques from 2006 to today — the catalogue behind the community’s annual "Top 10 Web Hacking Techniques" — each entry preserved as Markdown and PDF with Wayback backups so the research survives even when the original blog goes offline. Here is what it is, who built it, how its "Museum", Library and Time Machine views work, and how an AppSec team or security leader can actually use it. Source: https://playciso.com/blog/webhacklist-web-hacking-techniques-index-archive · Published: 2026-10-11 · Publisher: PlayCISO (https://playciso.com) Primary source: https://webhacklist.com --- Every so often a resource is good enough that the most useful thing we can do is point you straight at it. [webhacklist.com](https://webhacklist.com) — the **Web Hacking Techniques Index** — is one of those: a free, open archive of **1,100+ web-hacking techniques from 2006 to today**, each one preserved so the research doesn’t vanish when the blog that published it goes dark. To be clear up front: **PlayCISO didn’t build this**. We’re recommending someone else’s excellent work, and we’ve added it to our [Learn library](/learn) so it’s easy to find later. ## What it is For years the web-security community has nominated the year’s most innovative research and voted on a **Top 10 Web Hacking Techniques**. Jeremiah Grossman started and curated that list from 2006 to 2015; James Kettle and PortSwigger have curated it since 2016. The problem: a lot of that research lived on personal blogs and company sites that have since gone offline. webhacklist.com (maintained by Soroush Dalili, _@irsdl_, on GitHub) rebuilt the whole thing as a **preserved archive**. Its tagline says it plainly: _“Two decades of web hacking research, preserved before its hosts disappear.”_ Each technique gets a catalogue record with a **Markdown and PDF copy** and a link to the original source — and a large share were pulled back from the Wayback Machine because the original page no longer answers. That preservation is the quiet, valuable part: link rot eats security research faster than almost any other field. ## How to get around it The archive is presented through several views, which is where the **#museum** anchor you may have landed on comes in: - Investigation Board — a corkboard per year, good for seeing a single year’s standout research at a glance. - Museum — themed “exhibition rooms” that group techniques for browsing rather than searching. - Library — the “reading stacks” view for working through the catalogue. - Time Machine — research through time, ideal for watching a bug class evolve. - Signals & Constellation — a trend observatory and a relationship map that connects related techniques. - Hacker Terminal — a query console for people who’d rather search than browse. It’s free, it stays free, and browsing needs no account — a GitHub login is only needed to submit a technique or flag an inaccuracy. ## How a security team should actually use it **As a learning spine.** Pick a bug class — SSRF, HTTP request smuggling, deserialization, or the newer web-layer prompt-injection work — and read how it actually evolved year over year. You come away understanding the _shape_ of a vulnerability class, not just one CVE. **As a defence checklist.** Map the notable techniques to what your own stack exposes, then feed the ones that apply into your threat model and your test plan. “Has anyone checked whether _this_ class applies to us?” is a far better review question than “are we patched?” That second use is exactly where it plugs into the work we build here: take a technique that worries you, drop your system into the [Threat Model Studio](/tools/threat-model) to see where it would land, and — if it’s an AI-adjacent web surface — run the injection patterns through [PromptScan](/tools/promptscan). The archive tells you what attackers have figured out; the point is to check it against what you ship. For more free, curated resources like this one, the full [Learn library](/learn) is the place to browse. _Credit where it’s due: the Web Hacking Techniques Index is the work of its curators and maintainer, not PlayCISO. Details here reflect the site as of October 2026; visit [webhacklist.com](https://webhacklist.com) for the current archive._