Take it like a gift
Cross-site scripting cheat sheet
PortSwigger XSS cheat sheet that contains many vectors that can help you bypass WAFs and filters.
phpsploit
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor.
crowdsec
Offers crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
Security Monkey
Monitor AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.