h4cker: a link collection that never cuts a release
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
At a glance
- What is it?
- h4cker is a MIT-licensed index of cybersecurity references, labs and tools maintained by Omar Santos, organized around a domain taxonomy with exam material kept deliberately separate. Its weakness is not content but currency: it points outward at thousands of external resources, publishes no versions, and has at least one root directory the overview never mentions.
- Who is it for?
- Use it as a router into a domain you are already working in, especially alongside the books and courses it supports, and expect to supply your own ordering. Do not treat it as a standalone curriculum or as a pinned reference, because there is no release to pin and every link points outward where the project has no control.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- Mainly Jupyter Notebook, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
threat_hunting/ sits in the root but never in the overview
The directory overview in the root README walks through five areas: cybersecurity-domains, ai, certifications, build-your-own-lab, and training-reference. The root also holds a threat_hunting/ directory, and it is not mentioned anywhere in that walkthrough. For a repository whose entire value proposition is that you can find the right folder quickly, an unlisted root folder is a real gap. Someone looking for detection engineering material has to already know the folder exists before it can help them, and the one page built to route people does not route them there. Nothing in the repository explains whether threat_hunting/ is a landing page, a collection, or a pointer. If you navigate this project by its overview, check the root yourself rather than assuming the overview is complete.
The default branch is master and there is nothing to install
The default branch is master, not main, which matters the moment you script against the repository or pin a commit. Beyond that, the project has no GitHub releases at all. There is no version number to track, no changelog entry, and no tag to install from. That is a coherent choice for a link and reference collection, and it also means content keeps changing with no version boundary at all: the last push was 29 September 2026. If you want a stable snapshot for study notes, a course handout, or an internal wiki, you have to record a commit hash yourself on the day you copy anything. Nothing here promises that a path you linked to last month resolves to the same page today, because the project is not versioned and never was.
The primary language is Jupyter Notebook but the root is links
The repository's primary language is reported as Jupyter Notebook, yet the root of the tree is built from directories of reference material, a CONTRIBUTING.md, a LICENSE, a README, a TOML configuration file, and a single Python script. That gap tells you something real about the shape of the content. What is collected here is index material and instructional text rather than one runnable notebook project, so a language statistic computed across the tree gets dominated by a handful of notebooks sitting inside the domain folders. Do not read the language label as a prediction about what you will find when you browse. The signal worth trusting is the directory taxonomy, and the only place that taxonomy is written down is the root README.
cybersecurity-domains/ is the spine and the rest sit beside it
The root README calls cybersecurity-domains/ the main domain taxonomy, and it carries fundamentals, offensive security, defensive security, application security, cloud and container security, infrastructure and network security, cryptography and PKI, hardware and embedded security, governance/risk/compliance, and labs/practice. The other five directories sit beside that folder at the root rather than inside it, so certifications/ and training-reference/ are peers of the taxonomy instead of children of it. The split is deliberate and it does achieve its stated purpose, keeping exam preparation out of the broader domain tree. It also means a study path that crosses a domain and a certification has to jump between two top level folders, and the project offers no map that says which jump to make first.
It is positioned as supplemental material for someone else's course
The project states its own role directly: it is supplemental material for books, video courses, and live training created by Omar Santos, who also maintains it. That framing has consequences for how you should treat what you find. It is a companion index, not a curriculum with a beginning, and the intended sequence lives in the courses rather than in the repository. There is no difficulty ordering, no prerequisite marking between the ten domains, and no statement about which entries are current and which are historical. If you are working through a book or a course, this is a good place to expand one topic at a time. If you are trying to learn a domain starting from nothing, the collection gives you breadth without a route through it, and building that route becomes your job.
No releases means a link collection ages one dead pointer at a time
The absence of releases is the central practical risk for a collection like this, and it compounds with the outward pointing nature of the content. Every pointer here leads somewhere the project does not control: a tool page, a certification track, an O'Reilly resource, a curated list of people and projects worth following, an organized tool index. When any of those targets moves, the link rots and nothing inside the repository signals it, because there are no release notes recording that a path was repointed. The last push on 29 September 2026 shows work is still happening, which helps with additions and does nothing for removals. Treat any specific link you plan to depend on as something to verify, and keep a local copy of what you actually rely on.
MIT licensed, one named maintainer, one contact route
The license is MIT, so the material can be reused, modified, and redistributed with attribution, and there is no copyleft obligation to track downstream changes. Maintenance is attributed to one named person, Omar Santos, and the only contact route given is a LinkedIn profile. Contribution guidelines live in CONTRIBUTING.md, and the root README does not summarize them, so the mechanics of adding a resource or correcting a taxonomy entry are invisible from the front page. A single maintainer curating a collection this size has a predictable shape: additions land when there is time, and a directory nobody revisits stays wrong until someone reports it. MIT settles the licensing question and settles nothing about review.
hackerrepo.org and h4cker are two names for the same project
The homepage field points to hackerrepo.org, the repository sits under an organization named The-Art-of-Hacking with a repository named h4cker, and the project description also sends people to hackertraining.org. Three identifiers for one body of work costs real time when you are searching for it. The two spellings h4cker and hacker are close enough that unrelated results land in the same column, and the same is true of the two domains. The practical approach is to treat the GitHub organization as the canonical location, treat the sites as pointers, and bookmark the full repository path rather than a display name. It also means that when something changes, you have more than one place to look before you conclude that nothing did.
Editorial conclusion
Use it as a router into a domain you are already working in, especially alongside the books and courses it supports, and expect to supply your own ordering. Do not treat it as a standalone curriculum or as a pinned reference, because there is no release to pin and every link points outward where the project has no control. Before you rely on it, verify three things yourself: that the root README still describes the folder layout you navigate by, that any specific external link you intend to depend on still resolves, and that the material has not drifted out of date relative to your own training needs.
Frequently asked questions
Who is the No.1 hacker, in the h4cker collection?
The project does not rank anyone, and it does not claim a single top figure. It is a curated collection of cybersecurity references and training resources maintained by Omar Santos, covering offensive security, defensive security, application security, cloud and container security, cryptography and PKI, and other domains.
Can hackers see your screen, and does h4cker address it?
The project does not address that question directly. Its coverage is organized by domain rather than by attacker capability, and the taxonomy in cybersecurity-domains/ covers fundamentals, offensive and defensive security, application security, cryptography and PKI, and labs and practice.
What is the goal of a white hat hacker, in h4cker's terms?
The project points at that material rather than answering it in one place. Ethical hacking and bug bounties appear in the project description, and offensive security, defensive security, and certifications including CompTIA, ISC2, Cisco SCOR, and Kubernetes and CNCF tracks are separated into their own directories.
How can I check if I am hacked, using the h4cker layout?
There is a threat_hunting/ directory at the repository root, though the root README's directory overview does not mention it. Defensive security is a domain inside cybersecurity-domains/, and build-your-own-lab/ is described as a root level section for lab building and cyber range resources.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/the-art-of-hacking-h4cker)