Resources
Pentesting / Red Team
Linux Persistence
Web App Sec
Rev Engineering / Pwn
Malware Analysis
Threat Hunting
DFIR
Certifications
OSINT / Recon
Network Security
Hardware
Aviation / Auto Cyber
Crypto / Stego
Homelab / Infra
CTF Platforms
Foundations
Penetration Testing / Offensive / Red Team
- PentesterLab — Exercises
- Pentest Everything — Writeups
- Rowbot's PenTest Notes — Pre-engagement
- Pentesting Notes (Incendium)
- Reverse Shell Generator (revshells)
- Webhook.site
- FuzzySecurity — Windows Privilege Escalation
- Hacking Articles - PenTesting
- SysReptor — Pentest reporting platform Markdown is best
- Tradecraft Garden — PIC / implant research
- Atomic Red Team
- Metasploit — Exploitation framework
- msfvenom — Payload & shellcode generator
- Sliver — Cross-platform C2 framework
- Realm (Spellshift) — Adversary emulation framework
- Ligolo-ng — Tunneling & pivoting tool
- NetExec — Network service exploitation (ex-CrackMapExec)
- Hydra — Network login brute-forcer
- CUPP — Common User Passwords Profiler
- SecLists — Wordlists for security testing
- LinPEAS — Linux privesc enumeration
- WinPEAS — Windows privesc enumeration
- LinEnum — Linux enum & privesc checks
- HackTricks — Pentest methodology wiki / bible Most-referenced wiki in the field
- PayloadsAllTheThings — Payload & technique cheatsheets Same author as Internal All The Things
- GTFOBins — Linux living-off-the-land binaries
- LOLBAS — Windows living-off-the-land binaries
- BloodHound (CE) — Active Directory attack-path mapping The AD tool
- Impacket — AD / network protocol toolkit secretsdump, psexec, etc.
- Responder — LLMNR/NBT-NS poisoning
Linux Persistence & Post-Exploitation
- Threat Hunting Blog — pberba (Linux persistence series) Whole series lives here
- Internal All The Things — Linux Persistence
- 9 Ways to Backdoor a Linux Box
- My Methods To Achieve Persistence (flaviu.io)
- Linux Persistence Mechanisms & How to Find Them
- Hunting for Persistence in Linux Pt.2
- Linux Threat Hunting Persistence (0xMatheuZ) My Actual Goat for Linux threat hunting
Web Application Security
- Hacksplaining — XSS/prevention
- vulnbank — Vulnerable app Good target to practice on.
- Burp Suite — Web proxy & scanner
- Caido — Lightweight web pentest proxy 'The new burp suite'
- OWASP ZAP — Web app scanner & crawler
- sqlmap — Automated SQL injection tool Great for dumping databases for any SQL
- dalfox — Fast XSS scanner
- feroxbuster — Content/directory brute-forcer Good for recursion and large websites
- ffuf — Fast web fuzzer My Favorite
- Arjun — HTTP parameter discovery
- WPScan — WordPress vulnerability scanner
- droopescan — Drupal/SilverStripe CMS scanner
- PortSwigger Web Security Academy — Free web hacking course Best-in-class, pairs with Burp
- OWASP Web Security Testing Guide (WSTG) The testing standard
- OWASP Top 10
Reverse Engineering / Binary Exploitation / Pwn
- pwn.college My actual GOAT
- ROP Emporium Hard — very.
- Exploit Education — Phoenix
- Crackmes.one
- Microcorruption Great for Embedded (eCTF)
- Ghidra — NSA reverse engineering suite (free) Free + strong decompiler
- IDA (Hex-Rays) — Industry-standard disassembler Pro is expensive, Free tier exists
- Binary Ninja — Modern disassembler / decompiler Student disc. = personal license for $75
- dnSpy (dnSpyEx fork) — .NET debugger & assembly editor For .NET malware / crackmes
- x64dbg — Windows debugger
- Cutter — Free Rizin/Ghidra-backed RE GUI
- Decompiler Explorer (dogbolt) Great to compare different rev. tools
- Compiler Explorer (godbolt) Great for visuals
- Frida — Dynamic instrumentation
- LLDB Tutorial
- GDB Online Debugger Use Pwndbg — tons of plugins for GDB like 'GEF' and 'PEDA'
- rvcodec.js — RISC-V encoder/decoder
- Linux Syscalls — syscall.sh / x64.syscall.sh Super useful when writing/reading ASM
- C Standard Library Reference
- pwntools — CTF / exploit-dev framework Big one for pwn
- Nightmare — Free intro-to-advanced pwn/RE course
Malware Analysis
- Malware-Traffic-Analysis.net — Training
- Hunting Rootkits with eBPF (Aqua)
- strace — Trace system calls & signals Very useful tool to learn
- REMnux — Linux distro for malware analysis
- FLARE-VM — Windows malware analysis VM (Mandiant)
- CAPE Sandbox — Automated malware sandbox
- INetSim — Fake network services for dynamic analysis
- CAPA — Detect capabilities in executables (Mandiant)
- Detect It Easy (DIE) — Packer / PE identification
- PEStudio — Static PE triage
- oletools — Analyze malicious Office documents
- System Informer — Process / handle inspection (ex-Process Hacker)
- Sysinternals — ProcMon, Autoruns, Process Explorer The Goat
Threat Hunting / Detection
Digital Forensics / DFIR
- Volatility — Memory forensics
- Autopsy — GUI digital forensics platform Beginner friendly
- The Sleuth Kit — CLI disk / file-system forensics
- FTK Imager — Forensic disk imaging & acquisition Beginner friendly
- KAPE — Artifact collection & parsing (Kroll)
- Eric Zimmerman's Tools — Windows artifact parsers
- Plaso / log2timeline — Super-timeline generation
- RegRipper — Windows registry forensics
- DBAN — Darik's Boot and Nuke (disk wipe)
- Hiren's BootCD PE
- HDDSuperClone
- Disk Drill — Data recovery
Certifications
- TCM Security — Certifications (PNPT, PJPT, PSAA, etc.) Not half bad
- Invoke RE — Malware analysis & reverse engineering certs Great for RE
- Hack The Box — Certifications (CPTS, CBBH, CDSA) Best bang for your buck
- TryHackMe — Certifications (PT1, SAL1) It exists
- Zero-Point Security — Red Team Ops (CRTO / CRTO II) Uses Cobalt Strike. Great — many club members hold it.
- Zero-Point Security — Red Team Lead (CRTL)
- OffSec — Certifications (OSCP, OSEP, OSED) Overpriced and overhyped
- CompTIA Security+ Good for Gov.
- Cisco — Certifications (CCNA / CyberOps) Good if you love networking
OSINT / Recon
Network Security
Hardware / Firmware
- Das U-Boot — Bootloader docs
- J1939 PGN CAN ID converter (automotive/CAN bus) Good for semi-truck stuff
Aviation / Automotive / Drone Cyber
- CyberTruck Challenge Great program — went last summer 2025. You get selected and it's all paid for; expect ~60 hrs of work that week.
- CyberDrone Challenge Great program — same format as CyberTruck Challenge.
- Aerospace Hacking Tools (g4lxy)
Crypto / Encoding / Stego
Homelab / Infrastructure
- Proxmox VE — Virtualization & VM/container host The best bare-metal hypervisor, no doubt
- Apache Guacamole — Clientless remote desktop gateway VNC is trash — use Guac
- Pangolin — Self-hosted WireGuard reverse-proxy tunnel Super cool and useful for homelabs
- Tailscale — WireGuard-based mesh VPN The Goat
- Terraform — Infrastructure-as-code provisioning How we make labs — great for automating things.
- OpenTofu — Open-source Terraform fork (IaC)
- Ansible — IT automation & orchestration Great for all other uses — basically SSH to run commands
- Salt — Infra automation & config management Great when upstream is blocked — master reaches down to its 'minions'. The cyber range uses this.
CTF / Competitions / Practice Platforms
- CTFtime Great for finding a CTF to do
- National Cyber League — Cyber Skyline Great beginner CTF
- NSA Codebreaker Challenge Low-level RE. Resources page has free materials.
- The CTF Primer — CyLab Notes from CyLabs
- Cylab-Academy The new picoCTF
- HackTheBox Academy My Goat
- TryHackMe — Guided hands-on rooms & learning paths Lots of free content — but HTB is better
- TitanTurtles Cybersecurity Club Cyber Patriot images
- VulnHub — Downloadable vulnerable VMs
- IppSec — Searchable index of HTB walkthrough videos
Foundations / Programming Support
- Boot.dev — Courses / Git Expensive but good
- Codedex Little pixelated game (costs money)
- NandGame — Build a computer from scratch If you hate yourself
- Carbon — Code screenshots Used for slides sometimes
- Nand2Tetris — Build a working computer from NAND gates up
- Linux Journey — Free intro to Linux fundamentals
- Exercism — Free practice in 70+ languages w/ mentoring