RESOURCES
FILTER TAGS
WEB
OWASP Web Security Testing Guide
A structured reference for web-application and web-service security testing.
owasp.orgPortSwigger Web Security Academy
Interactive web-security learning material and labs covering common and advanced vulnerability classes.
portswigger.netOWASP Cheat Sheet Series
Concise application-security guidance covering authentication, authorization, input handling, APIs, cryptography, and defensive verification.
cheatsheetseries.owasp.org · VERIFIED 2026-08-24PortSwigger Web Security Topics
Research-backed explanations and exploitation methodology for modern web vulnerabilities, from foundational injection to advanced request and browser attacks.
portswigger.net · VERIFIED 2026-08-24PayloadsAllTheThings
Curated payloads, bypasses, methodology, and references for web application testing, privilege escalation, Active Directory, and shells.
github.com · VERIFIED 2026-08-24The Hacker Recipes
Detailed attack recipes with particularly strong coverage of Active Directory, Kerberos, NTLM, certificates, and Windows movement.
thehacker.recipes · VERIFIED 2026-08-24PentestMonkey Cheat Sheets
Compact command references for reverse shells, database-specific SQL injection, and common penetration-testing tasks.
pentestmonkey.net · VERIFIED 2026-08-24WADComs
Searchable Windows and Active Directory commands organized by what you have, where you are, and what action you need next.
wadcoms.github.io · VERIFIED 2026-08-24ired.team Offensive Notes
Technique-focused notes for Windows, Active Directory, Kerberos, lateral movement, persistence, and adversary simulation.
ired.team · VERIFIED 2026-08-24Active Directory Exploitation Cheat Sheet
Command-heavy reference for domain enumeration, credential attacks, movement, delegation, ACL abuse, and persistence.
github.com · VERIFIED 2026-08-24GTFOBins
Curated Unix binaries that can be used to escape restrictions, elevate privileges, transfer files, or obtain shell behavior when misconfigured.
gtfobins.github.io · VERIFIED 2026-08-24LOLBAS
Documented Windows binaries, scripts, and libraries with execution, download, bypass, and alternate-use behaviors.
lolbas-project.github.io · VERIFIED 2026-08-24LOLDrivers
Curated Windows drivers known to be abused for defense evasion and privilege-related attack paths, with hashes and detection context.
loldrivers.io · VERIFIED 2026-08-24Reverse Shell Generator
Searchable reverse-shell, bind-shell, listener, encoding, and payload-generation reference for multiple runtimes and operating systems.
revshells.com · VERIFIED 2026-08-24fuzzdb
Predictable attack strings, discovery patterns, regexes, and response-analysis material for testing application inputs.
github.com · VERIFIED 2026-08-24SQL Injection
Detection, UNION and blind techniques, database enumeration, file access, command execution, and dialect-specific payload families.
github.com · VERIFIED 2026-08-24Cross-Site Scripting
Context-specific XSS payloads, encodings, filter bypasses, CSP considerations, data access, and browser execution techniques.
github.com · VERIFIED 2026-08-24Cross-Site Request Forgery
Request construction, token weaknesses, SameSite behavior, method variations, content types, and cross-origin delivery patterns.
github.com · VERIFIED 2026-08-24Server-Side Request Forgery
Callback validation, localhost and private-network targeting, parser bypasses, alternate schemes, metadata, and blind SSRF.
github.com · VERIFIED 2026-08-24Server-Side Template Injection
Template-engine fingerprinting and sandbox-escape references for Jinja, Twig, FreeMarker, Pug, Handlebars, and other engines.
github.com · VERIFIED 2026-08-24OS Command Injection
Unix and Windows separators, blind timing, out-of-band confirmation, whitespace bypasses, and command-execution payloads.
github.com · VERIFIED 2026-08-24XML External Entity Injection
In-band, error-based, blind, external-DTD, parameter-entity, file-read, and SSRF-oriented XXE techniques.
github.com · VERIFIED 2026-08-24Directory Traversal and File Read
Linux and Windows traversal sequences, encoding, normalization bypasses, wrappers, file targets, and source disclosure.
github.com · VERIFIED 2026-08-24IDOR and Broken Object Authorization
Object discovery, identifier substitution, UUID collection, parameter pollution, method switching, and authorization testing.
github.com · VERIFIED 2026-08-24CORS Misconfiguration
Reflected origins, credentialed requests, null origins, parser mistakes, allowlist bypasses, and exploitation examples.
github.com · VERIFIED 2026-08-24Insecure File Upload
Extension, MIME, magic-byte, parser, filename, archive, and web-shell techniques for upload validation testing.
github.com · VERIFIED 2026-08-24NoSQL Injection
MongoDB and operator injection, authentication bypass, blind extraction, JavaScript execution, and syntax references.
github.com · VERIFIED 2026-08-24LDAP Injection
LDAP filter manipulation, authentication bypass, attribute discovery, blind extraction, escaping, and syntax differences.
github.com · VERIFIED 2026-08-24XPath Injection
Authentication bypass, boolean discovery, blind extraction, and XPath syntax for XML-backed applications.
github.com · VERIFIED 2026-08-24HTTP Request Smuggling
CL.TE, TE.CL, TE.TE, HTTP/2 downgrade, response queue poisoning, and front-end/back-end parsing discrepancies.
github.com · VERIFIED 2026-08-24HTTP Parameter Pollution
Duplicate parameter behavior across server technologies, client-side pollution, and filter-versus-backend parsing differences.
github.com · VERIFIED 2026-08-24Open Redirect
Parser edge cases, encoding, scheme-relative URLs, validation bypasses, and redirect chaining.
github.com · VERIFIED 2026-08-24OAuth Misconfiguration
Redirect URI weaknesses, state and PKCE problems, token leakage, account linking, and provider/application trust failures.
github.com · VERIFIED 2026-08-24JSON Web Token Attacks
Algorithm confusion, missing verification, key injection, JWK/JWKS abuse, claim manipulation, and cracking workflows.
github.com · VERIFIED 2026-08-24Insecure Deserialization
Serialization formats, gadget chains, detection markers, tooling, and language-specific exploitation references.
github.com · VERIFIED 2026-08-24Prototype Pollution
Client- and server-side JavaScript prototype manipulation, source/sink discovery, gadgets, and filter bypasses.
github.com · VERIFIED 2026-08-24Web Cache Poisoning and Deception
Cache-key analysis, unkeyed input, path confusion, delimiter differences, poisoning, and private-content deception.
github.com · VERIFIED 2026-08-24Race Conditions
Limit-overrun, state-transition, single-packet, session, and time-of-check/time-of-use testing patterns.
github.com · VERIFIED 2026-08-24WebSocket Vulnerabilities
Handshake manipulation, message tampering, cross-site WebSocket hijacking, authentication, and origin testing.
github.com · VERIFIED 2026-08-24GraphQL Injection and Abuse
Introspection, field suggestion, batching, alias abuse, authorization, injection, denial-of-service, and schema discovery.
github.com · VERIFIED 2026-08-24CRLF Injection
Header injection, response splitting, log injection, encoding variants, and downstream proxy behavior.
github.com · VERIFIED 2026-08-24Server-Side Include Injection
SSI directive detection, environment disclosure, file inclusion, and command execution on supported servers.
github.com · VERIFIED 2026-08-24XSLT Injection
Processor fingerprinting, file access, SSRF, extension functions, and code-execution paths in XSLT transformations.
github.com · VERIFIED 2026-08-24CSV and Formula Injection
Spreadsheet formula execution, exfiltration patterns, delimiters, encoding, and application export testing.
github.com · VERIFIED 2026-08-24SAML Injection and Signature Attacks
XML signature wrapping, assertion manipulation, identity-provider confusion, and SAML response testing.
github.com · VERIFIED 2026-08-24MySQL Injection Cheat Sheet
MySQL syntax for versioning, comments, string concatenation, conditional responses, timing, files, and command execution.
pentestmonkey.net · VERIFIED 2026-08-24MSSQL Injection Cheat Sheet
Microsoft SQL Server syntax for metadata, timing, errors, file access, linked servers, and operating-system interaction.
pentestmonkey.net · VERIFIED 2026-08-24PostgreSQL Injection Cheat Sheet
PostgreSQL syntax for metadata, type conversion, timing, files, stacked queries, and command-execution primitives.
pentestmonkey.net · VERIFIED 2026-08-24Oracle Injection Cheat Sheet
Oracle-specific comments, dual-table behavior, metadata views, timing, errors, network access, and file techniques.
pentestmonkey.net · VERIFIED 2026-08-24DB2 Injection Cheat Sheet
DB2 query syntax, metadata enumeration, comments, concatenation, conditional responses, and timing reference.
pentestmonkey.net · VERIFIED 2026-08-24Informix Injection Cheat Sheet
Informix syntax for version discovery, users, schemas, tables, comments, strings, and conditional behavior.
pentestmonkey.net · VERIFIED 2026-08-24Upgrading Simple Shells
Reliable PTY upgrade patterns, terminal settings, job control, and practical shell stabilization steps.
blog.ropnop.com · VERIFIED 2026-08-24OWASP WSTG Checklist
Spreadsheet and checklist artifacts mapped to Web Security Testing Guide identifiers for planning and coverage tracking.
github.com · VERIFIED 2026-08-24PortSwigger Complete Lab Index
Every Web Security Academy lab in one index, including mystery labs for methodology practice without knowing the vulnerability first.
portswigger.net · VERIFIED 2026-08-24OWASP API Security Top 10
Risk categories and assessment guidance for broken object authorization, authentication, resource consumption, business flows, SSRF, and API inventory.
owasp.org · VERIFIED 2026-08-24OWASP ASVS
Detailed application-security requirements useful for building test cases, remediation guidance, and coverage beyond vulnerability names.
owasp.org · VERIFIED 2026-08-24OWASP GraphQL Cheat Sheet
GraphQL input, authorization, query complexity, batching, introspection, error, and transport security guidance.
cheatsheetseries.owasp.org · VERIFIED 2026-08-24MDN HTTP Reference
Authoritative browser-oriented reference for HTTP methods, status codes, headers, cookies, caching, authentication, and cross-origin behavior.
developer.mozilla.org · VERIFIED 2026-08-24OWASP Web Service Security
Security guidance for REST and SOAP services, transport, schemas, message size, authentication, authorization, and content handling.
cheatsheetseries.owasp.org · VERIFIED 2026-08-24IDENTITY / WINDOWS
BloodHound Documentation
Official documentation for BloodHound Community Edition, collection, analysis, and identity attack-path concepts.
specterops.ioMicrosoft Active Directory DS
Primary documentation for Active Directory Domain Services concepts and administration.
learn.microsoft.comMicrosoft Kerberos Overview
Windows Kerberos components, ticket flow, delegation, authentication, and security behavior from the platform vendor.
learn.microsoft.com · VERIFIED 2026-08-24Certified Pre-Owned
Foundational SpecterOps research describing Active Directory Certificate Services escalation and persistence attack paths.
specterops.io · VERIFIED 2026-08-24ADSecurity.org
Sean Metcalf's research and defensive material on Active Directory, Kerberos, trusts, credentials, detection, and enterprise identity.
adsecurity.org · VERIFIED 2026-08-24NetExec Wiki
Protocol modules, authentication, enumeration, credential validation, databases, and command usage for NetExec.
netexec.wiki · VERIFIED 2026-08-24Certipy Wiki
Enumeration and exploitation documentation for Active Directory Certificate Services using Certipy.
github.com · VERIFIED 2026-08-24Impacket Examples
Canonical example scripts for SMB, Kerberos, NTLM, WMI, secrets, delegation, remote execution, and Windows protocols.
github.com · VERIFIED 2026-08-24AzureHound Documentation
Collection setup, permissions, authentication, and data gathering for Microsoft Entra ID attack-path analysis.
bloodhound.specterops.io · VERIFIED 2026-08-24ROADtools Wiki
Authentication, token, directory-data, and exploration documentation for Microsoft Entra ID research and assessment.
github.com · VERIFIED 2026-08-24NETWORK / EXTERNAL
MITRE ATT&CK
A common knowledge base for adversary tactics and techniques used to map and discuss observed behavior.
attack.mitre.orgNIST Cybersecurity Framework
High-level cybersecurity risk-management guidance and supporting implementation resources.
nist.govFIRST CVSS v4.0
Official CVSS v4 specification, calculator, metrics, supplemental guidance, and scoring resources.
first.org · VERIFIED 2026-08-24MITRE CWE
Software and hardware weakness definitions, relationships, consequences, mitigations, examples, and mappings.
cwe.mitre.org · VERIFIED 2026-08-24CWE Top 25
Data-driven list of widespread and consequential software weaknesses with scoring and mapping context.
cwe.mitre.org · VERIFIED 2026-08-24MITRE CAPEC
Attack-pattern descriptions with prerequisites, execution flow, consequences, mitigations, and related weaknesses.
capec.mitre.org · VERIFIED 2026-08-24CISA Known Exploited Vulnerabilities
Authoritative catalog of vulnerabilities with evidence of exploitation and remediation due-date context.
cisa.gov · VERIFIED 2026-08-24FIRST EPSS
Daily probability estimates for whether published CVEs will be exploited in the wild within the next 30 days.
first.org · VERIFIED 2026-08-24National Vulnerability Database
NIST vulnerability records, CVE enrichment, affected configurations, CVSS vectors, references, and search.
nvd.nist.gov · VERIFIED 2026-08-24Bugcrowd Vulnerability Rating Taxonomy
Living priority taxonomy for common web, API, mobile, infrastructure, hardware, and AI vulnerability classes.
bugcrowd.com · VERIFIED 2026-08-24HackerOne Severity Guidance
Platform guidance on report severity, qualitative ratings, CVSS calculator options, and program-specific scoring.
docs.hackerone.com · VERIFIED 2026-08-24OWASP Risk Rating Methodology
Structured likelihood and impact estimation for applications when a raw technical score does not tell the full story.
owasp.org · VERIFIED 2026-08-24NIST SP 800-115
Technical guide for planning, conducting, analyzing, and reporting security testing and assessment work.
csrc.nist.gov · VERIFIED 2026-08-24Penetration Testing Execution Standard
Engagement phases covering pre-engagement, intelligence, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
pentest-standard.org · VERIFIED 2026-08-24TOOLS / PLATFORMS
HackTricks
A resource to help hack almost anything.
hacktricks.wikiKali Linux Tools
An indexed reference for tools packaged with Kali, including descriptions, commands, and links.
kali.orgNmap Reference Guide
Primary reference for Nmap scanning behavior, options, output, and scripting capabilities.
nmap.orgHacking the Cloud
Cloud penetration-testing and red-team tradecraft for AWS, Azure, GCP, Terraform, containers, and identity.
hackingthe.cloud · VERIFIED 2026-08-24HackTricks Cloud
Provider and service-oriented enumeration, privilege escalation, persistence, and post-exploitation notes.
cloud.hacktricks.wiki · VERIFIED 2026-08-24CloudFox
Situational-awareness and attack-path discovery tool for unfamiliar cloud environments, with scoped enumeration workflows.
github.com · VERIFIED 2026-08-24Stratus Red Team
Granular, reproducible cloud attack techniques mapped to providers and MITRE ATT&CK tactics.
stratus-red-team.cloud · VERIFIED 2026-08-24Principal Mapper
Models AWS IAM principals and permissions to identify privilege escalation and access relationships.
github.com · VERIFIED 2026-08-24KubeHound
Kubernetes attack-path graphing for relationships between identities, workloads, permissions, and cluster resources.
github.com · VERIFIED 2026-08-24OWASP Kubernetes Top 10
Prioritized Kubernetes risks covering workload configuration, authorization, secrets, segmentation, components, and cloud movement.
owasp.org · VERIFIED 2026-08-24OWASP Kubernetes Security Testing Guide
Top-down methodology for architecture review, discovery, cluster assessment, container testing, and benchmark auditing.
owasp.org · VERIFIED 2026-08-24OWASP Kubernetes Security Cheat Sheet
Practical cluster, workload, authorization, networking, secret, and runtime security checks.
cheatsheetseries.owasp.org · VERIFIED 2026-08-24OWASP Docker Security Cheat Sheet
Common Docker security errors and controls for hosts, images, users, capabilities, sockets, secrets, and runtimes.
cheatsheetseries.owasp.org · VERIFIED 2026-08-24OWASP Mobile Application Security Testing Guide
Comprehensive Android and iOS security testing and reverse-engineering techniques mapped to mobile weaknesses and controls.
mas.owasp.org · VERIFIED 2026-08-24OWASP MASVS
Mobile application security requirements covering storage, cryptography, authentication, networking, platform, code, resilience, and privacy.
mas.owasp.org · VERIFIED 2026-08-24Mobile App Pentest Cheat Sheet
Compact Android and iOS test checklist with commands and references mapped to common mobile-security risk areas.
github.com · VERIFIED 2026-08-24MobSF Documentation
Static and dynamic analysis setup, APIs, analyzers, reports, and operational guidance for the Mobile Security Framework.
mobsf.github.io · VERIFIED 2026-08-24Frida Documentation
Dynamic instrumentation concepts, JavaScript APIs, Android, iOS, tracing, messages, modes, and examples.
frida.re · VERIFIED 2026-08-24Objection Wiki
Runtime mobile exploration workflows powered by Frida, including files, memory, storage, platform interaction, and patching.
github.com · VERIFIED 2026-08-24Android Security Best Practices
Vendor guidance for permissions, networking, WebView, storage, authentication, cryptography, and component exposure.
developer.android.com · VERIFIED 2026-08-24Aircrack-ng Documentation
Official suite reference for monitor mode, capture, packet injection, replay, access points, and WPA/WPA2 assessment.
aircrack-ng.org · VERIFIED 2026-08-24hcxtools
Packet-capture conversion and processing tools designed for Hashcat and John the Ripper wireless workflows.
github.com · VERIFIED 2026-08-24Hashcat Example Hashes
Canonical mode identifiers and test hashes for NTLM, Kerberos, WPA, archives, databases, applications, and other formats.
hashcat.net · VERIFIED 2026-08-24Bettercap Modules
Official module documentation for Wi-Fi, BLE, network discovery, proxies, packet streams, and event-driven assessment.
bettercap.org · VERIFIED 2026-08-24Kismet Documentation
Wireless discovery, capture sources, channel handling, logging, remote capture, alerts, and device tracking.
kismetwireless.net · VERIFIED 2026-08-24Hak5 WiFi Pineapple Documentation
Official WiFi Pineapple setup, campaigns, recon, captures, modules, storage, networking, and recovery documentation.
docs.hak5.org · VERIFIED 2026-08-24OWASP IoT Security Testing Guide
Methodology for IoT architecture, firmware, interfaces, communications, mobile companions, hardware, and privacy testing.
owasp.org · VERIFIED 2026-08-24OWASP Firmware Security Testing Methodology
Structured firmware assessment methodology covering acquisition, analysis, emulation, filesystem review, and dynamic testing.
github.com · VERIFIED 2026-08-24Binwalk
Firmware signature scanning, embedded-file identification, extraction, entropy analysis, and reverse-engineering support.
github.com · VERIFIED 2026-08-24FirmAE
Automated Linux-based firmware emulation and analysis for supported embedded device images.
github.com · VERIFIED 2026-08-24RouterSploit
Open-source exploitation framework for authorized assessment of embedded devices, routers, services, and credentials.
github.com · VERIFIED 2026-08-24OSINT Framework
A categorized map of public-source research tools for domains, usernames, people, infrastructure, files, images, and metadata.
osintframework.com · VERIFIED 2026-08-24IntelTechniques Search Tools
Centralized forms for public records, usernames, domains, email, social platforms, maps, and general OSINT pivots.
inteltechniques.com · VERIFIED 2026-08-24Shodan Search Query Fundamentals
Official filters and query behavior for finding exposed internet services, products, certificates, ports, networks, and organizations.
help.shodan.io · VERIFIED 2026-08-24Censys Search Language
Official field, boolean, range, existence, and structured-search syntax for hosts, certificates, and web properties.
docs.censys.com · VERIFIED 2026-08-24Google Search Operators
Primary reference for exact phrases, exclusions, site restrictions, file types, and other search refinements.
support.google.com · VERIFIED 2026-08-24GitHub Code Search Syntax
Official syntax for literal, regex, path, language, symbol, repository, organization, and boolean code searches.
docs.github.com · VERIFIED 2026-08-24Certificate Transparency Search
Public certificate-transparency lookup useful for discovering issued names, wildcard scope, and historical certificate data.
crt.sh · VERIFIED 2026-08-24urlscan.io
Historical and current page scans with requests, hosts, certificates, technologies, screenshots, and observed relationships.
urlscan.io · VERIFIED 2026-08-24Internet Archive Wayback Machine
Historical page, path, script, documentation, and asset snapshots useful for understanding earlier attack surface.
web.archive.org · VERIFIED 2026-08-24OWASP Amass Documentation
Asset-discovery concepts and configuration for DNS enumeration, graphing, data sources, tracking, and attack-surface mapping.
owasp-amass.github.io · VERIFIED 2026-08-24Subfinder Documentation
Passive subdomain discovery configuration, providers, inputs, outputs, recursion, filtering, and workflow integration.
docs.projectdiscovery.io · VERIFIED 2026-08-24Assetnote Wordlists
Continuously generated content-discovery and technology-specific wordlists derived from real-world web data.
wordlists.assetnote.io · VERIFIED 2026-08-24Nmap NSE Documentation
Searchable documentation for Nmap Scripting Engine categories, arguments, outputs, and protocol-specific checks.
nmap.org · VERIFIED 2026-08-24HackTricks Network Services
Enumeration and testing notes organized by common TCP and UDP services and their usual weaknesses.
hacktricks.wiki · VERIFIED 2026-08-24SecLists
Discovery, fuzzing, usernames, passwords, URLs, patterns, payloads, and protocol wordlists for authorized assessment work.
github.com · VERIFIED 2026-08-24SearchSploit Manual
Local Exploit-DB searching, path copying, mirror inspection, Nmap XML integration, and result filtering.
exploit-db.com · VERIFIED 2026-08-24Exploit Database
Public proof-of-concept archive and searchable vulnerability research maintained by OffSec.
exploit-db.com · VERIFIED 2026-08-24Metasploit Documentation
Modules, payloads, sessions, workspaces, databases, development, and safe framework usage documentation.
docs.metasploit.com · VERIFIED 2026-08-24Nuclei Templates
Community-curated vulnerability, exposure, misconfiguration, technology, and DAST templates for the Nuclei engine.
github.com · VERIFIED 2026-08-24testssl.sh
Command documentation and test coverage for TLS protocols, ciphers, certificates, vulnerabilities, and HTTP security headers.
github.com · VERIFIED 2026-08-24ssh-audit
SSH server and client auditing for algorithms, key sizes, versions, security recommendations, and known weaknesses.
github.com · VERIFIED 2026-08-24ffuf
Fast web fuzzing syntax for paths, virtual hosts, parameters, POST bodies, recursion, matchers, filters, and replay proxies.
github.com · VERIFIED 2026-08-24Feroxbuster Documentation
Recursive content discovery, filters, collection methods, configuration, state, proxying, and wordlist usage.
epi052.github.io · VERIFIED 2026-08-24curl Manual
Complete request construction reference for headers, cookies, authentication, proxies, certificates, uploads, protocols, and debugging.
curl.se · VERIFIED 2026-08-24Wireshark Display Filter Reference
Searchable protocol-field reference for precise display filters and packet-analysis evidence.
wireshark.org · VERIFIED 2026-08-24TRAINING / REFERENCES
TryHackMe
Hands-on cyber security training through real-world scenarios.
tryhackme.comHack The Box Academy
Develop your skills with guided training and prove your expertise with industry certifications. Become a market-ready cybersecurity professional.
hackthebox.com/Web Security Academy
Free, online web security training from the creators of Burp Suite.
portswigger.netHISYD OSWA Field Manual
Online WEB-200 methodology, nine vulnerability playbooks, searchable notes, downloadable Markdown checklists, evidence guidance, and reporting references.
PentesterLab
Focused web-security exercises organized around specific vulnerability classes and code-level understanding.
pentesterlab.com · VERIFIED 2026-08-24OffSec Proving Grounds
Standalone penetration-testing machines for enumeration, exploitation, privilege escalation, and exam-style practice.
offsec.com · VERIFIED 2026-08-24VulnHub
Downloadable intentionally vulnerable virtual machines for local, isolated penetration-testing practice.
vulnhub.com · VERIFIED 2026-08-24OverTheWire
Progressive command-line, Linux, web, cryptography, and exploitation challenges delivered as focused wargames.
overthewire.org · VERIFIED 2026-08-24pwn.college
Browser-accessible technical modules covering computing foundations, system security, web, software exploitation, and defense.
pwn.college · VERIFIED 2026-08-24OWASP Juice Shop
Modern intentionally insecure application with broad OWASP coverage, challenges, score tracking, and multiple deployment options.
owasp.org · VERIFIED 2026-08-24OWASP WebGoat
Guided lessons demonstrating common application vulnerabilities and their defensive fixes in a controlled environment.
owasp.org · VERIFIED 2026-08-24OWASP crAPI
Intentionally vulnerable API application designed around modern API-security risks and realistic business flows.
owasp.org · VERIFIED 2026-08-24DVWA
Compact PHP and MariaDB application for practicing common web vulnerabilities at configurable difficulty levels.
github.com · VERIFIED 2026-08-24Game of Active Directory
Free multi-domain Active Directory lab designed for practicing common domain, trust, delegation, ADCS, and movement techniques.
orange-cyberdefense.github.io · VERIFIED 2026-08-24CloudFoxable
Terraform-deployed AWS environment with gamified attack paths for learning cloud enumeration and privilege relationships.
github.com · VERIFIED 2026-08-24flaws.cloud
AWS security challenge series built around common storage, identity, metadata, and service misconfigurations.
flaws.cloud · VERIFIED 2026-08-24Kubernetes Goat
Intentionally vulnerable Kubernetes environment with scenarios covering workloads, secrets, RBAC, networking, and cluster risks.
github.com · VERIFIED 2026-08-24WRITEUPS / NOTES
VM-Notes
Notes for setting up and managing my virtual machines
HISYD / IDENTITYBloodHound
Attack-path analysis, collection concepts, graph thinking, and practical notes for reviewing Active Directory relationships.
HISYD / IDENTITYBurp Suite
Proxy-driven web testing workflow, request inspection, Repeater habits, scope control, and keeping evidence organized.
HISYD / WEBNmap
Host and service discovery, scan planning, output formats, and turning raw enumeration into useful testing notes.
HISYD / NETWORKWireshark
Packet-analysis workflow, display-filter habits, capture review, and extracting evidence without getting lost in the noise.
HISYD / TRAFFICOWASP ZAP
My ZAP workflow for manual request testing, fuzzing, session handling, evidence capture, and using automation without letting it replace analysis.
NetExec
My NetExec notes for scoped protocol enumeration, credential validation, parsing results, and avoiding unnecessary authentication noise.
Certipy and ADCS
My Certipy notes for enumerating Active Directory Certificate Services, validating ESC paths, requesting certificates, and preserving the evidence that proves the issue.
Impacket
My Impacket notes for choosing the right example script, handling credential formats, troubleshooting Kerberos, and documenting remote-protocol activity.
Responder
My Responder notes for controlled LLMNR, NBT-NS, and mDNS assessment, capture handling, relay prerequisites, and reducing disruption.
HISYD / INTERNAL · VERIFIED -08-24Hashcat
My Hashcat notes for identifying the correct mode, cleaning inputs, building bounded attacks, reading status, and preserving reproducible results.
WiFi Pineapple MK VII
My WiFi Pineapple notes for recon, campaign scoping, captures, client testing, storage, and keeping radio work controlled.
Android Testing Stack
My Android notes for ADB, emulators, proxying, certificates, split APKs, static analysis, runtime inspection, and evidence collection.
External Crypto Triage
My testssl.sh and ssh-audit notes for turning protocol output into accurate, consolidated findings with practical remediation.
Google Dorks / Search Operators
A scope-first reference for search operators, reusable query recipes, result validation, evidence habits, and primary reconnaissance sources.
HISYD / RECON · VERIFIED 2026-08-25