RESOURCES

01

WEB

GUIDE

OWASP Web Security Testing Guide

A structured reference for web-application and web-service security testing.

WEBAPI
owasp.org
TRAINING

PortSwigger Web Security Academy

Interactive web-security learning material and labs covering common and advanced vulnerability classes.

WEBAPI
portswigger.net
CHEAT SHEETS

OWASP Cheat Sheet Series

Concise application-security guidance covering authentication, authorization, input handling, APIs, cryptography, and defensive verification.

WEBAPIDEFENSE
cheatsheetseries.owasp.org · VERIFIED 2026-08-24
TECHNIQUE LIBRARY

PortSwigger Web Security Topics

Research-backed explanations and exploitation methodology for modern web vulnerabilities, from foundational injection to advanced request and browser attacks.

WEBAPIOSWA
portswigger.net · VERIFIED 2026-08-24
PAYLOAD LIBRARY

PayloadsAllTheThings

Curated payloads, bypasses, methodology, and references for web application testing, privilege escalation, Active Directory, and shells.

WEBINTERNALPAYLOADS
github.com · VERIFIED 2026-08-24
TECHNIQUE LIBRARY

The Hacker Recipes

Detailed attack recipes with particularly strong coverage of Active Directory, Kerberos, NTLM, certificates, and Windows movement.

ADINTERNALWINDOWS
thehacker.recipes · VERIFIED 2026-08-24
CHEAT SHEETS

PentestMonkey Cheat Sheets

Compact command references for reverse shells, database-specific SQL injection, and common penetration-testing tasks.

WEBDATABASESHELLS
pentestmonkey.net · VERIFIED 2026-08-24
INTERACTIVE CHEAT SHEET

WADComs

Searchable Windows and Active Directory commands organized by what you have, where you are, and what action you need next.

ADWINDOWSINTERNAL
wadcoms.github.io · VERIFIED 2026-08-24
FIELD NOTES

ired.team Offensive Notes

Technique-focused notes for Windows, Active Directory, Kerberos, lateral movement, persistence, and adversary simulation.

ADWINDOWSRED-TEAM
ired.team · VERIFIED 2026-08-24
CHEAT SHEET

Active Directory Exploitation Cheat Sheet

Command-heavy reference for domain enumeration, credential attacks, movement, delegation, ACL abuse, and persistence.

ADINTERNALOSCP
github.com · VERIFIED 2026-08-24
LIVING OFF THE LAND

GTFOBins

Curated Unix binaries that can be used to escape restrictions, elevate privileges, transfer files, or obtain shell behavior when misconfigured.

LINUXPRIVESCPOST-EXPLOIT
gtfobins.github.io · VERIFIED 2026-08-24
LIVING OFF THE LAND

LOLBAS

Documented Windows binaries, scripts, and libraries with execution, download, bypass, and alternate-use behaviors.

WINDOWSPOST-EXPLOITDEFENSE
lolbas-project.github.io · VERIFIED 2026-08-24
DRIVER REFERENCE

LOLDrivers

Curated Windows drivers known to be abused for defense evasion and privilege-related attack paths, with hashes and detection context.

WINDOWSDRIVERSDEFENSE
loldrivers.io · VERIFIED 2026-08-24
SHELL GENERATOR

Reverse Shell Generator

Searchable reverse-shell, bind-shell, listener, encoding, and payload-generation reference for multiple runtimes and operating systems.

SHELLSWINDOWSLINUX
revshells.com · VERIFIED 2026-08-24
FUZZING DATA

fuzzdb

Predictable attack strings, discovery patterns, regexes, and response-analysis material for testing application inputs.

WEBFUZZINGPAYLOADS
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

SQL Injection

Detection, UNION and blind techniques, database enumeration, file access, command execution, and dialect-specific payload families.

WEBSQLIDATABASEOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Cross-Site Scripting

Context-specific XSS payloads, encodings, filter bypasses, CSP considerations, data access, and browser execution techniques.

WEBXSSCLIENT-SIDEOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Cross-Site Request Forgery

Request construction, token weaknesses, SameSite behavior, method variations, content types, and cross-origin delivery patterns.

WEBCSRFAUTHOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Server-Side Request Forgery

Callback validation, localhost and private-network targeting, parser bypasses, alternate schemes, metadata, and blind SSRF.

WEBSSRFCLOUDOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Server-Side Template Injection

Template-engine fingerprinting and sandbox-escape references for Jinja, Twig, FreeMarker, Pug, Handlebars, and other engines.

WEBSSTIRCEOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

OS Command Injection

Unix and Windows separators, blind timing, out-of-band confirmation, whitespace bypasses, and command-execution payloads.

WEBCOMMAND-INJECTIONRCEOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

XML External Entity Injection

In-band, error-based, blind, external-DTD, parameter-entity, file-read, and SSRF-oriented XXE techniques.

WEBXXEXMLOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Directory Traversal and File Read

Linux and Windows traversal sequences, encoding, normalization bypasses, wrappers, file targets, and source disclosure.

WEBTRAVERSALFILE-READOSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

IDOR and Broken Object Authorization

Object discovery, identifier substitution, UUID collection, parameter pollution, method switching, and authorization testing.

WEBAPIIDOROSWA
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

CORS Misconfiguration

Reflected origins, credentialed requests, null origins, parser mistakes, allowlist bypasses, and exploitation examples.

WEBAPICORS
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Insecure File Upload

Extension, MIME, magic-byte, parser, filename, archive, and web-shell techniques for upload validation testing.

WEBFILE-UPLOADRCE
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

NoSQL Injection

MongoDB and operator injection, authentication bypass, blind extraction, JavaScript execution, and syntax references.

WEBAPINOSQL
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

LDAP Injection

LDAP filter manipulation, authentication bypass, attribute discovery, blind extraction, escaping, and syntax differences.

WEBLDAPAD
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

XPath Injection

Authentication bypass, boolean discovery, blind extraction, and XPath syntax for XML-backed applications.

WEBXPATHXML
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

HTTP Request Smuggling

CL.TE, TE.CL, TE.TE, HTTP/2 downgrade, response queue poisoning, and front-end/back-end parsing discrepancies.

WEBHTTPEXTERNAL
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

HTTP Parameter Pollution

Duplicate parameter behavior across server technologies, client-side pollution, and filter-versus-backend parsing differences.

WEBAPIHTTP
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Open Redirect

Parser edge cases, encoding, scheme-relative URLs, validation bypasses, and redirect chaining.

WEBREDIRECTAUTH
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

OAuth Misconfiguration

Redirect URI weaknesses, state and PKCE problems, token leakage, account linking, and provider/application trust failures.

WEBAPIOAUTHIDENTITY
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

JSON Web Token Attacks

Algorithm confusion, missing verification, key injection, JWK/JWKS abuse, claim manipulation, and cracking workflows.

WEBAPIJWTAUTH
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Insecure Deserialization

Serialization formats, gadget chains, detection markers, tooling, and language-specific exploitation references.

WEBDESERIALIZATIONRCE
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Prototype Pollution

Client- and server-side JavaScript prototype manipulation, source/sink discovery, gadgets, and filter bypasses.

WEBJAVASCRIPTAPI
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Web Cache Poisoning and Deception

Cache-key analysis, unkeyed input, path confusion, delimiter differences, poisoning, and private-content deception.

WEBCACHEHTTP
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Race Conditions

Limit-overrun, state-transition, single-packet, session, and time-of-check/time-of-use testing patterns.

WEBAPIBUSINESS-LOGIC
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

WebSocket Vulnerabilities

Handshake manipulation, message tampering, cross-site WebSocket hijacking, authentication, and origin testing.

WEBWEBSOCKETAPI
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

GraphQL Injection and Abuse

Introspection, field suggestion, batching, alias abuse, authorization, injection, denial-of-service, and schema discovery.

WEBAPIGRAPHQL
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

CRLF Injection

Header injection, response splitting, log injection, encoding variants, and downstream proxy behavior.

WEBHTTPINJECTION
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

Server-Side Include Injection

SSI directive detection, environment disclosure, file inclusion, and command execution on supported servers.

WEBSSIRCE
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

XSLT Injection

Processor fingerprinting, file access, SSRF, extension functions, and code-execution paths in XSLT transformations.

WEBXSLTXML
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

CSV and Formula Injection

Spreadsheet formula execution, exfiltration patterns, delimiters, encoding, and application export testing.

WEBCSVCLIENT-SIDE
github.com · VERIFIED 2026-08-24
EXPLOIT SHEET

SAML Injection and Signature Attacks

XML signature wrapping, assertion manipulation, identity-provider confusion, and SAML response testing.

WEBSAMLIDENTITY
github.com · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

MySQL Injection Cheat Sheet

MySQL syntax for versioning, comments, string concatenation, conditional responses, timing, files, and command execution.

WEBSQLIMYSQL
pentestmonkey.net · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

MSSQL Injection Cheat Sheet

Microsoft SQL Server syntax for metadata, timing, errors, file access, linked servers, and operating-system interaction.

WEBSQLIMSSQL
pentestmonkey.net · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

PostgreSQL Injection Cheat Sheet

PostgreSQL syntax for metadata, type conversion, timing, files, stacked queries, and command-execution primitives.

WEBSQLIPOSTGRESQL
pentestmonkey.net · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

Oracle Injection Cheat Sheet

Oracle-specific comments, dual-table behavior, metadata views, timing, errors, network access, and file techniques.

WEBSQLIORACLE
pentestmonkey.net · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

DB2 Injection Cheat Sheet

DB2 query syntax, metadata enumeration, comments, concatenation, conditional responses, and timing reference.

WEBSQLIDB2
pentestmonkey.net · VERIFIED 2026-08-24
DATABASE CHEAT SHEET

Informix Injection Cheat Sheet

Informix syntax for version discovery, users, schemas, tables, comments, strings, and conditional behavior.

WEBSQLIINFORMIX
pentestmonkey.net · VERIFIED 2026-08-24
SHELL CHEAT SHEET

Upgrading Simple Shells

Reliable PTY upgrade patterns, terminal settings, job control, and practical shell stabilization steps.

LINUXSHELLSPOST-EXPLOIT
blog.ropnop.com · VERIFIED 2026-08-24
CHECKLIST

OWASP WSTG Checklist

Spreadsheet and checklist artifacts mapped to Web Security Testing Guide identifiers for planning and coverage tracking.

WEBCHECKLISTREPORTING
github.com · VERIFIED 2026-08-24
PRACTICE INDEX

PortSwigger Complete Lab Index

Every Web Security Academy lab in one index, including mystery labs for methodology practice without knowing the vulnerability first.

WEBAPITRAININGOSWA
portswigger.net · VERIFIED 2026-08-24
API STANDARD

OWASP API Security Top 10

Risk categories and assessment guidance for broken object authorization, authentication, resource consumption, business flows, SSRF, and API inventory.

APIWEBMETHODOLOGY
owasp.org · VERIFIED 2026-08-24
VERIFICATION STANDARD

OWASP ASVS

Detailed application-security requirements useful for building test cases, remediation guidance, and coverage beyond vulnerability names.

WEBAPIDEFENSE
owasp.org · VERIFIED 2026-08-24
CHEAT SHEET

OWASP GraphQL Cheat Sheet

GraphQL input, authorization, query complexity, batching, introspection, error, and transport security guidance.

APIGRAPHQLDEFENSE
cheatsheetseries.owasp.org · VERIFIED 2026-08-24
PROTOCOL REFERENCE

MDN HTTP Reference

Authoritative browser-oriented reference for HTTP methods, status codes, headers, cookies, caching, authentication, and cross-origin behavior.

WEBHTTPPROTOCOL
developer.mozilla.org · VERIFIED 2026-08-24
CHEAT SHEET

OWASP Web Service Security

Security guidance for REST and SOAP services, transport, schemas, message size, authentication, authorization, and content handling.

APISOAPRESTDEFENSE
cheatsheetseries.owasp.org · VERIFIED 2026-08-24
02

IDENTITY / WINDOWS

DOCUMENTATION

BloodHound Documentation

Official documentation for BloodHound Community Edition, collection, analysis, and identity attack-path concepts.

ADINTERNALIDENTITY
specterops.io
PLATFORM DOCS

Microsoft Active Directory DS

Primary documentation for Active Directory Domain Services concepts and administration.

ADINTERNALIDENTITY
learn.microsoft.com
PROTOCOL DOCS

Microsoft Kerberos Overview

Windows Kerberos components, ticket flow, delegation, authentication, and security behavior from the platform vendor.

ADKERBEROSIDENTITY
learn.microsoft.com · VERIFIED 2026-08-24
ADCS RESEARCH

Certified Pre-Owned

Foundational SpecterOps research describing Active Directory Certificate Services escalation and persistence attack paths.

ADADCSINTERNAL
specterops.io · VERIFIED 2026-08-24
RESEARCH

ADSecurity.org

Sean Metcalf's research and defensive material on Active Directory, Kerberos, trusts, credentials, detection, and enterprise identity.

ADKERBEROSDEFENSE
adsecurity.org · VERIFIED 2026-08-24
TOOL DOCS

NetExec Wiki

Protocol modules, authentication, enumeration, credential validation, databases, and command usage for NetExec.

ADINTERNALTOOL-DOCS
netexec.wiki · VERIFIED 2026-08-24
TOOL DOCS

Certipy Wiki

Enumeration and exploitation documentation for Active Directory Certificate Services using Certipy.

ADADCSTOOL-DOCS
github.com · VERIFIED 2026-08-24
TOOL DOCS

Impacket Examples

Canonical example scripts for SMB, Kerberos, NTLM, WMI, secrets, delegation, remote execution, and Windows protocols.

ADINTERNALTOOL-DOCS
github.com · VERIFIED 2026-08-24
COLLECTOR DOCS

AzureHound Documentation

Collection setup, permissions, authentication, and data gathering for Microsoft Entra ID attack-path analysis.

ENTRACLOUDIDENTITY
bloodhound.specterops.io · VERIFIED 2026-08-24
TOOL DOCS

ROADtools Wiki

Authentication, token, directory-data, and exploration documentation for Microsoft Entra ID research and assessment.

ENTRACLOUDTOOL-DOCS
github.com · VERIFIED 2026-08-24
03

NETWORK / EXTERNAL

KNOWLEDGE BASE

MITRE ATT&CK

A common knowledge base for adversary tactics and techniques used to map and discuss observed behavior.

REPORTINGDEFENSERISK
attack.mitre.org
FRAMEWORK

NIST Cybersecurity Framework

High-level cybersecurity risk-management guidance and supporting implementation resources.

REPORTINGDEFENSERISK
nist.gov
SCORING STANDARD

FIRST CVSS v4.0

Official CVSS v4 specification, calculator, metrics, supplemental guidance, and scoring resources.

REPORTINGCVSSRISK
first.org · VERIFIED 2026-08-24
WEAKNESS TAXONOMY

MITRE CWE

Software and hardware weakness definitions, relationships, consequences, mitigations, examples, and mappings.

REPORTINGCWEDEFENSE
cwe.mitre.org · VERIFIED 2026-08-24
RISK LIST

CWE Top 25

Data-driven list of widespread and consequential software weaknesses with scoring and mapping context.

REPORTINGCWERISK
cwe.mitre.org · VERIFIED 2026-08-24
ATTACK PATTERNS

MITRE CAPEC

Attack-pattern descriptions with prerequisites, execution flow, consequences, mitigations, and related weaknesses.

REPORTINGATTACK-PATHDEFENSE
capec.mitre.org · VERIFIED 2026-08-24
PRIORITIZATION

CISA Known Exploited Vulnerabilities

Authoritative catalog of vulnerabilities with evidence of exploitation and remediation due-date context.

CVEEXTERNALPRIORITIZATION
cisa.gov · VERIFIED 2026-08-24
LIKELIHOOD MODEL

FIRST EPSS

Daily probability estimates for whether published CVEs will be exploited in the wild within the next 30 days.

CVERISKPRIORITIZATION
first.org · VERIFIED 2026-08-24
VULNERABILITY DATA

National Vulnerability Database

NIST vulnerability records, CVE enrichment, affected configurations, CVSS vectors, references, and search.

CVERESEARCHREPORTING
nvd.nist.gov · VERIFIED 2026-08-24
SEVERITY TAXONOMY

Bugcrowd Vulnerability Rating Taxonomy

Living priority taxonomy for common web, API, mobile, infrastructure, hardware, and AI vulnerability classes.

BUG-BOUNTYREPORTINGRISK
bugcrowd.com · VERIFIED 2026-08-24
SEVERITY GUIDANCE

HackerOne Severity Guidance

Platform guidance on report severity, qualitative ratings, CVSS calculator options, and program-specific scoring.

BUG-BOUNTYREPORTINGRISK
docs.hackerone.com · VERIFIED 2026-08-24
RISK METHOD

OWASP Risk Rating Methodology

Structured likelihood and impact estimation for applications when a raw technical score does not tell the full story.

REPORTINGWEBRISK
owasp.org · VERIFIED 2026-08-24
TESTING STANDARD

NIST SP 800-115

Technical guide for planning, conducting, analyzing, and reporting security testing and assessment work.

METHODOLOGYREPORTINGDEFENSE
csrc.nist.gov · VERIFIED 2026-08-24
METHODOLOGY

Penetration Testing Execution Standard

Engagement phases covering pre-engagement, intelligence, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.

METHODOLOGYREPORTINGPENTEST
pentest-standard.org · VERIFIED 2026-08-24
04

TOOLS / PLATFORMS

REFERENCE

HackTricks

A resource to help hack almost anything.

INTERNALEXTERNALTOOL-DOCS
hacktricks.wiki
REFERENCE

Kali Linux Tools

An indexed reference for tools packaged with Kali, including descriptions, commands, and links.

INTERNALEXTERNALTOOL-DOCS
kali.org
REFERENCE

Nmap Reference Guide

Primary reference for Nmap scanning behavior, options, output, and scripting capabilities.

INTERNALEXTERNALTOOL-DOCS
nmap.org
CLOUD TECHNIQUES

Hacking the Cloud

Cloud penetration-testing and red-team tradecraft for AWS, Azure, GCP, Terraform, containers, and identity.

CLOUDAWSAZUREGCP
hackingthe.cloud · VERIFIED 2026-08-24
CLOUD PLAYBOOKS

HackTricks Cloud

Provider and service-oriented enumeration, privilege escalation, persistence, and post-exploitation notes.

CLOUDAWSAZUREGCP
cloud.hacktricks.wiki · VERIFIED 2026-08-24
TOOL DOCS

CloudFox

Situational-awareness and attack-path discovery tool for unfamiliar cloud environments, with scoped enumeration workflows.

CLOUDAWSGCPTOOL-DOCS
github.com · VERIFIED 2026-08-24
ATTACK EMULATION

Stratus Red Team

Granular, reproducible cloud attack techniques mapped to providers and MITRE ATT&CK tactics.

CLOUDAWSAZUREGCP
stratus-red-team.cloud · VERIFIED 2026-08-24
IAM ANALYSIS

Principal Mapper

Models AWS IAM principals and permissions to identify privilege escalation and access relationships.

CLOUDAWSIAM
github.com · VERIFIED 2026-08-24
ATTACK PATHS

KubeHound

Kubernetes attack-path graphing for relationships between identities, workloads, permissions, and cluster resources.

CLOUDKUBERNETESCONTAINER
github.com · VERIFIED 2026-08-24
RISK STANDARD

OWASP Kubernetes Top 10

Prioritized Kubernetes risks covering workload configuration, authorization, secrets, segmentation, components, and cloud movement.

KUBERNETESCONTAINERDEFENSE
owasp.org · VERIFIED 2026-08-24
TESTING GUIDE

OWASP Kubernetes Security Testing Guide

Top-down methodology for architecture review, discovery, cluster assessment, container testing, and benchmark auditing.

KUBERNETESCONTAINERMETHODOLOGY
owasp.org · VERIFIED 2026-08-24
CHEAT SHEET

OWASP Kubernetes Security Cheat Sheet

Practical cluster, workload, authorization, networking, secret, and runtime security checks.

KUBERNETESCONTAINERDEFENSE
cheatsheetseries.owasp.org · VERIFIED 2026-08-24
CHEAT SHEET

OWASP Docker Security Cheat Sheet

Common Docker security errors and controls for hosts, images, users, capabilities, sockets, secrets, and runtimes.

DOCKERCONTAINERDEFENSE
cheatsheetseries.owasp.org · VERIFIED 2026-08-24
TESTING GUIDE

OWASP Mobile Application Security Testing Guide

Comprehensive Android and iOS security testing and reverse-engineering techniques mapped to mobile weaknesses and controls.

MOBILEANDROIDIOSMETHODOLOGY
mas.owasp.org · VERIFIED 2026-08-24
VERIFICATION STANDARD

OWASP MASVS

Mobile application security requirements covering storage, cryptography, authentication, networking, platform, code, resilience, and privacy.

MOBILEANDROIDIOSDEFENSE
mas.owasp.org · VERIFIED 2026-08-24
CHEAT SHEET

Mobile App Pentest Cheat Sheet

Compact Android and iOS test checklist with commands and references mapped to common mobile-security risk areas.

MOBILEANDROIDIOS
github.com · VERIFIED 2026-08-24
TOOL DOCS

MobSF Documentation

Static and dynamic analysis setup, APIs, analyzers, reports, and operational guidance for the Mobile Security Framework.

MOBILEANDROIDIOSTOOL-DOCS
mobsf.github.io · VERIFIED 2026-08-24
INSTRUMENTATION DOCS

Frida Documentation

Dynamic instrumentation concepts, JavaScript APIs, Android, iOS, tracing, messages, modes, and examples.

MOBILERUNTIMETOOL-DOCS
frida.re · VERIFIED 2026-08-24
TOOL DOCS

Objection Wiki

Runtime mobile exploration workflows powered by Frida, including files, memory, storage, platform interaction, and patching.

MOBILEANDROIDIOSTOOL-DOCS
github.com · VERIFIED 2026-08-24
PLATFORM DOCS

Android Security Best Practices

Vendor guidance for permissions, networking, WebView, storage, authentication, cryptography, and component exposure.

MOBILEANDROIDDEFENSE
developer.android.com · VERIFIED 2026-08-24
WIRELESS DOCS

Aircrack-ng Documentation

Official suite reference for monitor mode, capture, packet injection, replay, access points, and WPA/WPA2 assessment.

WIRELESSWIFITOOL-DOCS
aircrack-ng.org · VERIFIED 2026-08-24
WIRELESS TOOLING

hcxtools

Packet-capture conversion and processing tools designed for Hashcat and John the Ripper wireless workflows.

WIRELESSWIFIHASHES
github.com · VERIFIED 2026-08-24
HASH REFERENCE

Hashcat Example Hashes

Canonical mode identifiers and test hashes for NTLM, Kerberos, WPA, archives, databases, applications, and other formats.

PASSWORDSWIRELESSADTOOL-DOCS
hashcat.net · VERIFIED 2026-08-24
RADIO TOOL DOCS

Bettercap Modules

Official module documentation for Wi-Fi, BLE, network discovery, proxies, packet streams, and event-driven assessment.

WIRELESSWIFIBLETOOL-DOCS
bettercap.org · VERIFIED 2026-08-24
WIRELESS DOCS

Kismet Documentation

Wireless discovery, capture sources, channel handling, logging, remote capture, alerts, and device tracking.

WIRELESSWIFIRECON
kismetwireless.net · VERIFIED 2026-08-24
DEVICE DOCS

Hak5 WiFi Pineapple Documentation

Official WiFi Pineapple setup, campaigns, recon, captures, modules, storage, networking, and recovery documentation.

WIRELESSWIFIHARDWARE
docs.hak5.org · VERIFIED 2026-08-24
TESTING GUIDE

OWASP IoT Security Testing Guide

Methodology for IoT architecture, firmware, interfaces, communications, mobile companions, hardware, and privacy testing.

IOTFIRMWAREHARDWARE
owasp.org · VERIFIED 2026-08-24
FIRMWARE GUIDE

OWASP Firmware Security Testing Methodology

Structured firmware assessment methodology covering acquisition, analysis, emulation, filesystem review, and dynamic testing.

IOTFIRMWAREMETHODOLOGY
github.com · VERIFIED 2026-08-24
FIRMWARE TOOL DOCS

Binwalk

Firmware signature scanning, embedded-file identification, extraction, entropy analysis, and reverse-engineering support.

FIRMWAREIOTTOOL-DOCS
github.com · VERIFIED 2026-08-24
FIRMWARE EMULATION

FirmAE

Automated Linux-based firmware emulation and analysis for supported embedded device images.

FIRMWAREIOTEMULATION
github.com · VERIFIED 2026-08-24
EMBEDDED FRAMEWORK

RouterSploit

Open-source exploitation framework for authorized assessment of embedded devices, routers, services, and credentials.

IOTHARDWAREEXTERNAL
github.com · VERIFIED 2026-08-24
OSINT INDEX

OSINT Framework

A categorized map of public-source research tools for domains, usernames, people, infrastructure, files, images, and metadata.

OSINTRECONEXTERNAL
osintframework.com · VERIFIED 2026-08-24
SEARCH TOOLS

IntelTechniques Search Tools

Centralized forms for public records, usernames, domains, email, social platforms, maps, and general OSINT pivots.

OSINTRECON
inteltechniques.com · VERIFIED 2026-08-24
SEARCH SYNTAX

Shodan Search Query Fundamentals

Official filters and query behavior for finding exposed internet services, products, certificates, ports, networks, and organizations.

OSINTEXTERNALRECON
help.shodan.io · VERIFIED 2026-08-24
SEARCH SYNTAX

Censys Search Language

Official field, boolean, range, existence, and structured-search syntax for hosts, certificates, and web properties.

OSINTEXTERNALRECON
docs.censys.com · VERIFIED 2026-08-24
SEARCH SYNTAX

Google Search Operators

Primary reference for exact phrases, exclusions, site restrictions, file types, and other search refinements.

OSINTRECON
support.google.com · VERIFIED 2026-08-24
SEARCH SYNTAX

GitHub Code Search Syntax

Official syntax for literal, regex, path, language, symbol, repository, organization, and boolean code searches.

OSINTCODESECRETS
docs.github.com · VERIFIED 2026-08-24
CERTIFICATE SEARCH

Certificate Transparency Search

Public certificate-transparency lookup useful for discovering issued names, wildcard scope, and historical certificate data.

OSINTDNSRECON
crt.sh · VERIFIED 2026-08-24
WEB INTELLIGENCE

urlscan.io

Historical and current page scans with requests, hosts, certificates, technologies, screenshots, and observed relationships.

OSINTWEBRECON
urlscan.io · VERIFIED 2026-08-24
WEB ARCHIVE

Internet Archive Wayback Machine

Historical page, path, script, documentation, and asset snapshots useful for understanding earlier attack surface.

OSINTWEBRECON
web.archive.org · VERIFIED 2026-08-24
ENUMERATION DOCS

OWASP Amass Documentation

Asset-discovery concepts and configuration for DNS enumeration, graphing, data sources, tracking, and attack-surface mapping.

RECONDNSEXTERNAL
owasp-amass.github.io · VERIFIED 2026-08-24
ENUMERATION DOCS

Subfinder Documentation

Passive subdomain discovery configuration, providers, inputs, outputs, recursion, filtering, and workflow integration.

RECONDNSEXTERNAL
docs.projectdiscovery.io · VERIFIED 2026-08-24
WORDLISTS

Assetnote Wordlists

Continuously generated content-discovery and technology-specific wordlists derived from real-world web data.

RECONWEBFUZZING
wordlists.assetnote.io · VERIFIED 2026-08-24
SCRIPT INDEX

Nmap NSE Documentation

Searchable documentation for Nmap Scripting Engine categories, arguments, outputs, and protocol-specific checks.

EXTERNALNETWORKNSE
nmap.org · VERIFIED 2026-08-24
SERVICE PLAYBOOKS

HackTricks Network Services

Enumeration and testing notes organized by common TCP and UDP services and their usual weaknesses.

EXTERNALNETWORKINTERNAL
hacktricks.wiki · VERIFIED 2026-08-24
WORDLIST COLLECTION

SecLists

Discovery, fuzzing, usernames, passwords, URLs, patterns, payloads, and protocol wordlists for authorized assessment work.

RECONFUZZINGEXTERNAL
github.com · VERIFIED 2026-08-24
EXPLOIT SEARCH

SearchSploit Manual

Local Exploit-DB searching, path copying, mirror inspection, Nmap XML integration, and result filtering.

EXTERNALEXPLOIT-RESEARCHTOOL-DOCS
exploit-db.com · VERIFIED 2026-08-24
EXPLOIT DATABASE

Exploit Database

Public proof-of-concept archive and searchable vulnerability research maintained by OffSec.

EXTERNALEXPLOIT-RESEARCHCVE
exploit-db.com · VERIFIED 2026-08-24
FRAMEWORK DOCS

Metasploit Documentation

Modules, payloads, sessions, workspaces, databases, development, and safe framework usage documentation.

EXTERNALINTERNALTOOL-DOCS
docs.metasploit.com · VERIFIED 2026-08-24
TEMPLATE LIBRARY

Nuclei Templates

Community-curated vulnerability, exposure, misconfiguration, technology, and DAST templates for the Nuclei engine.

EXTERNALWEBSCANNING
github.com · VERIFIED 2026-08-24
TLS REFERENCE

testssl.sh

Command documentation and test coverage for TLS protocols, ciphers, certificates, vulnerabilities, and HTTP security headers.

EXTERNALTLSTOOL-DOCS
github.com · VERIFIED 2026-08-24
SSH REFERENCE

ssh-audit

SSH server and client auditing for algorithms, key sizes, versions, security recommendations, and known weaknesses.

EXTERNALSSHTOOL-DOCS
github.com · VERIFIED 2026-08-24
FUZZER DOCS

ffuf

Fast web fuzzing syntax for paths, virtual hosts, parameters, POST bodies, recursion, matchers, filters, and replay proxies.

WEBFUZZINGEXTERNAL
github.com · VERIFIED 2026-08-24
DISCOVERY DOCS

Feroxbuster Documentation

Recursive content discovery, filters, collection methods, configuration, state, proxying, and wordlist usage.

WEBRECONEXTERNAL
epi052.github.io · VERIFIED 2026-08-24
HTTP CLIENT DOCS

curl Manual

Complete request construction reference for headers, cookies, authentication, proxies, certificates, uploads, protocols, and debugging.

WEBHTTPTOOL-DOCS
curl.se · VERIFIED 2026-08-24
FILTER REFERENCE

Wireshark Display Filter Reference

Searchable protocol-field reference for precise display filters and packet-analysis evidence.

NETWORKTRAFFICTOOL-DOCS
wireshark.org · VERIFIED 2026-08-24
05

TRAINING / REFERENCES

HANDS ON

TryHackMe

Hands-on cyber security training through real-world scenarios.

TRAININGLABS
tryhackme.com
HANDS ON

Hack The Box Academy

Develop your skills with guided training and prove your expertise with industry certifications. Become a market-ready cybersecurity professional.

TRAININGLABS
hackthebox.com/
HANDS ON

Web Security Academy

Free, online web security training from the creators of Burp Suite.

TRAININGLABS
portswigger.net
FIELD MANUAL

HISYD OSWA Field Manual

Online WEB-200 methodology, nine vulnerability playbooks, searchable notes, downloadable Markdown checklists, evidence guidance, and reporting references.

OSWAWEBTRAINING
WEB TRAINING

PentesterLab

Focused web-security exercises organized around specific vulnerability classes and code-level understanding.

TRAININGWEBAPI
pentesterlab.com · VERIFIED 2026-08-24
PRACTICE RANGE

OffSec Proving Grounds

Standalone penetration-testing machines for enumeration, exploitation, privilege escalation, and exam-style practice.

TRAININGOSCPEXTERNAL
offsec.com · VERIFIED 2026-08-24
VULNERABLE VMS

VulnHub

Downloadable intentionally vulnerable virtual machines for local, isolated penetration-testing practice.

TRAININGOSCPLAB
vulnhub.com · VERIFIED 2026-08-24
WARGAMES

OverTheWire

Progressive command-line, Linux, web, cryptography, and exploitation challenges delivered as focused wargames.

TRAININGLINUXWEB
overthewire.org · VERIFIED 2026-08-24
HANDS-ON COURSES

pwn.college

Browser-accessible technical modules covering computing foundations, system security, web, software exploitation, and defense.

TRAININGLINUXEXPLOITATION
pwn.college · VERIFIED 2026-08-24
VULNERABLE APP

OWASP Juice Shop

Modern intentionally insecure application with broad OWASP coverage, challenges, score tracking, and multiple deployment options.

TRAININGWEBLAB
owasp.org · VERIFIED 2026-08-24
VULNERABLE APP

OWASP WebGoat

Guided lessons demonstrating common application vulnerabilities and their defensive fixes in a controlled environment.

TRAININGWEBLAB
owasp.org · VERIFIED 2026-08-24
VULNERABLE API

OWASP crAPI

Intentionally vulnerable API application designed around modern API-security risks and realistic business flows.

TRAININGAPILAB
owasp.org · VERIFIED 2026-08-24
VULNERABLE APP

DVWA

Compact PHP and MariaDB application for practicing common web vulnerabilities at configurable difficulty levels.

TRAININGWEBLAB
github.com · VERIFIED 2026-08-24
VULNERABLE AD LAB

Game of Active Directory

Free multi-domain Active Directory lab designed for practicing common domain, trust, delegation, ADCS, and movement techniques.

TRAININGADLAB
orange-cyberdefense.github.io · VERIFIED 2026-08-24
VULNERABLE CLOUD LAB

CloudFoxable

Terraform-deployed AWS environment with gamified attack paths for learning cloud enumeration and privilege relationships.

TRAININGAWSCLOUD
github.com · VERIFIED 2026-08-24
CLOUD CHALLENGES

flaws.cloud

AWS security challenge series built around common storage, identity, metadata, and service misconfigurations.

TRAININGAWSCLOUD
flaws.cloud · VERIFIED 2026-08-24
VULNERABLE K8S LAB

Kubernetes Goat

Intentionally vulnerable Kubernetes environment with scenarios covering workloads, secrets, RBAC, networking, and cluster risks.

TRAININGKUBERNETESCONTAINER
github.com · VERIFIED 2026-08-24
06

WRITEUPS / NOTES

WRITE-UP

VM-Notes

Notes for setting up and managing my virtual machines

TOOL-NOTES
HISYD / IDENTITY
WRITE-UP

BloodHound

Attack-path analysis, collection concepts, graph thinking, and practical notes for reviewing Active Directory relationships.

TOOL-NOTES
HISYD / IDENTITY
WRITE-UP

Burp Suite

Proxy-driven web testing workflow, request inspection, Repeater habits, scope control, and keeping evidence organized.

TOOL-NOTES
HISYD / WEB
WRITE-UP

Nmap

Host and service discovery, scan planning, output formats, and turning raw enumeration into useful testing notes.

TOOL-NOTES
HISYD / NETWORK
WRITE-UP

Wireshark

Packet-analysis workflow, display-filter habits, capture review, and extracting evidence without getting lost in the noise.

TOOL-NOTES
HISYD / TRAFFIC
HISYD WRITE-UP

OWASP ZAP

My ZAP workflow for manual request testing, fuzzing, session handling, evidence capture, and using automation without letting it replace analysis.

WEBPROXYFUZZINGTOOL-NOTES
HISYD WRITE-UP

NetExec

My NetExec notes for scoped protocol enumeration, credential validation, parsing results, and avoiding unnecessary authentication noise.

ACTIVE DIRECTORYSMBLDAPTOOL-NOTES
HISYD WRITE-UP

Certipy and ADCS

My Certipy notes for enumerating Active Directory Certificate Services, validating ESC paths, requesting certificates, and preserving the evidence that proves the issue.

ACTIVE DIRECTORYADCSCERTIFICATESTOOL-NOTES
HISYD WRITE-UP

Impacket

My Impacket notes for choosing the right example script, handling credential formats, troubleshooting Kerberos, and documenting remote-protocol activity.

SMBKERBEROSNTLMTOOL-NOTES
HISYD WRITE-UP

Responder

My Responder notes for controlled LLMNR, NBT-NS, and mDNS assessment, capture handling, relay prerequisites, and reducing disruption.

INTERNALLLMNRNBT-NSTOOL-NOTES
HISYD / INTERNAL · VERIFIED -08-24
HISYD WRITE-UP

Hashcat

My Hashcat notes for identifying the correct mode, cleaning inputs, building bounded attacks, reading status, and preserving reproducible results.

PASSWORDSHASHESGPUTOOL-NOTES
HISYD WRITE-UP

WiFi Pineapple MK VII

My WiFi Pineapple notes for recon, campaign scoping, captures, client testing, storage, and keeping radio work controlled.

WIRELESSWIFIHARDWARETOOL-NOTES
HISYD WRITE-UP

Android Testing Stack

My Android notes for ADB, emulators, proxying, certificates, split APKs, static analysis, runtime inspection, and evidence collection.

ANDROIDADBBURPTOOL-NOTES
HISYD WRITE-UP

External Crypto Triage

My testssl.sh and ssh-audit notes for turning protocol output into accurate, consolidated findings with practical remediation.

EXTERNALTLSSSHTOOL-NOTES
HISYD REFERENCE

Google Dorks / Search Operators

A scope-first reference for search operators, reusable query recipes, result validation, evidence habits, and primary reconnaissance sources.

OSINTRECONEXTERNALWEBTOOL-NOTES
HISYD / RECON · VERIFIED 2026-08-25