Browse historical snapshots of websites. Invaluable for OSINT, investigating past configurations, and finding removed content.
// resource network
// resource network
// resource network
A human-reviewed directory. Filter by category, search by tag or keyword, and follow the trust rating.
// 54 entries
Browse historical snapshots of websites. Invaluable for OSINT, investigating past configurations, and finding removed content.
// learning
TryHackMeGuided, gamified cybersecurity training with browser-based labs. Great for beginners through intermediate practitioners.
// learning
Hack The BoxAdvanced penetration testing labs and challenges. Retired machines have community walkthroughs.
// learning
HTB AcademyStructured cybersecurity courses from Hack The Box covering everything from networking fundamentals to advanced exploitation.
// learning
PortSwigger Web Security AcademyFree, comprehensive web security training from the makers of Burp Suite. Covers OWASP Top 10 and beyond with interactive labs.
// learning
PentesterLabHands-on web penetration testing exercises progressing from basic to advanced topics.
// learning
picoCTFFree beginner-friendly CTF platform by Carnegie Mellon. Excellent for learning binary exploitation, crypto, forensics, and web.
// learning
OverTheWire WargamesClassic wargames for learning security concepts through SSH-based challenges. Start with Bandit for Linux basics.
// learning
VulnHubDownloadable vulnerable virtual machines for offline penetration testing practice.
// learning
pwnable.twBinary exploitation wargame with high-quality pwn challenges ranging from easy to very hard.
// learning
OWASP Juice ShopIntentionally insecure web app for security training. Covers the entire OWASP Top 10 and more.
// learning
CyberTalentsCTF platform with challenges, competitions, and cybersecurity talent recruitment.
// learning
HackTricksComprehensive pentesting methodology wiki. Covers enumeration, exploitation, and privilege escalation across platforms.
// learning
ired.team Red Team NotesIn-depth red team and offensive security notes covering Windows internals, persistence, evasion, and more.
// learning
OffSec TrainingIndustry-standard offensive security certifications including OSCP, OSWE, and OSED.
// learning
MalDev AcademyAdvanced malware development training for red teamers and security researchers.
// learning
MITRE ATT&CK FrameworkKnowledge base of adversary tactics and techniques based on real-world observations. The industry standard for threat modeling.
// learning
Developer Roadmaps — Cyber SecurityCommunity-driven cybersecurity learning roadmap covering fundamentals to advanced topics.
// bug bounty
HackerOneLeading bug bounty and vulnerability disclosure platform. Browse public programs and disclosed reports to learn.
// bug bounty
Payload All The ThingsMassive collection of payloads and bypasses for web application security testing. Covers XSS, SQLi, SSRF, SSTI, and more.
// tooling
GTFOBinsCurated list of Unix binaries that can be used to bypass local security restrictions for privilege escalation.
// tooling
RevShellsOnline reverse shell generator supporting Bash, PowerShell, Python, PHP, and many more languages.
// tooling
NucleiFast, customizable vulnerability scanner driven by YAML templates. Thousands of community templates available.
// tooling
SubfinderFast passive subdomain enumeration tool by ProjectDiscovery. Essential for recon.
// tooling
httpxFast multi-purpose HTTP toolkit for probing live hosts, grabbing titles, status codes, and tech stacks.
// tooling
OWASP AmassIn-depth attack surface mapping and asset discovery using OSINT and active recon techniques.
// tooling
SecListsCollection of wordlists for fuzzing, passwords, usernames, URLs, and payloads used during security assessments.
// tooling
Pentest-Tools.comOnline penetration testing and vulnerability assessment toolkit with scanners, recon, and exploitation tools.
// osint
ShodanSearch engine for internet-connected devices. Find exposed services, open ports, and vulnerable systems.
// osint
CensysInternet-wide scanning platform for discovering hosts, certificates, and services across IPv4 and IPv6.
// osint
crt.shCertificate Transparency log search. Find subdomains by querying SSL/TLS certificate issuance.
// osint
Hunter.ioFind and verify professional email addresses associated with a domain. Useful for phishing assessments.
// osint
LeakIXSearch engine for exposed data, misconfigured services, and leaked information on the internet.
// osint
HackerTargetFree online tools for IP/AS lookup, DNS recon, port scanning, and vulnerability scanning.
// osint
Netcraft Research ToolsSite reports, hosting history, and technology detection for any website.
// malware
VirusTotalAnalyze suspicious files, URLs, domains, and IPs against 70+ antivirus engines and sandboxes.
// malware
ANY.RUNInteractive online malware sandbox. Watch malware execute in real-time and analyze network/file behavior.
// malware
Malware Traffic AnalysisBlog with pcap files and exercises for analyzing malware network traffic. Excellent for DFIR practice.
// malware
abuse.chCommunity-driven threat intelligence on malware, botnets, and C2 infrastructure. Hosts MalwareBazaar and URLhaus.
// reverse engineering
GhidraNSA's open-source software reverse engineering framework. Supports decompilation across many architectures.
// forensics
WiresharkThe world's most popular network protocol analyzer. Capture and inspect traffic in real-time.
// cryptography
HashcatWorld's fastest and most advanced password recovery utility. Supports 350+ hash types with GPU acceleration.
// other
Exploit-DBCVE-compliant archive of public exploits and vulnerable software. Maintained by OffSec.
U.S. government repository of vulnerability data with CVSS scores, CPE matching, and CWE classification.
// other
CVE — MITREThe authoritative source for CVE identifiers. Reference point for vulnerability tracking worldwide.
Open-source threat intelligence sharing platform. Create, store, and share structured threat data (IoCs, TTPs).
// osint
DNSDumpsterFree domain research tool for DNS recon and discovering host records. Visualizes DNS data for attack surface mapping.
// osint
URLScan.ioScan and analyze URLs for phishing, malware, and suspicious content. See DOM, requests, and screenshots.
// osint
AbuseIPDBCommunity-driven IP abuse reporting database. Check and report malicious IPs involved in attacks.
// osint
SecurityTrailsHistorical DNS data, WHOIS records, and domain intelligence. Trace infrastructure changes over time.
// other
Have I Been PwnedCheck if your email or phone has been compromised in a data breach. Essential awareness tool by Troy Hunt.
// tooling
CanarytokensFree tripwire tokens that alert you when triggered. Deploy as URLs, DNS, documents, or AWS keys to detect intrusions.
// forensics
FotoForensicsAnalyze images for hidden data, ELA, metadata, and digital tampering. Useful for OSINT and forensics.
// cryptography
CyberChefEncode and Decode
[submitted via public form]