Back to updates
UpdatedJul 14, 2026

ULTIMATE-CYBERSECURITY-MASTER-GUIDE — Updated!

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and Step-by-Step Guides across various critical security domains. Content is sourced from industry-leading books and technical presentations, focusing on practical application rather than JUST theory.

Share

PNWC Ultimate Cybersecurity Master Guide

🛡️ ULTIMATE CYBERSECURITY MASTER GUIDE

Professional Cybersecurity Knowledge Base · Red Team · Blue Team · Purple Team

Maintained Books Docs OSINT Scripts License Last Commit

Compiled from 70+ expert books · 90+ PNWC internal documents · custom tools & scripts
Abide by the Legal Terms of Use & Disclaimer for the use and misuse of this repository.

"Under pressure, you don't rise to the occasion; you fall to the level of your training."

"It ain't what you don't know that gets you into trouble. It's what you know for sure that just ain't so."


This is the repository's front door and master index.

Every guide, playbook, script folder, and reference in this project is linked from here.

Unlike START_HERE.md (a role-based navigation guide), this file is a flat catalog; the what exists, where it lives, and a description of each.

The START_HERE.md guide, can be used to route yourself through the sea of data by role/goal rather than listing EVERYTHING like it is here. But START_HERE.md does differ from the three Master Guides. The three Master Guides contain actual technical content, rather than just linking to everyting.

Master Guides:

This README is the entry point when landing on this repo:

  • Gives a general overview of the repository
  • Helps users look for specific subjects or topics, such as "What guide covers %TOPIC%"
  • Check on what's been added/credited since a prior visit

From this main page you can find any resource in the repository within one click of this file, and understand at a glance what the project covers and how it's licensed/credited.

THANK YOU FOR CHECKING THIS OUT!


🎯 START HERE

🆕 New to IT/Computers/Networks in General? - READ OUR IT MANUAL TO GET YOURSELF STARTED!

START_HERE.md - START HERE IF YOU ARE READY TO JUMP IN!

Your complete navigation guide with quick paths for every role and purpose (Red Team, Blue Team, OSINT, Forensics, Homelab, Career).


📚 PRIMARY MASTER GUIDES

GuideDescription
🔥 Ultimate Cybersecurity Master GuideTHE main comprehensive guide - key takeaways from 70+ professional security books, full penetration testing lifecycle
🔥 Enhanced Cybersecurity Master GuideAll of the above + 90+ PNWC internal docs, KB articles, and operational experience layered in
🔥 Specialized Topics GuideDeep-dive into specialized/emerging domains: AI & LLM Security, Hardware Hacking, Hardware Testing, uConsole Cyberdeck, Space Security, SDR & RF Security

📖 SUPPORTING GUIDES & REFERENCE MATERIAL

Core References

ResourceDescription
Cybersecurity Cliff NotesQuick command reference; the essentials at a glance
Advanced Techniques - Part 1Advanced Metasploit, cloud pentesting, lateral movement, pivoting, etc.
Advanced Techniques - Part 2Exploit development, buffer overflows, shellcode, custom payloads, etc.
DIY Hardware & Firmware CompatibilitySBC-based DIY pentesting devices as well as compatibility & firmware guides
Debian Linux Command Cheat SheetLinux CLI commands for Debian/Ubuntu/Kali/Parrot
Arch Linux Command Cheat SheetLinux CLI commands for Arch
BlackArch Linux Cheat SheetLinux CLI commands for BlackArch
OSINT Cheat SheetQuick-reference OSINT cheat sheet

Operational Sections

SectionDescription
📋 Operational PlaybooksFull index of all playbooks - network audits, WiFi assessments, IR, phishing, unauthorized access
🟣 Purple Team PlaybooksSimple, Detailed, and Multi-Script purple team exercises
🔵 Blue Team PlaybooksIncident response procedures - simple and enhanced versions
🔬 Network Audit PlaybookField-ready professional network security audit procedure
🎣 SOP: Phishing AnalysisStandard operating procedure for phishing email triage
🚷 Unauthorized Access InvestigationPlaybook for investigating unauthorized access incidents
🚨 Incident ResponseBlue Team operations - threat detection, log aggregation, artifact analysis, standardized response procedures
📊 SIEM Deployment GuidesELK Stack, Wazuh, Splunk, and Graylog setup and configuration
🔍 OSINT Guide, Tools & TechniquesComprehensive OSINT methodology - 400+ categorized tools, investigation workflows, automated VM setup
🔴 OPSECOperational security practices - anonymity workflows, VM setup, personal rules for professionals
🏠 Homelab GuidesBuilding and maintaining safe, isolated labs for offensive and defensive practice
🤖 AI Cybersecurity ResourcesSelf-hosted AI agents (OpenClaw, AnythingLLM), LLM prompting for security, offline AI deployment, AI-powered security workflows
👾 Space SecurityOffensive and defensive security across the three segments of modern space systems
📻 SDRSoftware Defined Radio theory, practice, and applications
🥷 Hardware HackingPhysical and electronic attack techniques against embedded systems, microcontrollers, SoCs, and cryptographic hardware
🧰 Hardware TestingDiagnostic, benchmarking, and reliability stress testing guides and scripts for PC test benches
📟 uConsoleConfiguration, portable pentesting setups, and operational workflows optimized for the ClockworkPi uConsole cyberdeck.
📱 Mobile SecurityKali NetHunter on OnePlus 6 (rooting, install, field SOPs), Android/iOS app pentesting, mobile forensics, and engagement-level mobile pentest SOP
💻 ScriptsSecurity automation scripts, exploitation tools, recon utilities, and utility programs
📋 ChecklistsPre-engagement, testing, and post-engagement checklists
📄 PDF ResourcesCurated PDF references and guides
📚 DocumentationSupplemental technical documentation and cheat sheets

🆕 UNIQUE & PERSONAL CONTENT

Content sourced from PNWC's internal Notion knowledge base and real-world operations - not found in textbooks.

🔴 OPSEC & Operations

  • Personal field rules ("ALWAYS use a 3rd-party network!")
  • VM isolation and compartmentalization procedures
  • Anonymity and identity-separation workflows

🔍 OSINT Arsenal

  • 400+ tools organized by category
  • Automated OSINT VM build scripts
  • Full investigation methodology (target profiling → pivot → report)

📘 Team Playbooks

Purple Team

Blue Team

Detection Pipeline & SIEM

💻 Custom Scripts & Tools

  • pnwc_install_tools.sh - Cross-distro Linux installer for all tools in this guide (apt · pacman · dnf)
  • PowerShell - 12 scripts: AD testing, SMB auth, brute force, port scanning, reverse shells, system enumeration
  • Python - 30+ scripts: network recon, credential analysis, Bluetooth, web, geolocation, exploitation tools
  • Bash - System admin, recon, auditing, log analysis utilities (Scripts/Bash/)
  • C - Low-level utilities: user enumeration, port scanning, system manipulation
  • SQL - WordPress admin injection testing scripts
  • Go - (Scripts/GO/)

🎯 Attack Case Studies (10+ Analyzed)

IncidentType
StuxnetNation-state cyberweapon - Iranian nuclear facilities
WannaCryGlobal ransomware outbreak
EternalBlue / NSA LeakNSA exploit leaked by Shadow Brokers
SolarWindsSoftware supply chain compromise
CarbanakAPT banking theft campaign
NotPetyaDestructive malware disguised as ransomware
Edward Snowden / NSAMass surveillance program revelations
+ 3 additional major data breach case studiesAnalysis of root cause, TTPs, and defensive lessons

🔧 Hardware Arsenal Documented

Multi-tools: Flipper Zero · WiFi Pineapple · Proxmark3

📟 uConsole & Portable Operations

Field-side cybersecurity requires reliable, highly-portable hardware. This new section is dedicated to the ClockworkPi uConsole. It includes step-by-step documentation on turning the uConsole into a dedicated cyberdeck for mobile operations.

  • OS & Toolkit Optimization: Customizing Kali Linux, Parrot OS, or custom Debian builds for the uConsole's unique form factor.
  • SDR & Wireless Assessments: Configurations for running Wireshark, Kismet, and RTL-SDR in the field.
  • Hardware Interfacing: Using the uConsole for serial connections, hardware debugging, and local network audits.

Hak5 Suite: Rubber Ducky · Bash Bunny · LAN Turtle · Packet Squirrel · Shark Jack · O.MG Cable

RF / SDR: HackRF One · RTL-SDR · Ubertooth One · YardStick One

WiFi Adapters: Alfa AWUS036ACH · Alfa AWUS036NHA · TP-Link TL-WN722N


📊 REPOSITORY STATISTICS

CategoryCount
Expert books referenced70+
PNWC internal docs90+
Lines of content9,600+
OSINT tools catalogued400+
Operational playbooks5
Custom scripts15+
Attack case studies10+
Hardware devices documented20+

🚀 WHAT YOU CAN DO WITH THIS GUIDE

Immediately

  • ✅ Conduct professional penetration tests
  • ✅ Perform OSINT investigations
  • ✅ Execute incident response procedures
  • ✅ Automate security tasks with ready-made scripts
  • ✅ Assess IoT and embedded device security
  • ✅ Develop and analyze exploits
  • ✅ Build and operate a security homelab
  • ✅ Analyze real-world attack campaigns
  • Deploy Portable Cyberdecks: Set up and optimize the uConsole for on-the-go pentesting, SDR (Software Defined Radio), and field operations.

For Your Career

  • ✅ Prepare for OSCP, CEH, GPEN, CySA+, CISSP
  • ✅ Build skills for SOC analyst roles
  • ✅ Work as a professional pentester or red teamer
  • ✅ Specialize in OSINT, forensics, or hardware security
  • ✅ Build automation tooling for security workflows

🙏 CREDITS & ACKNOWLEDGMENTS

This guide stands on the shoulders of the global cybersecurity community.

🛠️ Key Tools & Frameworks

Exploitation & Post-Exploitation

OSINT

Network & Web Security

Password & Credentials

Wireless & RF

Forensics & Reverse Engineering

Monitoring & Defense

📚 Book Authors & Publishers

No Starch Press (primary reference publisher)

  • David Kennedy et al. - Metasploit: The Penetration Tester's Guide
  • Georgia Weidman - Penetration Testing: A Hands-On Introduction
  • OccupyTheWeb - Linux Basics for Hackers
  • Justin Seitz - Black Hat Python
  • Al Sweigart - Automate the Boring Stuff with Python

Other key works: Ryan Barnett (Black Hat Bash) · Travis Goodspeed (Microcontroller Exploits) · Seth Enoka (Cybersecurity for Small Networks) · Peter Kim (The Hacker Playbook 3) · Ben Clark (RTFM / BTFM) · Christopher Hadnagy (Social Engineering) · Kevin Mitnick (The Art of Invisibility)

See the full 78-entry bibliography below.

🐧 Security Linux Distributions

Kali Linux · BlackArch · Parrot Security OS · BackBox · Tails · Whonix

🌐 Knowledge Frameworks & Communities

MITRE ATT&CK · OWASP · NIST NVD · CVE · CISA · SANS

HackTheBox · TryHackMe · VulnHub · OverTheWire · PentesterLab

TryHackMe FREE Roadmap - 350+ free rooms, beginner → advanced, curated by Uttambodara

🔐 Privacy & Anonymity Tools

Tor Project · Mullvad VPN · ProtonVPN · IVPN VeraCrypt · ProtonMail · Signal

🎓 Certification Bodies

Offensive Security (OSCP, OSEP, OSCE) · EC-Council (CEH, CHFI) · GIAC (GPEN, GWAPT, GCIH) · CompTIA (Security+, PenTest+, CySA+) · (ISC)² (CISSP)

👥 Notable Security Researchers

Kevin Mitnick (1963–2023) · Bruce Schneier · Dan Kaminsky (1979–2021) · HD Moore · Tavis Ormandy · Marcus Hutchins · Brian Krebs · Troy Hunt · Katie Moussouris · Parisa Tabriz · The Grugq · and countless others


📚 Complete Bibliography

I. Foundational & General Hacking

  1. Hacking: The Art of Exploitation (2nd Ed.) - Jon Erickson · No Starch Press · 2008 · ISBN 978-1593271442
  2. The Basics of Hacking and Penetration Testing (2nd Ed.) - Patrick Engebretson · Syngress · 2013 · ISBN 978-0124116443
  3. Gray Hat Hacking: The Ethical Hacker's Handbook (5th Ed.) - Allen Harper et al. · McGraw-Hill · 2018 · ISBN 978-1260108415
  4. The Hacker's Underground Handbook - David Melnichuk · Self-published · 2008
  5. Hacking: Computer Hacking Beginners Guide - Alan T. Norman · Self-published
  6. The Code Book - Simon Singh · Anchor Books · 1999 · ISBN 978-0385495325
  7. Steal This Computer Book 4.0 - Wallace Wang · No Starch Press · 2006 · ISBN 978-1593271053
  8. Cybersecurity - Attack and Defense Strategies - Yuri Diogenes, Erdal Ozkaya · Packt · 2018 · ISBN 978-1788837074
  9. The NICE Cyber Security Framework - Izzat Alsmadi · Springer · 2019 · ISBN 978-3030023591
  10. Ethical Hacking MindMap - Educational material
  11. Introduction to Ethical Hacking - Chinni Diwakar · Educational material

II. Penetration Testing & Operations

  1. Penetration Testing: A Hands-On Introduction to Hacking - Georgia Weidman · No Starch Press · 2014 · ISBN 978-1593275648
  2. The Hacker Playbook 3: Red Team Edition - Peter Kim · Secure Planet · 2018 · ISBN 978-1980901754
  3. Advanced Penetration Testing - Wil Allsopp · Wiley · 2017 · ISBN 978-1119367680
  4. Google Hacking for Penetration Testers, Vol. 2 - Johnny Long et al. · Syngress · 2007 · ISBN 978-1597491761
  5. Real-World Bug Hunting - Peter Yaworski · No Starch Press · 2019 · ISBN 978-1593278618
  6. Quick Start Guide to Penetration Testing - Sagar Rahalkar · Apress · 2019 · ISBN 978-1484242698
  7. Offensive Security OSCP Exam with AD Preparation - Michael Mancao · Educational material · 2022
  8. OSCP Like Vulns Machines - Joas Antonio · Educational material
  9. Pentest in Office365 and Security - Joas Antonio · Educational material
  10. Exploiting Misconfigurations (CSP Bypass) - Jamy Casteel · GIAC/SANS Gold Paper · 2021

III. Defense & Team Strategies

  1. RTFM: Red Team Field Manual - Ben Clark · CreateSpace · 2014 · ISBN 978-1494295509
  2. Blue Team Field Manual (BTFM) - Alan J. White, Ben Clark · CreateSpace · 2017 · ISBN 978-1541216044
  3. Purple Team Field Manual (PTFM) - Tim Bryant · Self-published · 2020
  4. Jump-start Your SOC Analyst Career - Tyler Wall, Jarrett Rodrick · Apress · 2021 · ISBN 978-1484269039

IV. Operating Systems, Tools & Frameworks

  1. Kali Linux Revealed - Raphaël Hertzog, Jim O'Gorman, Mati Aharoni · Offsec Press · 2017 · ISBN 978-0-9976402-0-2
  2. Mastering Kali Linux for Advanced Penetration Testing - Robert W. Beggs · Packt · 2014 · ISBN 978-1782169735
  3. Linux Basics for Hackers - OccupyTheWeb · No Starch Press · 2019 · ISBN 978-1593278557
  4. Metasploit: The Penetration Tester's Guide (2nd Ed.) - David Kennedy et al. · No Starch Press · 2023 · ISBN 978-1718501237
  5. Metasploit Penetration Testing Cookbook - Abhinav Singh · Packt · 2012 · ISBN 978-1849517409
  6. Nmap 6: Network Exploration and Security Auditing Cookbook - Paulino Calderón Pale · Packt · 2012 · ISBN 978-1849517447
  7. Reconnaissance: Nmap and NSE Practical Guide - INVETECK GLOBAL · Educational material
  8. Hacking Android - Kotipalli, Imran · Packt · 2016 · ISBN 978-1785883149
  9. Developing Burp Suite Extensions - Luca Carettoni · DOYENSEC · Conference presentation
  10. Linux for Beginners - Noah Herrmann · Self-published · 2021
  11. How Linux Works (3rd Ed.) - Brian Ward · No Starch Press · 2021 · ISBN 978-1718500254
  12. Linux Command Line and Shell Scripting Bible (3rd Ed.) - Blum, Bresnahan · Wiley · 2015 · ISBN 978-1118983843
  13. Shell Scripting: Expert Recipes - Steve Parker · Wrox
  14. Ultimate Linux Projects - Future PLC (Linux Format) · 2022

V. Web & Network Security

  1. The Web Application Hacker's Handbook (2nd Ed.) - Stuttard, Pinto · Wiley · 2011 · ISBN 978-1118026472
  2. Web Application Security for Dummies - Mike Shema · Wiley · 2011 · ISBN 978-1119994879
  3. Network Security Assessment (3rd Ed.) - Chris McNab · O'Reilly · 2016 · ISBN 978-1491910955
  4. The Shellcoder's Handbook (2nd Ed.) - Anley, Heasman, Lindner, Richarte · Wiley · 2007 · ISBN 978-0470080238
  5. Web Scraping with Python (2nd Ed.) - Ryan Mitchell · O'Reilly
  6. SAST Scanners Cheat Sheet - WeHackPurple / @SheHacksPurple · Educational material
  7. Session Hijacking - Educational material
  8. SQL Injection - Comprehensive Guide - Educational material
  9. Learn SQL Using Squid Game - @codechips (Cody) · Educational material

VI. Wireless & Mobile Hacking

  1. WiFi Hacking for Beginners - James Wells · Self-published
  2. Kali Linux Wireless Pentesting and Security for Beginners - Hardeep Singh · 2017
  3. WiFi: Hack Proof Your Wireless Network - Barnes, Bautts, Lloyd et al. · Syngress
  4. Hacking HLR, HSS and MME Core Network Elements - Philippe Langlois · Black Hat USA 2014
  5. Hacking LTE Public Warning Systems - Weiguang Li · HAXPO Conference

VII. Reverse Engineering & Exploit Development

  1. Practical Reverse Engineering - Dang, Gazet, Bachaalany · Wiley · 2014 · ISBN 978-1118787311
  2. Mastering Reverse Engineering - Reginald Wong · Packt · 2018 · ISBN 978-1788832918
  3. Reverse Engineering for Beginners - Dennis Yurichev · Creative Commons · 2016
  4. Reverse Engineering for Beginners (Lite) - Dennis Yurichev · Creative Commons

VIII. Programming & Data Science for Security

  1. Black Hat Python - Justin Seitz · No Starch Press · 2014 · ISBN 978-1593275907
  2. Violent Python - TJ O'Connor · Syngress · 2012 · ISBN 978-1597499576
  3. Understanding Network Hacks: Attack and Defense with Python - Bastian Ballmann · Springer · 2015 · ISBN 978-3662444368
  4. Hacking with Python: The Ultimate Beginner's Guide - Steve Tale · Self-published · 2017
  5. Perl Programming for Beginners - Nathan Metzler · Lightbulb Publishing
  6. Malware Data Science - Joshua Saxe, Hillary Sanders · No Starch Press · 2018 · ISBN 978-1593278595
  7. Machine Learning Mastery with Python - Jason Brownlee · Machine Learning Mastery · 2016
  8. Deep Learning with Python - Jason Brownlee · Machine Learning Mastery · 2016
  9. Long Short-Term Memory Networks with Python - Jason Brownlee · Machine Learning Mastery · 2017
  10. Machine Learning with Python for Everyone - Mark E. Fenner · Addison-Wesley

IX. Social Engineering & Forensics

  1. Social Engineering: The Science of Human Hacking - Christopher Hadnagy · Wiley · 2018 · ISBN 978-1119433385
  2. The Art of Invisibility - Kevin Mitnick · Little, Brown & Company · 2017 · ISBN 978-0316380492
  3. Digital Forensics Explained (2nd Ed.) - Greg Gogolin · CRC Press · 2018 · ISBN 978-1138491029
  4. How to Hide Data in Audio Files (Steganography) - Ismael Nelson S. · Educational material

X. Dark Web & Lab Guides

  1. Dark Web: Exploring and Data Mining the Dark Side of the Web - Hsinchun Chen · Springer · 2012 · ISBN 978-1461415565
  2. Inside the Dark Web - Arun Adhikari · DARKNET
  3. Footprinting and Reconnaissance LAB - Chinni Diwakar · Educational material
  4. Sniffers LAB - Network Traffic Analysis & MITM - Chinni Diwakar · Educational material
  5. DOS LAB - Denial of Service Attack Techniques - Chinni Diwakar · Educational material
  6. Metasploit Framework Guide - Chinni Diwakar · Educational material
  7. System Hacking LAB - Chinni Diwakar · Educational material

❌ NEVER✅ ALWAYS
Test without written authorizationObtain written permission before any test
Use tools on systems you don't ownAct within the scope of your engagement
Share exploit code irresponsiblyFollow responsible disclosure practices
Violate local, state, or federal lawComply with all applicable laws and regulations

Unauthorized access to computer systems is a federal crime under the CFAA and equivalent laws worldwide. This repository is for educational purposes and authorized security testing only.

Authorized Use Cases

  • Professional penetration testing with signed client authorization
  • Security research in isolated lab environments you own
  • CTF (Capture the Flag) competitions
  • Homelab and educational practice on your own systems
  • Defensive security tooling and monitoring

See the full LEGAL.md for complete terms.


🏆 What Makes This Guide Different

FeatureDetail
📚 70+ professional books synthesizedComplete coverage from recognized industry experts
🏢 90+ PNWC internal docsReal operational experience - not just theory
🎯 10+ attack case studiesRoot cause, TTPs, IOCs, and defensive lessons analyzed
⚙️ 5 field-ready playbooksDrop-in procedures for professional engagements
🛠️ 15+ production scriptsTested automation tools ready to deploy
📡 20+ hardware devicesIoT and embedded security from real-world toolkit
🔍 400+ OSINT toolsOrganized by category with usage methodology
🤖 AI security workflowsSelf-hosted LLM integration for security operations
🎓 Cert-aligned contentOSCP · CEH · GPEN · CySA+ · CISSP mapped
🔁 Full lifecycle coverageOffense + Defense + Operations + Forensics

📬 Contributing & Contact

This is a personal operational knowledge base, but the security community thrives on shared knowledge.

Want to help the community?

  • Contribute to the open-source tools referenced here
  • Write and publish your own security research
  • Mentor newcomers entering the field
  • Practice responsible disclosure on vulnerabilities you find
  • Purchase the original books to support the authors

Use it wisely. Use it ethically. Use it legally.
Learn → Practice → Contribute back to the community. 🚀


Last Updated: June 2026 · Maintained by PNW Computers · Vancouver, WA

Categories