😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.
What I’m sharing here is a collection of some best resources about Hacking & Penetration Testing to make you learn faster! Let's make it the best resource repository for our community.
You are welcome to fork and contribute.
Also you can find my writeups/tutorials on medium: @hussnainfareed :)
| Name | Description |
|---|---|
| CTF Hacker101 | The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers. |
| Hack The Box :: Penetration Testing Labs | An online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs. |
| TryHackMe | TryHackMe is an online platform that teaches cyber security through short, gamified real-world labs. |
| CTF365 | An account-based ctf site, awarded by Kaspersky, MIT, and T-Mobile. |
| Backdoor | Pen testing labs that have a space for beginners, a practice arena, and various competitions, account required. |
| Hack.me | Lets you build/host/attack vulnerable web apps. |
| CTFLearn | An account-based ctf site, where users can go in and solve a range of challenges. |
| OWASP Vulnerable Web Applications Directory Project (Online) | List of online available vulnerable applications for learning purposes. |
| Pentestit labs | Hands-on Pentesting Labs (OSCP style) |
| Root-me.org | Hundreds of challenges are available to train yourself in different and not simulated environments |
| Vulnhub.com | Vulnerable By Design VMs for practical 'hands-on' experience in digital security |
| Windows / Linux Local Privilege Escalation Workshop | Practice your Linux and Windows privilege escalation. |
| Hacking Articles | CTF Brief Write-up collection with a lot of screenshots good for beginners. |
| Rafay Hacking Articles, a great blog | Write up collections by Rafay Baloch. |
| PentesterLab | 20$ signature, complete content basic to write exploits, web, android. |
| CyberSec WTF | Emulated web pentesting challenges from bounty write-ups |
| Pentest-Ground | Pentest Ground is a free playground with deliberately vulnerable web applications and network services. |
| pwn.guide | A cybersecurity education website, offering about 100 tutorials, ranging from web, wireless... hacking to defense tutorials & forensics. Offers free plan. |
| HTB Writeups | The most comprehensive collection of Hack The Box writeups on GitHub - 500+ machines, 400+ challenges, ProLabs, Sherlocks (DFIR), endgames, and CTF events with full walkthroughs. |
| Name | Description |
|---|---|
| Damn Vulnerable Xebia Training Environment | Docker Container including several vulnerable web applications (DVWA, DVWServices, DVWSockets, WebGoat, Juiceshop, Railsgoat, django.NV, Buggy Bank, Mutilidae II and more) |
| OopsSec Store | An intentionally vulnerable e-commerce app built with Next.js for web security training (OWASP Top 10, API security, CTF challenges). Quick start with npx create-oss-store. |
| OWASP Vulnerable Web Applications Directory Project (Offline) | List of offline available vulnerable applications for learning purposes |
Vulnerability Databases are the first place to start your day as a security professional. Any new vulnerability detection is generally available through the public vulnerability databases. These databases are a big source of information for hackers to be able to understand and exploit/avoid/fix the vulnerability.
| Name | Description |
|---|---|
| Malware traffic analysis | list of traffic analysis exercises |
| Malware Analysis - CSCI 4976 | another class from the folks at RPISEC, quality content |
| Bad Binaries | walkthrough documents of malware traffic analysis exercises and some occasional malware analysis. |
| Name | Description |
|---|---|
| Kali | the infamous pen-testing distro from the folks at Offensive Security |
| Parrot | Debian includes a full portable lab for security, DFIR, and development |
| Android Tamer | Android Tamer is a Virtual / Live Platform for Android Security professionals. |
| BlackArch | Arch Linux-based pentesting distro, compatible with Arch installs |
| LionSec Linux | pentesting OS based on Ubuntu |
| NullSec Linux | Security-focused distro with automotive hacking, forensics, and advanced pentesting tools |