
This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and Step-by-Step Guides across various critical security domains. Content is sourced from industry-leading books and technical presentations, focusing on practical application rather than JUST theory.
Compiled from 70+ expert books · 90+ PNWC internal documents · custom tools & scripts
Abide by the Legal Terms of Use & Disclaimer for the use and misuse of this repository.
"Under pressure, you don't rise to the occasion; you fall to the level of your training."
"It ain't what you don't know that gets you into trouble. It's what you know for sure that just ain't so."
Your complete navigation guide with quick paths for every role and purpose (Red Team, Blue Team, OSINT, Forensics, Homelab, Career).
Content sourced from PNWC's internal Notion knowledge base and real-world operations - not found in textbooks.
Purple Team
Blue Team
Detection Pipeline & SIEM
pnwc_install_tools.sh - Cross-distro Linux installer for all tools in this guide (apt · pacman · dnf)Scripts/Bash/)Scripts/GO/)Multi-tools: Flipper Zero · WiFi Pineapple · Proxmark3
Field-side cybersecurity requires reliable, highly-portable hardware. This new section is dedicated to the ClockworkPi uConsole. It includes step-by-step documentation on turning the uConsole into a dedicated cyberdeck for mobile operations.
Hak5 Suite: Rubber Ducky · Bash Bunny · LAN Turtle · Packet Squirrel · Shark Jack · O.MG Cable
RF / SDR: HackRF One · RTL-SDR · Ubertooth One · YardStick One
WiFi Adapters: Alfa AWUS036ACH · Alfa AWUS036NHA · TP-Link TL-WN722N
This guide stands on the shoulders of the global cybersecurity community.
Exploitation & Post-Exploitation
OSINT
Network & Web Security
Password & Credentials
Wireless & RF
Forensics & Reverse Engineering
Monitoring & Defense
No Starch Press (primary reference publisher)
Other key works: Ryan Barnett (Black Hat Bash) · Travis Goodspeed (Microcontroller Exploits) · Seth Enoka (Cybersecurity for Small Networks) · Peter Kim (The Hacker Playbook 3) · Ben Clark (RTFM / BTFM) · Christopher Hadnagy (Social Engineering) · Kevin Mitnick (The Art of Invisibility)
See the full 78-entry bibliography below.
Kali Linux · BlackArch · Parrot Security OS · BackBox · Tails · Whonix
MITRE ATT&CK · OWASP · NIST NVD · CVE · CISA · SANS
HackTheBox · TryHackMe · VulnHub · OverTheWire · PentesterLab
TryHackMe FREE Roadmap - 350+ free rooms, beginner → advanced, curated by Uttambodara
Tor Project · Mullvad VPN · ProtonVPN · IVPN VeraCrypt · ProtonMail · Signal
Offensive Security (OSCP, OSEP, OSCE) · EC-Council (CEH, CHFI) · GIAC (GPEN, GWAPT, GCIH) · CompTIA (Security+, PenTest+, CySA+) · (ISC)² (CISSP)
Kevin Mitnick (1963–2023) · Bruce Schneier · Dan Kaminsky (1979–2021) · HD Moore · Tavis Ormandy · Marcus Hutchins · Brian Krebs · Troy Hunt · Katie Moussouris · Parisa Tabriz · The Grugq · and countless others
| ❌ NEVER | ✅ ALWAYS |
|---|---|
| Test without written authorization | Obtain written permission before any test |
| Use tools on systems you don't own | Act within the scope of your engagement |
| Share exploit code irresponsibly | Follow responsible disclosure practices |
| Violate local, state, or federal law | Comply with all applicable laws and regulations |
Unauthorized access to computer systems is a federal crime under the CFAA and equivalent laws worldwide. This repository is for educational purposes and authorized security testing only.
See the full LEGAL.md for complete terms.
This is a personal operational knowledge base, but the security community thrives on shared knowledge.
Want to help the community?
Use it wisely. Use it ethically. Use it legally.
Learn → Practice → Contribute back to the community. 🚀
Last Updated: June 2026 · Maintained by PNW Computers · Vancouver, WA
| Guide | Description |
|---|
| 🔥 Ultimate Cybersecurity Master Guide | THE main comprehensive guide - key takeaways from 70+ professional security books, full penetration testing lifecycle |
| 🔥 Enhanced Cybersecurity Master Guide | All of the above + 90+ PNWC internal docs, KB articles, and operational experience layered in |
| 🔥 Specialized Topics Guide | Deep-dive into specialized/emerging domains: AI & LLM Security, Hardware Hacking, Hardware Testing, uConsole Cyberdeck, Space Security, SDR & RF Security |
| Resource | Description |
|---|
| Cybersecurity Cliff Notes | Quick command reference; the essentials at a glance |
| Advanced Techniques - Part 1 | Advanced Metasploit, cloud pentesting, lateral movement, pivoting, etc. |
| Advanced Techniques - Part 2 | Exploit development, buffer overflows, shellcode, custom payloads, etc. |
| DIY Hardware & Firmware Compatibility | SBC-based DIY pentesting devices as well as compatibility & firmware guides |
| Debian Linux Command Cheat Sheet | Linux CLI commands for Debian/Ubuntu/Kali/Parrot |
| Arch Linux Command Cheat Sheet | Linux CLI commands for Arch |
| BlackArch Linux Cheat Sheet | Linux CLI commands for BlackArch |
| OSINT Cheat Sheet | Quick-reference OSINT cheat sheet |
| Section | Description |
|---|
| 📋 Operational Playbooks | Full index of all playbooks - network audits, WiFi assessments, IR, phishing, unauthorized access |
| 🟣 Purple Team Playbooks | Simple, Detailed, and Multi-Script purple team exercises |
| 🔵 Blue Team Playbooks | Incident response procedures - simple and enhanced versions |
| 🔬 Network Audit Playbook | Field-ready professional network security audit procedure |
| 🎣 SOP: Phishing Analysis | Standard operating procedure for phishing email triage |
| 🚷 Unauthorized Access Investigation | Playbook for investigating unauthorized access incidents |
| 🚨 Incident Response | Blue Team operations - threat detection, log aggregation, artifact analysis, standardized response procedures |
| 📊 SIEM Deployment Guides | ELK Stack, Wazuh, Splunk, and Graylog setup and configuration |
| 🔍 OSINT Guide, Tools & Techniques | Comprehensive OSINT methodology - 400+ categorized tools, investigation workflows, automated VM setup |
| 🔴 OPSEC | Operational security practices - anonymity workflows, VM setup, personal rules for professionals |
| 🏠 Homelab Guides | Building and maintaining safe, isolated labs for offensive and defensive practice |
| 🤖 AI Cybersecurity Resources | Self-hosted AI agents (OpenClaw, AnythingLLM), LLM prompting for security, offline AI deployment, AI-powered security workflows |
| 👾 Space Security | Offensive and defensive security across the three segments of modern space systems |
| 📻 SDR | Software Defined Radio theory, practice, and applications |
| 🥷 Hardware Hacking | Physical and electronic attack techniques against embedded systems, microcontrollers, SoCs, and cryptographic hardware |
| 🧰 Hardware Testing | Diagnostic, benchmarking, and reliability stress testing guides and scripts for PC test benches |
| 📟 uConsole | Configuration, portable pentesting setups, and operational workflows optimized for the ClockworkPi uConsole cyberdeck. |
| 📱 Mobile Security | Kali NetHunter on OnePlus 6 (rooting, install, field SOPs), Android/iOS app pentesting, mobile forensics, and engagement-level mobile pentest SOP |
| 💻 Scripts | Security automation scripts, exploitation tools, recon utilities, and utility programs |
| 📋 Checklists | Pre-engagement, testing, and post-engagement checklists |
| 📄 PDF Resources | Curated PDF references and guides |
| 📚 Documentation | Supplemental technical documentation and cheat sheets |
| Incident | Type |
|---|
| Stuxnet | Nation-state cyberweapon - Iranian nuclear facilities |
| WannaCry | Global ransomware outbreak |
| EternalBlue / NSA Leak | NSA exploit leaked by Shadow Brokers |
| SolarWinds | Software supply chain compromise |
| Carbanak | APT banking theft campaign |
| NotPetya | Destructive malware disguised as ransomware |
| Edward Snowden / NSA | Mass surveillance program revelations |
| + 3 additional major data breach case studies | Analysis of root cause, TTPs, and defensive lessons |
| Category | Count |
|---|
| Expert books referenced | 70+ |
| PNWC internal docs | 90+ |
| Lines of content | 9,600+ |
| OSINT tools catalogued | 400+ |
| Operational playbooks | 5 |
| Custom scripts | 15+ |
| Attack case studies | 10+ |
| Hardware devices documented | 20+ |
| Feature | Detail |
|---|
| 📚 70+ professional books synthesized | Complete coverage from recognized industry experts |
| 🏢 90+ PNWC internal docs | Real operational experience - not just theory |
| 🎯 10+ attack case studies | Root cause, TTPs, IOCs, and defensive lessons analyzed |
| ⚙️ 5 field-ready playbooks | Drop-in procedures for professional engagements |
| 🛠️ 15+ production scripts | Tested automation tools ready to deploy |
| 📡 20+ hardware devices | IoT and embedded security from real-world toolkit |
| 🔍 400+ OSINT tools | Organized by category with usage methodology |
| 🤖 AI security workflows | Self-hosted LLM integration for security operations |
| 🎓 Cert-aligned content | OSCP · CEH · GPEN · CySA+ · CISSP mapped |
| 🔁 Full lifecycle coverage | Offense + Defense + Operations + Forensics |