
threat-hunting-guide
Structured guide to threat hunting using Zeek logs, aligned with MITRE ATT&CK framework for proactive detection of adversary tactics and techniques.

Structured guide to threat hunting using Zeek logs, aligned with MITRE ATT&CK framework for proactive detection of adversary tactics and techniques.

A collection of awesome framework, libraries, learning tutorials, videos, webcasts, technical resources and cool stuff about Interview for Security &…

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Daily YARA rule challenge and community collection where malware analysts share detection patterns, tips, and unconventional YARA uses to advance…

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

Remote hypervisor development class for security researchers; covers virtualization internals, hypervisor security, and vulnerabilities in privileged…

A collection of threat hunting and detection engineering Jupyter notebooks accompanying the Weekly Purple Team YouTube channel. Each notebook…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Curated collection of free, interactive AI-powered training materials for security awareness education, with community contributions and practical…

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

Comprehensive, open-source guide teaching online anonymity, OpSec, and identity protection techniques for activists, journalists, and…