TryHackMe learning paths (opens in a new tab)
Guided rooms with the theory built in. The gentlest on-ramp, and still the fastest way into a topic you have never touched.
Curated resources for learning and security research, useful tools, labs, scripts, documentation, references, and other resources worth keeping close.
Start here, in this order
Start on guided rooms where the answer is checked for you, then move to boxes where nothing tells you if you are close. The jump is the point: it is the first time you have to decide for yourself whether an idea is worth ten more minutes.
Free, and still the most complete treatment of web vulnerability classes anywhere. Work the labs in order rather than cherry-picking: the later ones assume the mental model the earlier ones build.
Both reward methodology over tool knowledge. Keep a written enumeration checklist from day one and refine it every box; by exam day the checklist is the thing being tested, not your recall.
Roadmaps & certification prep
TryHackMe learning paths (opens in a new tab)
Guided rooms with the theory built in. The gentlest on-ramp, and still the fastest way into a topic you have never touched.
OWASP Top 10 (opens in a new tab)
The shared vocabulary for web risk. Worth reading as a document rather than a checklist — the reasoning behind each ranking is the useful part.
MITRE ATT&CK (opens in a new tab)
Adversary behaviour catalogued as techniques rather than tools. The map both offence and defence plan against.
YouTube Channels
Hacking hardware, cybersecurity news, hardware tools, and general hacking tutorials.
Webpwnized (opens in a new tab)
Web application hacking tutorials, CTF walkthroughs, and Linux security fundamentals.
Practical hacking tutorials, CTF challenges, and hands-on cybersecurity projects.
Hackhappy (opens in a new tab)
Ethical hacking guides, CTF walkthroughs, and Linux administration.
Derek Rook (opens in a new tab)
Capture The Flag (CTF) video writeups and security challenge breakdowns.
John Hammond (opens in a new tab)
Malware analysis, programming, CTF walkthroughs, Linux, and infosec career advice.
Null Byte (opens in a new tab)
Ethical hacking tutorials and computer security guides for programmers and researchers.
HackerSploit (opens in a new tab)
Penetration testing courses, web app exploitation, Linux security, and malware analysis.
InsiderPhD (opens in a new tab)
Actionable educational guides on starting with bug bounty hunting and web security.
Bug bounty methodology, vulnerability analysis, hacking tools, and industry mindset.
LiveOverflow (opens in a new tab)
Deep dives into binary exploitation, CTF challenges, HackTheBox, and web security.
Detailed HackTheBox machine walkthroughs and CTF lab solution videos.
Peter Yaworski (opens in a new tab)
Web application hacking tips, bug bounty techniques, and security interviews.
Official Bugcrowd channel covering bug bounty methodology, triage, and researcher interviews.
The Cyber Mentor (opens in a new tab)
Ethical hacking training, web application testing, hardware tutorials, and tech reviews.
Educational bug bounty content, live reconnaissance streams, and career guidance.
Simply Cyber (opens in a new tab)
Cybersecurity career development, industry advice, and daily cybersecurity news updates.
Black Hat (opens in a new tab)
Official technical talks and briefings from Black Hat security conferences.
Presentation recordings and technical talks from the world famous DEF CON conference.
In-depth tutorials focused on digital forensics, incident response (DFIR), and security tools.
BlackPerl (opens in a new tab)
Malware analysis breakdowns, digital forensics, and incident response tutorials.
Computerphile (opens in a new tab)
Computer science concepts, cryptography explanations, network theory, and Linux internals.
Security Weekly (opens in a new tab)
Interviews and technical discussions with leading figures in cybersecurity.
Security Now (opens in a new tab)
Weekly breakdown of cybercrime news, vulnerabilities, and internet security protocols.
Infosec Institute (opens in a new tab)
Cybersecurity awareness training materials, career guides, and certification insights.
InfoSec Live (opens in a new tab)
All-around infosec streaming channel featuring security tutorials, discussions, and interviews.
The PC Security Channel (opens in a new tab)
Windows security deep dives, real-world malware testing, and defensive tech tutorials.
David Bombal (opens in a new tab)
Networking, Python, ethical hacking, Wireshark, and Cisco/CompTIA certification prep.
Barnacules Nerdgasm (opens in a new tab)
Tech reviews, hardware teardowns, 3D printing, and geek culture tutorials.
Linus Tech Tips (opens in a new tab)
Hardware benchmarking, PC building guides, technology overviews, and consumer reviews.
PC tech guides, Windows optimization tips, hardware reviews, and privacy guides.
Eli the Computer Guy (opens in a new tab)
Networking tutorials, Linux basics, web development, and hardware technology fundamentals.
Joe Collins (opens in a new tab)
Dedicated Linux desktop and server tutorials, distribution guides, and system tips.
NetworkChuck (opens in a new tab)
Engaging tutorials on computer networking, Python, cloud computing, and Linux fundamentals.
Professor Messer (opens in a new tab)
Free, complete training courses for CompTIA A+, Network+, and Security+ certification exams.
Cybersecurity Podcasts
Darknet Diaries (opens in a new tab)
True storytelling podcast covering hackers, malware, botnets, surveillance, and cybercrime.
Simply Cyber Podcast (opens in a new tab)
Daily cybersecurity news podcast and community platform helping pros advance their careers.
Smashing Security (opens in a new tab)
A lighthearted chat about cybercrime, internet privacy, and security breaches.
Hacking Humans (opens in a new tab)
Deconstructs the human element of security, social engineering, and phishing scams.
Fraudology (opens in a new tab)
Examines online fraud prevention, e-commerce security, payment abuse, and risk management.
The Brett Johnson Show (opens in a new tab)
Insights into cybercrime tactics, fraud prevention, and identity theft from a former cybercriminal.
What The Shell (opens in a new tab)
Accessible podcast exploring major cyber incidents, hacks, and vulnerabilities.
The Hacker Mind (opens in a new tab)
Original podcast highlighting security researchers, bug hunters, and vulnerability disclosures.
The Cyber Queens Podcast (opens in a new tab)
Empowers women, Gen-Z, and minorities to bridge the diversity gap in cybersecurity.
Cyber Warrior Studios (opens in a new tab)
Live discussions and audio podcasts covering self-improvement, career paths, and technical topics.
The Hacker Factory (opens in a new tab)
Hosted by Phillip Wylie, featuring interviews on breaking into and succeeding in infosec.
Practice & CTF Platforms
HackTheBox (opens in a new tab)
Unguided machines and multi-stage pro labs. The place to go once a walkthrough stops feeling necessary.
TryHackMe (opens in a new tab)
Guided rooms with the theory built in. The gentlest on-ramp, and still useful for a topic you have never touched.
Blue Team Labs Online (opens in a new tab)
The defensive counterpart: investigations, log analysis and incident response against realistic telemetry.
pwn.college (opens in a new tab)
Education platform breaking down cybersecurity concepts into interactive, hands-on learning dojos.
CyberDefenders (opens in a new tab)
Blue team training platform offering practical incident response, digital forensics, and threat hunting labs.
OverTheWire (opens in a new tab)
Classic war games designed to teach security fundamentals, shell commands, and privilege escalation level by level.
Dedicated collection of web-focused vulnerability challenges for testing web exploitation techniques.
RangeForce (opens in a new tab)
Simulated enterprise environments and hands-on exercises for defensive security skill building.
Free computer security education program and gamified CTF created by security experts at Carnegie Mellon University.
Multi-disciplinary learning platform with hundreds of hacking challenges spanning web, network, and reverse engineering.
PortSwigger Web Security Labs (opens in a new tab)
Comprehensive index of interactive web security labs covering real-world web vulnerability classes.
Hacker101 (opens in a new tab)
Free educational program by HackerOne featuring video lessons, guides, and practice CTF challenges for bug hunters.
Crowdsourced ethical hacking platform offering beginner-friendly and advanced CTF challenges.
Catalog of downloadable vulnerable virtual machines for offline boot-to-root laboratory testing.
HackThisSite (opens in a new tab)
Long-standing legal training ground offering interactive ethical hacking challenges, tutorials, and community forums.
CTF challenge platform focused on IT security vulnerabilities, reverse engineering, and exploitation practice.
Bug Bounty Platforms
Intigriti (opens in a new tab)
Global crowdsourced security and bug bounty platform connecting ethical hackers with organizations.
Pentest-as-a-Service and bug bounty platform connecting companies to elite security researchers.
Crowdsourced security testing platform providing bug bounty, vulnerability disclosure, and pentesting.
YesWeHack (opens in a new tab)
Global bug bounty and vulnerability management platform enabling agile security testing.
HackerOne (opens in a new tab)
Leading vulnerability coordination and bug bounty platform trusted by organizations worldwide.
Invitation-only security platform connecting vetted ethical hackers with enterprise targets.
Continuous vulnerability assessment platform designed for bug bounty programs and triage.
Open Bug Bounty (opens in a new tab)
Open, non-profit vulnerability disclosure platform allowing researchers to report web flaws.
Browser Extensions
Wappalyzer (opens in a new tab)
Technology profiler that identifies web technologies, CMS, frameworks, and analytics tools.
Displays open ports, services, and device information for the current website.
FoxyProxy (opens in a new tab)
Advanced proxy management tool to easily switch between proxies like Burp Suite or OWASP ZAP.
Cookie-Editor (opens in a new tab)
Simple cookie manager to quickly view, edit, create, or delete cookies for the active page.
User-Agent Switcher (opens in a new tab)
Quickly change and spoof your browser user-agent string to test mobile and device response.
Web security testing sidebar for manual SQLi, XSS, encoding, and hash payload injection.
BuiltWith (opens in a new tab)
Identifies framework, infrastructure, and web technology stacks running on websites.
Retire.js (opens in a new tab)
Scans web applications for vulnerable JavaScript libraries with known CVEs.
HTTP Header Live (opens in a new tab)
Real-time HTTP/HTTPS header inspector and modifier for request parameter debugging.
Tamper Data (opens in a new tab)
Interprets and modifies HTTP/HTTPS requests and header parameters on the fly.
HTTPS Everywhere (opens in a new tab)
Security extension that automatically rewrites requests to enforce encrypted HTTPS connections.
Blocks active content like JavaScript, Flash, and Java except on trusted white-listed domains.
Resurrect Pages (opens in a new tab)
Access cached and archived versions of pages using Wayback Machine, Google Cache, and Archive.is.
Penetration Testing Kit (opens in a new tab)
Comprehensive browser toolkit for web security testing, cookie auditing, and target analysis.
Passive web page scanner checking software versions against the Vulners CVE database.
Web Developer (opens in a new tab)
Extensive web development and testing toolbar with element inspection, DOM, and form controls.
Security Tools & Utilities
Metasploit (opens in a new tab)
Penetration testing framework used for vulnerability discovery, exploit development, and post-exploitation.
Burp Suite (opens in a new tab)
The intercepting proxy every web assessment runs through. The Community edition is enough to learn on.
ZAP (OWASP ZAP) (opens in a new tab)
Open-source web application security scanner and intercepting proxy for finding web vulnerabilities.
Network discovery and security auditing tool for port scanning, service detection, and OS fingerprinting.
Modern, high-performance port scanner built in Rust that automatically pipes open ports directly into Nmap.
Fast, simple port scanner written in Go designed for fast SYN/CONNECT probes with high reliability.
Wireshark (opens in a new tab)
The industry-standard network protocol analyzer for deep packet inspection and live traffic analysis.
Vulnerability assessment scanner for automated asset discovery, vulnerability checks, and compliance auditing.
Fast web fuzzer written in Go for directory discovery, virtual host enumeration, and parameter fuzzing.
High-performance URI/file, DNS subdomain, and VHOST brute-forcing tool written in Go.
Dirsearch (opens in a new tab)
Feature-rich command-line tool designed to brute-force directories and files on web servers.
HTTP parameter discovery suite that finds hidden query parameters for URL endpoints.
OWASP network mapping tool for attack surface discovery and external asset identification using OSINT.
Full-featured Web Reconnaissance framework written in Python with modular OSINT gathering capability.
Sublist3r (opens in a new tab)
Fast Python tool designed to enumerate subdomains using search engines and certificate transparency logs.
BloodHound (opens in a new tab)
Maps Active Directory as a graph, so a path to Domain Admin becomes a query rather than a hunch.
World's fastest GPU-accelerated password recovery utility supporting hundreds of hash algorithms.
John the Ripper (opens in a new tab)
Fast offline password cracker supporting dozens of hash and cipher types across operating systems.
CTF framework and exploit development library written in Python for rapid binary exploitation.
The NSA's open-source reverse-engineering suite — a decompiler that holds its own against paid tools.
What a Unix binary can be talked into doing when setuid or reachable through sudo.
CyberChef (opens in a new tab)
Encoding, decoding, decryption and data mangling as composable steps. Saves writing a throwaway script.
Threat intel, original research, and the newsletters worth an inbox slot.
Krebs on Security (opens in a new tab)
Long-form investigative reporting on cybercrime, usually well ahead of the trade press.
Google Project Zero (opens in a new tab)
Full technical write-ups of real zero-days, at a depth almost nothing else publishes.
PortSwigger Research (opens in a new tab)
Original web security research from the team behind Burp — new attack classes, not commentary.
SANS Internet Storm Center (opens in a new tab)
A daily diary of what is actually being scanned and exploited right now, written by handlers.
BleepingComputer (opens in a new tab)
Fast, reliable breach and ransomware reporting. Where stories break before mainstream media.
The Hacker News (opens in a new tab)
High-volume industry news. Useful as a wide net for what happened this week.
tl;dr sec (opens in a new tab)
A weekly newsletter summarising conference talks, tools and research.
Darknet Diaries (opens in a new tab)
Narrative interviews with people who were actually there — breaches, intrusions and arrests.
Risky Business (opens in a new tab)
A weekly news podcast with practitioner commentary rather than vendor talking points.
Discord entries point at each platform's official hub page rather than temporary invite codes.
A moderated feed of technical security content. The moderation keeps the signal-to-noise ratio high.
r/AskNetsec (opens in a new tab)
Where the questions go that r/netsec would remove. Genuinely useful for problem solving.
HackTheBox Discord (opens in a new tab)
The busiest room in offensive security practice with box-specific channels.
TryHackMe Discord (opens in a new tab)
Beginner-tolerant community hub. A reasonable first place to ask questions.
OWASP chapters (opens in a new tab)
Local, free and mostly in person. Meet practitioners working in application security.
The DFIR Report (opens in a new tab)
Full intrusion reports with timelines and detection opportunities based on real incidents.