Terminal

Resources

Curated resources for learning and security research, useful tools, labs, scripts, documentation, references, and other resources worth keeping close.

Learning resources

Start here, in this order

  1. CTF progression — TryHackMe to HackTheBox

    Start on guided rooms where the answer is checked for you, then move to boxes where nothing tells you if you are close. The jump is the point: it is the first time you have to decide for yourself whether an idea is worth ten more minutes.

  2. Web security fundamentals — PortSwigger Academy

    Free, and still the most complete treatment of web vulnerability classes anywhere. Work the labs in order rather than cherry-picking: the later ones assume the mental model the earlier ones build.

  3. Certification prep — CPTS and OSCP

    Both reward methodology over tool knowledge. Keep a written enumeration checklist from day one and refine it every box; by exam day the checklist is the thing being tested, not your recall.

Roadmaps & certification prep

OWASP Top 10 (opens in a new tab)

The shared vocabulary for web risk. Worth reading as a document rather than a checklist — the reasoning behind each ranking is the useful part.

WebReferenceFree

MITRE ATT&CK (opens in a new tab)

Adversary behaviour catalogued as techniques rather than tools. The map both offence and defence plan against.

FrameworkThreat intelFree

YouTube Channels

Hak5 (opens in a new tab)

Hacking hardware, cybersecurity news, hardware tools, and general hacking tutorials.

YouTubeHardwareNews

STÖK (opens in a new tab)

Bug bounty methodology, vulnerability analysis, hacking tools, and industry mindset.

YouTubeBug BountyMethodology

Bugcrowd (opens in a new tab)

Official Bugcrowd channel covering bug bounty methodology, triage, and researcher interviews.

YouTubeBug BountyInterviews

DEFCON (opens in a new tab)

Presentation recordings and technical talks from the world famous DEF CON conference.

YouTubeConferenceHacking

13Cubed (opens in a new tab)

In-depth tutorials focused on digital forensics, incident response (DFIR), and security tools.

YouTubeDFIRForensics

Cybersecurity Podcasts

Tools & labs

Practice & CTF Platforms

TryHackMe (opens in a new tab)

Guided rooms with the theory built in. The gentlest on-ramp, and still useful for a topic you have never touched.

PlatformGuidedBeginner

OverTheWire (opens in a new tab)

Classic war games designed to teach security fundamentals, shell commands, and privilege escalation level by level.

WargamesLinuxBeginner

WebSec (opens in a new tab)

Dedicated collection of web-focused vulnerability challenges for testing web exploitation techniques.

CTFWebChallenges

PicoCTF (opens in a new tab)

Free computer security education program and gamified CTF created by security experts at Carnegie Mellon University.

CTFEducationBeginner

Root-Me (opens in a new tab)

Multi-disciplinary learning platform with hundreds of hacking challenges spanning web, network, and reverse engineering.

PlatformMulti-disciplinaryChallenges

Hacker101 (opens in a new tab)

Free educational program by HackerOne featuring video lessons, guides, and practice CTF challenges for bug hunters.

Bug BountyWebFree

HackThisSite (opens in a new tab)

Long-standing legal training ground offering interactive ethical hacking challenges, tutorials, and community forums.

ClassicWebCommunity

Pwn.tn (opens in a new tab)

CTF challenge platform focused on IT security vulnerabilities, reverse engineering, and exploitation practice.

CTFExploitationChallenges

Bug Bounty Platforms

Intigriti (opens in a new tab)

Global crowdsourced security and bug bounty platform connecting ethical hackers with organizations.

PlatformBug BountyCrowdsourced

Cobalt (opens in a new tab)

Pentest-as-a-Service and bug bounty platform connecting companies to elite security researchers.

PaaSBug BountyPentest

Bugcrowd (opens in a new tab)

Crowdsourced security testing platform providing bug bounty, vulnerability disclosure, and pentesting.

PlatformBug BountyCrowdsourced

Synack (opens in a new tab)

Invitation-only security platform connecting vetted ethical hackers with enterprise targets.

PlatformVettedEnterprise

BugBase (opens in a new tab)

Continuous vulnerability assessment platform designed for bug bounty programs and triage.

PlatformVulnerabilityAssessment

Browser Extensions

Security Tools & Utilities

Metasploit (opens in a new tab)

Penetration testing framework used for vulnerability discovery, exploit development, and post-exploitation.

FrameworkExploitationRed Team

Nmap (opens in a new tab)

Network discovery and security auditing tool for port scanning, service detection, and OS fingerprinting.

ToolNetworkScanning

RustScan (opens in a new tab)

Modern, high-performance port scanner built in Rust that automatically pipes open ports directly into Nmap.

ToolScanningRust

Naabu (opens in a new tab)

Fast, simple port scanner written in Go designed for fast SYN/CONNECT probes with high reliability.

ToolScanningGo

Wireshark (opens in a new tab)

The industry-standard network protocol analyzer for deep packet inspection and live traffic analysis.

ToolNetworkAnalysis

Nessus (opens in a new tab)

Vulnerability assessment scanner for automated asset discovery, vulnerability checks, and compliance auditing.

ToolScanningVulnerability

Ffuf (opens in a new tab)

Fast web fuzzer written in Go for directory discovery, virtual host enumeration, and parameter fuzzing.

ToolWebFuzzing

Amass (opens in a new tab)

OWASP network mapping tool for attack surface discovery and external asset identification using OSINT.

ToolReconOSINT

Recon-ng (opens in a new tab)

Full-featured Web Reconnaissance framework written in Python with modular OSINT gathering capability.

FrameworkOSINTRecon

Sublist3r (opens in a new tab)

Fast Python tool designed to enumerate subdomains using search engines and certificate transparency logs.

ToolReconSubdomains

Hashcat (opens in a new tab)

World's fastest GPU-accelerated password recovery utility supporting hundreds of hash algorithms.

ToolPasswordGPU

Ghidra (opens in a new tab)

The NSA's open-source reverse-engineering suite — a decompiler that holds its own against paid tools.

ToolReverse engineeringFree

News & blogs

Threat intel, original research, and the newsletters worth an inbox slot.

Communities & forums

Discord entries point at each platform's official hub page rather than temporary invite codes.

r/netsec (opens in a new tab)

A moderated feed of technical security content. The moderation keeps the signal-to-noise ratio high.

SubredditTechnicalCurated