Bookmarks Menu
Bookmarks Toolbar
Athena OS
- Athena OS Website
- Docker Hub Images
- Nix Configuration
- Project Source
- WSL - Microsoft Apps
Artificial Intelligence
- ChatGPT - OpenAI
- Colab - Welcome To Colab
- PyTorch - Documentation
- PyTorch - Zero to Mastery Learn PyTorch for Deep Learning
Bug Bounty Hunting
CVSS
- Common Vulnerability Scoring System SIG
- Common Vulnerability Scoring System Version 3.1 Calculator
HackerOne
- Bug Bounty Program - Complete List | HackerOne
- Hacker Mediation | HackerOne Platform Documentation
- HackerOne | #1 Trusted Security Platform and Hacker Program
- HackerOne Code of Conduct | Hacker101
- HackerOne Directory: Report Vulnerabilities to Companies' Security Teams
- Invitations | HackerOne Platform Documentation
- Submitting Reports | HackerOne Platform Documentation
- BugBounty.jp - ใใฐใใฆใณใใฃใปใใฉใใใใฉใผใ
- Bugcrowd - Crowdsourced Cybersecurity Platform
- CWE - Common Weakness Enumeration
- FireBounty - The Ultimate Vulnerability Disclosure Policy and Bug Bounty List!
- HackenProof - Web3 Bug Bounty platform for Crypto Projects
- Intigriti - Bug Bounty & Agile Pentesting Platform
- Open Bug Bounty - Free Bug Bounty Program and Coordinated Vulnerability Disclosure
- RedStorm - Bug Bounty
- Safehats - Bug Bounty Program | Vulnerability Disclosure
- Synack - Premier Security Testing Platform
- Vulnerability Lab - SECURITY VULNERABILITY RESEARCH LABORATORY - Best Bug Bounty Programs, Vulnerability Coordination and Bug Bounty Platform
- YesWeHack - Global Bug Bounty platform & VDP platform
- Yogosha - VOC / Vulnerability Operations Center
Crypto Tools
- Brainfuck/Text/Ook! Obfuscator-Deobfuscator
- Cipher Identifier
- CrackStation - Online Password Hash Cracking - MD5, SHA1, Linux, Rainbow Tables, etc.
- CrackStation's Password Cracking Dictionary (Pay what you want!)
- CyberChef
- Generate All Hashes - MD5, SHA1, SHA3, CRC32 - Online - Browserling Web Developer Tools
- Hash Encoders Online
- Hash Encryption and Reverse Decryption
- Hash Type Identifier - Check and validate your hash string
- Hashes - Decrypt MD5, SHA1, MySQL, NTLM, SHA256, SHA512, Wordpress, Bcrypt hashes for free online
- Hashkiller.io
- jwt.io - JSON Web Tokens
- rot13.com
- URL Decoder/Encoder
- Vigenรจre Cipher Online
- XOR Calculator Online
Events
- Cybersecurity Conferences [Updated Daily]
Exploit Databases
- Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers
- Rapid7 - Vulnerability & Exploit Database
- Vulnerability Database ๐ก
Hacking Platforms
- Hack The Box: Hacking Training For The Best | Individuals & Companies
- PentesterLab: Learn Web Penetration Testing: The Right Way
- PortSwigger Labs | Web Security Academy
- Proving Grounds | Offensive Security
- PWNX
- Root Me - Hacking and Information Security learning platform
- TryHackMe | Cyber Security Training
Hardware
- Flipper Zero - Portable Multi-tool Device for Geeks
- Hak5 - Hacking Tools & Media
- Maltronics - Pentesting Products
JavaScript
Deobfuscators
- JS NICE: Statistical renaming, Type inference and Deobfuscation
Formatters
- JavaScript Beautifier
- Prettier v2.3.2
Obfuscators
- aaencode - Encode any JavaScript program to Japanese style emoticons (^_^)
- Javascript Obfuscator - BeautifyTools.com
- JavaScript Obfuscator Tool
- jjencode - Encode any JavaScript program using only symbols
- JSFuck - Write any JavaScript with 6 Characters: []()!+
- JavaScript Minifier
- JSConsole
- JSFiddle - Code Playground
OSINT
Onion Network
- Onion Search Engine
- Ransomware Group Sites
- Torch : The Tor Search Engine
Sandbox
- Any Run - Interactive Online Malware Analysis Sandbox
- Hybrid Analysis - Free Automated Malware Analysis Service
Whois
- Central Ops - Free online network tools - traceroute, nslookup, dig, whois lookup, ping - IPv6
- Whois.com - Domain Names & Identity for Everyone
- abuse.ch | Fighting malware and botnets
- AsINT_Collection - start.me
- BreachDirectory - Check If Your Email or Username was Compromised
- Censys - Hosts and Certificates
- Cisco Talos Intelligence Group - Comprehensive Threat Intelligence
- CoinBlockerLists - Search
- commandergirl's suggestions - start.me
- crt.sh - Certificate Search
- d๏ปฟark.fai๏ปฟl: Which darknet sites are online?
- de๐ธdigger find public files in Google Drive
- Diff Checker - Compare the difference between images
- domain.glass - Domain DNS Record and WHOIS Information
- Forensic Magnifier - free online photo forensics tools - 29a.ch
- GrayhatWarfare - Public Buckets
- GreyNoise Visualizer
- Have I Been Pwned: Check if your email has been compromised in a data breach
- i2OCR - Free Online OCR
- ICANN Lookup
- Insecam - World biggest online cameras directory
- Intelligence X
- Maltiverse
- MX Lookup Tool - Check your DNS MX Records online - MxToolbox
- netograph.io ~ mapping the deep structure of the web.
- OSINT Framework
- Pulsedive - Threat Intelligence
- Rapid7 Open Data
- Scamalytics
- Shodan
- Squatm3gator - a complete web solution based on the python tool squatm3, designed to enumerate available domains generated modifying the original domain name through different cybersquatting techniques
- TinEye Reverse Image Search
- ViewDNS.info - Your one source for DNS related tools!
- Vigilante.pw โ The Breached Database Directory
- VirusTotal
- Wappalyzer - Find out what websites are built with
- WiGLE: Wireless Network Mapping
- xResolver โข Dashboard
- Yandex Images: search for images online or search by image
- ZorexEye - The Hacker's Search Engine
Resources
Application References
Hashcat
- example_hashes [hashcat wiki]
- mask_attack [hashcat wiki]
- rejection_rule_based_attack [hashcat wiki]
- rule_based_attack [hashcat wiki]
Nessus
- Nessus Report Downloader script
- Plugins (Nessus)
- Plugins | Tenableยฎ
- Scan and Policy Templates (Nessus)
- 10. Scanning a System โ Greenbone Security Manager (GSM) 6 documentation
OpenVAS
- OpenVAS Reporting: Convert OpenVAS XML report files to reports
- Scanning a System โ Greenbone Security Manager (GSM) 6 documentation
Privilege Escalation
Linux
- Checklist - Linux Privilege Escalation - HackTricks
- GitHub - rebootuser/LinEnum: Scripted Local Linux Enumeration & Privilege Escalation Checks
- GitHub - sleventyeleven/linuxprivchecker: linuxprivchecker.py -- a Linux Privilege Escalation Check Script
- GTFOBins
Windows
- Checklist - Local Windows Privilege Escalation - HackTricks
- GitHub - 411Hall/JAWS: JAWS - Just Another Windows (Enum) Script
- GitHub - GhostPack/Seatbelt: Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
- LOLBAS
- GitHub - carlospolop/privilege-escalation-awesome-scripts-suite: PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
SQLMap
- SQLMap - Boundaries
- SQLMap - Enumeration queries
- SQLMap - Payloads
- A Great Vim Cheat Sheet
- GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and Pentest/CTF
- HackTricks - HackTricks
- John The Ripper Hash Formats | pentestmonkey
- NMAP - Default NSE Category
- PayloadsAllTheThings/Bind Shell Cheatsheet.md at master ยท swisskyrepo/PayloadsAllTheThings ยท GitHub
- regex101: build, test, and debug regex
- Regulex๏ผJavaScript Regular Expression Visualizer
- Special Characters in HTML
- SQL Injection Cheat Sheet | pentestmonkey
- Tmux Cheat Sheet & Quick Reference
- Upgrading Simple Shells to Fully Interactive TTYs - ropnop blog
Blogs
- 0xdf hacks stuff | CTF solutions, malware analysis, home lab development
Books
- Hacking Multifactor Authentication | Wiley
Callback Servers
- GitHub - projectdiscovery/interactsh: An OOB interaction gathering server and client library
- Interact.sh | Web Client
- pingb.in
- Webhook.site - Test, process and transform emails and HTTP requests
- XSS Hunter
Laboratories
- GitHub - digininja/DVWA: Damn Vulnerable Web Application (DVWA)
- GitHub - rapid7/metasploitable3: Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
- Juice Shop - Insecure Web Application for Training | OWASP
- Metasploitable 2 Exploitability Guide | Metasploit Documentation
Network
- \(Cheat Sheet - Common Ports\) - common-ports.pdf
- Check ALL open ports, scan open ports online free tool
- Common Ports
- List of HTTP status codes - Wikipedia
- Subnet Calculator - NetworkCalc
- Top 1,000 TCP and UDP ports (nmap default)
Steganography
- 4qrcode - QR Code image reader
Tutorial Websites
- OverTheWire: Wargames
- UTW โ Under the Wireโฆ PowerShell Training for the People
Wordlists
- https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux
- https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows
Youtube
- IppSec - YouTube
- LiveOverflow - YouTube
- STรK - YouTube
- VbScrub - YouTube
- [TUT] Scan networks and perform DoS Attack
- [Tutorial] Guide to Cracking using STORM or other Cracking Softwares (NOOB Friendly)
- AttackerKB
- AutoRegex: Convert from English to RegEx with Natural Language Processing
- Best hacking books for aspiring hackers - Real life hacking scenarios
- Chapterย 14.ย iptables firewall
- CyberSpace Gitbook - CyberSpace
- Darknet Markets Tips
- Exploiting the xmlrpc.php on all WordPress versions
- File Inclusion/Path traversal - HackTricks
- Get-CIMInstance - PowerShell - SS64.com
- GitHub - fastfire/deepdarkCTI: Collection of Cyber Threat Intelligence sources from the deep and dark web
- HackTricks: pentesting-web
- Helpful free tools and resources.
- KMimeMagic
- List of file signatures - Wikipedia
- Maintaining Privacy and Security Online
- Metasploit anonymous question
- Recon Everything. Bug Bounty Hunting Tip #1- Always readโฆ | by SACHIN GROVER | InfoSec Write-ups
- Secure-Cookie
- Telegram: Contact @hacker_resources
- The Top 60 Rat Open Source Projects
- Tutorial for simple "bulletproof" setup
- URL-encoding Reference
- Windows Local Privilege Escalation - HackTricks
Reverse Shells
- PayloadsAllTheThings/Reverse Shell Cheatsheet.md at master ยท swisskyrepo/PayloadsAllTheThings ยท GitHub
- PentestMonkey - PHP Reverse Shell
- PentestMonkey - Reverse Shell Cheat Sheet
- Reverse Shell Cheat Sheet
- Reverse Shell Online Generator
Web Shells
- Interactive PHP webshell - GitHub
- Simple-Backdoor-One-Liner.php ยท GitHub