Bookmarks Menu




Bookmarks Toolbar

Athena OS

Athena OS Website
Docker Hub Images
Nix Configuration
Project Source
WSL - Microsoft Apps

Artificial Intelligence

ChatGPT - OpenAI
Colab - Welcome To Colab
PyTorch - Documentation
PyTorch - Zero to Mastery Learn PyTorch for Deep Learning

Bug Bounty Hunting

CVSS

Common Vulnerability Scoring System SIG
Common Vulnerability Scoring System Version 3.1 Calculator

HackerOne

Bug Bounty Program - Complete List | HackerOne
Hacker Mediation | HackerOne Platform Documentation
HackerOne | #1 Trusted Security Platform and Hacker Program
HackerOne Code of Conduct | Hacker101
HackerOne Directory: Report Vulnerabilities to Companies' Security Teams
Invitations | HackerOne Platform Documentation
Submitting Reports | HackerOne Platform Documentation

BugBounty.jp - ใƒใ‚ฐใƒใ‚ฆใƒณใƒ†ใ‚ฃใƒปใƒ—ใƒฉใƒƒใƒˆใƒ•ใ‚ฉใƒผใƒ 
Bugcrowd - Crowdsourced Cybersecurity Platform
CWE - Common Weakness Enumeration
FireBounty - The Ultimate Vulnerability Disclosure Policy and Bug Bounty List!
HackenProof - Web3 Bug Bounty platform for Crypto Projects
Intigriti - Bug Bounty & Agile Pentesting Platform
Open Bug Bounty - Free Bug Bounty Program and Coordinated Vulnerability Disclosure
RedStorm - Bug Bounty
Safehats - Bug Bounty Program | Vulnerability Disclosure
Synack - Premier Security Testing Platform
Vulnerability Lab - SECURITY VULNERABILITY RESEARCH LABORATORY - Best Bug Bounty Programs, Vulnerability Coordination and Bug Bounty Platform
YesWeHack - Global Bug Bounty platform & VDP platform
Yogosha - VOC / Vulnerability Operations Center

Crypto Tools

Brainfuck/Text/Ook! Obfuscator-Deobfuscator
Cipher Identifier
CrackStation - Online Password Hash Cracking - MD5, SHA1, Linux, Rainbow Tables, etc.
CrackStation's Password Cracking Dictionary (Pay what you want!)
CyberChef
Generate All Hashes - MD5, SHA1, SHA3, CRC32 - Online - Browserling Web Developer Tools
Hash Encoders Online
Hash Encryption and Reverse Decryption
Hash Type Identifier - Check and validate your hash string
Hashes - Decrypt MD5, SHA1, MySQL, NTLM, SHA256, SHA512, Wordpress, Bcrypt hashes for free online
Hashkiller.io
jwt.io - JSON Web Tokens
rot13.com
URL Decoder/Encoder
Vigenรจre Cipher Online
XOR Calculator Online

Events

Cybersecurity Conferences [Updated Daily]

Exploit Databases

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers
Rapid7 - Vulnerability & Exploit Database
Vulnerability Database ๐Ÿ›ก

Hacking Platforms

Hack The Box: Hacking Training For The Best | Individuals & Companies
PentesterLab: Learn Web Penetration Testing: The Right Way
PortSwigger Labs | Web Security Academy
Proving Grounds | Offensive Security
PWNX
Root Me - Hacking and Information Security learning platform
TryHackMe | Cyber Security Training

Hardware

Flipper Zero - Portable Multi-tool Device for Geeks
Hak5 - Hacking Tools & Media
Maltronics - Pentesting Products

JavaScript

Deobfuscators

JS NICE: Statistical renaming, Type inference and Deobfuscation

Formatters

JavaScript Beautifier
Prettier v2.3.2

Obfuscators

aaencode - Encode any JavaScript program to Japanese style emoticons (^_^)
Javascript Obfuscator - BeautifyTools.com
JavaScript Obfuscator Tool
jjencode - Encode any JavaScript program using only symbols
JSFuck - Write any JavaScript with 6 Characters: []()!+

JavaScript Minifier
JSConsole
JSFiddle - Code Playground

OSINT

Onion Network

Onion Search Engine
Ransomware Group Sites
Torch : The Tor Search Engine

Sandbox

Any Run - Interactive Online Malware Analysis Sandbox
Hybrid Analysis - Free Automated Malware Analysis Service

Whois

Central Ops - Free online network tools - traceroute, nslookup, dig, whois lookup, ping - IPv6
Whois.com - Domain Names & Identity for Everyone

abuse.ch | Fighting malware and botnets
AsINT_Collection - start.me
BreachDirectory - Check If Your Email or Username was Compromised
Censys - Hosts and Certificates
Cisco Talos Intelligence Group - Comprehensive Threat Intelligence
CoinBlockerLists - Search
commandergirl's suggestions - start.me
crt.sh - Certificate Search
d๏ปฟark.fai๏ปฟl: Which darknet sites are online?
de๐Ÿ”ธdigger find public files in Google Drive
Diff Checker - Compare the difference between images
domain.glass - Domain DNS Record and WHOIS Information
Forensic Magnifier - free online photo forensics tools - 29a.ch
GrayhatWarfare - Public Buckets
GreyNoise Visualizer
Have I Been Pwned: Check if your email has been compromised in a data breach
i2OCR - Free Online OCR
ICANN Lookup
Insecam - World biggest online cameras directory
Intelligence X
Maltiverse
MX Lookup Tool - Check your DNS MX Records online - MxToolbox
netograph.io ~ mapping the deep structure of the web.
OSINT Framework
Pulsedive - Threat Intelligence
Rapid7 Open Data
Scamalytics
Shodan
Squatm3gator - a complete web solution based on the python tool squatm3, designed to enumerate available domains generated modifying the original domain name through different cybersquatting techniques
TinEye Reverse Image Search
ViewDNS.info - Your one source for DNS related tools!
Vigilante.pw โ€ The Breached Database Directory
VirusTotal
Wappalyzer - Find out what websites are built with
WiGLE: Wireless Network Mapping
xResolver โ€ข Dashboard
Yandex Images: search for images online or search by image
ZorexEye - The Hacker's Search Engine

Resources

Application References

Hashcat

example_hashes [hashcat wiki]
mask_attack [hashcat wiki]
rejection_rule_based_attack [hashcat wiki]
rule_based_attack [hashcat wiki]

Nessus

Nessus Report Downloader script
Plugins (Nessus)
Plugins | Tenableยฎ
Scan and Policy Templates (Nessus)
10. Scanning a System โ€” Greenbone Security Manager (GSM) 6 documentation

OpenVAS

OpenVAS Reporting: Convert OpenVAS XML report files to reports
Scanning a System โ€” Greenbone Security Manager (GSM) 6 documentation

Privilege Escalation

Linux

Checklist - Linux Privilege Escalation - HackTricks
GitHub - rebootuser/LinEnum: Scripted Local Linux Enumeration & Privilege Escalation Checks
GitHub - sleventyeleven/linuxprivchecker: linuxprivchecker.py -- a Linux Privilege Escalation Check Script
GTFOBins

Windows

Checklist - Local Windows Privilege Escalation - HackTricks
GitHub - 411Hall/JAWS: JAWS - Just Another Windows (Enum) Script
GitHub - GhostPack/Seatbelt: Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
LOLBAS

GitHub - carlospolop/privilege-escalation-awesome-scripts-suite: PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

SQLMap

SQLMap - Boundaries
SQLMap - Enumeration queries
SQLMap - Payloads

A Great Vim Cheat Sheet
GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and Pentest/CTF
HackTricks - HackTricks
John The Ripper Hash Formats | pentestmonkey
NMAP - Default NSE Category
PayloadsAllTheThings/Bind Shell Cheatsheet.md at master ยท swisskyrepo/PayloadsAllTheThings ยท GitHub
regex101: build, test, and debug regex
Regulex๏ผšJavaScript Regular Expression Visualizer
Special Characters in HTML
SQL Injection Cheat Sheet | pentestmonkey
Tmux Cheat Sheet & Quick Reference
Upgrading Simple Shells to Fully Interactive TTYs - ropnop blog

Blogs

0xdf hacks stuff | CTF solutions, malware analysis, home lab development

Books

Hacking Multifactor Authentication | Wiley

Callback Servers

GitHub - projectdiscovery/interactsh: An OOB interaction gathering server and client library
Interact.sh | Web Client
pingb.in
Webhook.site - Test, process and transform emails and HTTP requests
XSS Hunter

Laboratories

GitHub - digininja/DVWA: Damn Vulnerable Web Application (DVWA)
GitHub - rapid7/metasploitable3: Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
Juice Shop - Insecure Web Application for Training | OWASP
Metasploitable 2 Exploitability Guide | Metasploit Documentation

Network

\(Cheat Sheet - Common Ports\) - common-ports.pdf
Check ALL open ports, scan open ports online free tool
Common Ports
List of HTTP status codes - Wikipedia
Subnet Calculator - NetworkCalc
Top 1,000 TCP and UDP ports (nmap default)

Steganography

4qrcode - QR Code image reader

Tutorial Websites

OverTheWire: Wargames
UTW โ€“ Under the Wireโ€ฆ PowerShell Training for the People

Wordlists

https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux
https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows

Youtube

IppSec - YouTube
LiveOverflow - YouTube
STร–K - YouTube
VbScrub - YouTube

[TUT] Scan networks and perform DoS Attack
[Tutorial] Guide to Cracking using STORM or other Cracking Softwares (NOOB Friendly)
AttackerKB
AutoRegex: Convert from English to RegEx with Natural Language Processing
Best hacking books for aspiring hackers - Real life hacking scenarios
Chapterย 14.ย iptables firewall
CyberSpace Gitbook - CyberSpace
Darknet Markets Tips
Exploiting the xmlrpc.php on all WordPress versions
File Inclusion/Path traversal - HackTricks
Get-CIMInstance - PowerShell - SS64.com
GitHub - fastfire/deepdarkCTI: Collection of Cyber Threat Intelligence sources from the deep and dark web
HackTricks: pentesting-web
Helpful free tools and resources.
KMimeMagic
List of file signatures - Wikipedia
Maintaining Privacy and Security Online
Metasploit anonymous question
Recon Everything. Bug Bounty Hunting Tip #1- Always readโ€ฆ | by SACHIN GROVER | InfoSec Write-ups
Secure-Cookie
Telegram: Contact @hacker_resources
The Top 60 Rat Open Source Projects
Tutorial for simple "bulletproof" setup
URL-encoding Reference
Windows Local Privilege Escalation - HackTricks

Reverse Shells

PayloadsAllTheThings/Reverse Shell Cheatsheet.md at master ยท swisskyrepo/PayloadsAllTheThings ยท GitHub
PentestMonkey - PHP Reverse Shell
PentestMonkey - Reverse Shell Cheat Sheet
Reverse Shell Cheat Sheet
Reverse Shell Online Generator

Web Shells

Interactive PHP webshell - GitHub
Simple-Backdoor-One-Liner.php ยท GitHub