home/toolvault

THE TOOL//VAULT

Every tool from the guide gets its own animated deep-dive: what it is, how to actually use it, the commands that matter, flag cheat-sheets and pro tips. 45 flagship guides are hand-written in depth; the rest follow true practitioner workflows.

0
tool guides
0
categories
0
flagship deep-dives
0
command demos typed*

πŸ–₯️ Security Operating Systems Β· 8

Security Operating Systems
BlackArch

Enormous arsenal on Arch Linux. Fantastic once you're comfortable with Linux β€” not day-one material.

30 min to first windive in β†’
Security Operating Systems
Commando VM

Turns a Windows VM into an attack box β€” perfect for Active Directory practice on the platform attackers actually target.

30 min to first windive in β†’
Security Operating Systems
FLARE VM

Mandiant's Windows box of debuggers/decompilers for safe malware study in an isolated VM.

30 min to first windive in β†’
Security Operating Systems
Kali Linux

Start here. Prebuilt with Nmap, Metasploit, Burp, Wireshark & 600 more. Free from kali.org β€” run it as a VM.

30 min to first windive in β†’
Security Operating Systems
Parrot Security OS

Beautiful, lighter on RAM (good for older laptops), includes anon tools like Tor/AnonSurf.

30 min to first windive in β†’
Security Operating Systems
REMnux

Preloaded with malware-dissection tools (Ghidra, PE tools, fake network services). Pair with Flare VM.

30 min to first windive in β†’
Security Operating Systems
Security Onion

Bundles Suricata, Zeek, Elastic, Kibana, CyberChef. Build this in your home lab = real blue-team experience on your resume.

30 min to first windive in β†’
Security Operating Systems
SIFT Workstation

DFIR toolkit matching SANS courses: timeline analysis, memory forensics, registry tools.

30 min to first windive in β†’

πŸ“‘ Recon & Scanning Β· 13

Recon & Scanning
Amass

OWASP's deep subdomain enumerator β€” discovers an org's forgotten dev/staging servers where bugs breed.

10 min to first windive in β†’
Recon & Scanning
Angry IP Scanner

Simple friendly GUI ping/port sweeper β€” handy for surveying your home lab.

10 min to first windive in β†’
Recon & Scanning
Censys

Shodan's scholarly sibling: internet-scan data + TLS certificate history to map any org's footprint.

10 min to first windive in β†’
Recon & Scanning
enum4linux-ng

Rips users, shares, and policy info out of Windows/Samba hosts. First stop on any box with SMB open.

10 min to first windive in β†’
Recon & Scanning
Masscan

Scans absurdly fast (the whole internet in minutes). Careless use = knocking on every door in town.

10 min to first windive in β†’
Recon & Scanning
Netcat (nc)

Read/write raw network connections: banner grab, chat, transfer files, catch reverse shells. Tiny tool, infinite uses.

10 min to first windive in β†’
Recon & Scanning
Nmap

The network scanner: discover hosts, open ports, service versions, OS, run scripted checks (-sC). Learn it until flags are muscle …

10 min to first windive in β†’
Recon & Scanning
Recon-ng

Modular web-recon framework with marketplace modules β€” automates the "who are they?" phase.

10 min to first windive in β†’
Recon & Scanning
Rustscan

Blazing-fast port scanner that pipes results into Nmap. CTF favourite: full port sweep in seconds.

10 min to first windive in β†’
Recon & Scanning
Shodan

The search engine of internet-connected devices: open cams, exposed databases, ICS gear. Recon without sending a single packet.

10 min to first windive in β†’
Recon & Scanning
subfinder

Fast passive subdomain discovery. Pipe into httpx β†’ live web targets in two commands.

10 min to first windive in β†’
Recon & Scanning
theHarvester

Harvests emails, subdomains, employee names from public sources β€” builds a phishing-target list (defenders: audit yourself!).

10 min to first windive in β†’
Recon & Scanning
Zenmap

Point-and-click Nmap with topology maps. Great while you memorise CLI flags.

10 min to first windive in β†’

🌐 Traffic Analysis · 8

Traffic Analysis
Bettercap

Modern MITM framework: ARP/DNS spoofing, wifi attacks, credential capture. The attacker's Wireshark.

15 min to first windive in β†’
Traffic Analysis
Brim / Zui

Beautiful desktop app for hunting through pcaps with Zed queries. Great intro to network forensics.

15 min to first windive in β†’
Traffic Analysis
Ettercap

Classic ARP-poisoning/MITM suite for your lab only. Seeing cleartext creds fly by teaches why TLS matters.

15 min to first windive in β†’
Traffic Analysis
NetworkMiner

Passive sniffer that rebuilds files, images, credentials from pcaps. Blue-team CTF darling.

15 min to first windive in β†’
Traffic Analysis
tcpdump

Terminal packet capture for servers and CTF boxes. The flags look scary; learn five and you're set.

15 min to first windive in β†’
Traffic Analysis
tshark

Scriptable Wireshark β€” extract fields from huge pcaps, perfect for CTF automation.

15 min to first windive in β†’
Traffic Analysis
Wireshark

The world's most-used protocol analyser. Capture traffic, follow TCP streams, carve files. Do the Wireshark TryHackMe room early.

15 min to first windive in β†’
Traffic Analysis
Zeek (Bro)

Turns raw traffic into structured logs (conn.log, dns.log, http.log). Core of network security monitoring & Security Onion.

15 min to first windive in β†’

🌏 Web App Testing · 13

Web App Testing
Browser DevTools

Already installed! Inspect requests, cookies, localStorage, JavaScript. Solve XSS labs with nothing else.

15 min to first windive in β†’
Web App Testing
Burp Suite

The web-tester's weapon #1: intercept, replay (Repeater), fuzz (Intruder), scan (Pro). Community Edition is free β€” learn it deeply…

15 min to first windive in β†’
Web App Testing
Caido

Fast, pretty newcomer for HTTP interception β€” nice alternative when Burp CE rate-limits Intruder.

15 min to first windive in β†’
Web App Testing
ffuf

"Fuzz Faster U Fool": fuzz parameters, dirs, vhosts at high speed with fine filters. CTF essential.

15 min to first windive in β†’
Web App Testing
Gobuster

Brute-forces hidden directories/files (/admin, /backup.zip), virtual hosts and subdomains.

15 min to first windive in β†’
Web App Testing
httpx

Probes huge host lists: which are live, what tech, what status. Glue tool of recon pipelines.

15 min to first windive in β†’
Web App Testing
Nikto

Veteran web server scanner: outdated software, dangerous files, misconfigs. Noisy β€” which is a lesson itself.

15 min to first windive in β†’
Web App Testing
Nuclei

Community template–driven scanner: thousands of one-click CVE/misconfig checks. Bug-bounty hunters live in it.

15 min to first windive in β†’
Web App Testing
OWASP ZAP

100% free/open from OWASP. Great for automated scans and CI pipelines. Teams often run both ZAP and Burp.

15 min to first windive in β†’
Web App Testing
Postman

APIs leak data constantly (see OWASP API Top 10). Postman is how you poke them methodically.

15 min to first windive in β†’
Web App Testing
sqlmap

Detects & exploits SQL injection automatically β€” even dumps databases. Learn manual SQLi first, then let sqlmap flex.

15 min to first windive in β†’
Web App Testing
Wappalyzer

Identifies CMS, frameworks, server tech on any site β€” shapes your attack plan instantly.

15 min to first windive in β†’
Web App Testing
WPScan

WordPress = 40%+ of the web. WPScan finds vulnerable plugins/themes and enumerates users.

15 min to first windive in β†’

πŸ’₯ Exploitation Β· 11

Exploitation
BeEF

Browser Exploitation Framework β€” demonstrates why XSS is terrifying: control the victim's browser in real time.

20 min to first windive in β†’
Exploitation
Chisel / Ligolo-ng

Relay traffic through compromised hosts to reach hidden networks β€” pivoting made simple.

20 min to first windive in β†’
Exploitation
Evil-WinRM

The comfortable way to land on Windows via WinRM with creds or a hash. HTB players' best friend.

20 min to first windive in β†’
Exploitation
Exploit-DB / Searchsploit

Offline copy of the Exploit Database. Found a service version? Searchsploit finds the public exploit. CTF daily driver.

20 min to first windive in β†’
Exploitation
Impacket

Python classes for attacking Windows protocols β€” the toolbox behind most AD exploitation and Kerberos attacks.

20 min to first windive in β†’
Exploitation
Metasploit Framework

The legendary exploit framework: 2,000+ modules, payloads and post-ex modules. The free "Metasploit Unleashed" course is a rite of…

20 min to first windive in β†’
Exploitation
Meterpreter

Metasploit's in-memory super-shell: file system control, keylogging, pivoting, privilege escalation β€” all living in RAM.

20 min to first windive in β†’
Exploitation
msfvenom

Metasploit's payload factory: generate shells for any platform/format. Learn payloads by building them.

20 min to first windive in β†’
Exploitation
NetExec (nxc)

CrackMapExec's successor: validate creds, spray, dump, execute across whole subnets. AD pentest essential.

20 min to first windive in β†’
Exploitation
Responder

Poisons LLMNR/NBT-NS on Windows networks and catches password hashes from thin air. Lab-only; shows why those protocols die in sec…

20 min to first windive in β†’
Exploitation
SET (Social-Engineer Toolkit)

TrustedSec's framework for authorized social-engineering simulations. Why "think before you click" training exists.

20 min to first windive in β†’

πŸ”‘ Password Attacks Β· 8

Password Attacks
CeWL

Spiders a website to build a company-flavoured wordlist ("AcmeCorp2026!"). Passwords come from culture β€” exploit it (with permissi…

10 min to first windive in β†’
Password Attacks
CrackStation / Name-That-Hash

Online rainbow-table lookup for quick checks; Name-That-Hash identifies unknown hash formats instantly.

10 min to first windive in β†’
Password Attacks
Hashcat

The fastest hash cracker on earth, powered by your GPU. Combine wordlists + rules to crack NTLM/SHA/etc. Benchmark it once β€” it's …

10 min to first windive in β†’
Password Attacks
Hydra

Parallel online login attacks against SSH/FTP/web forms/RDP. Use in labs; in the real world it locks accounts and trips alarms.

10 min to first windive in β†’
Password Attacks
John the Ripper

The classic cracker, superb on Linux/Unix hashes (/etc/shadow). Pairs with ssh2john/zip2john to crack archives & keys.

10 min to first windive in β†’
Password Attacks
Medusa

Hydra's stable, speedy cousin. Know both; they complement oddly-specific services.

10 min to first windive in β†’
Password Attacks
rockyou.txt

Ships with Kali (gzip'd at /usr/share/wordlists). The definitive wordlist β€” together with SecLists it forms 90% of password challe…

10 min to first windive in β†’
Password Attacks
SecLists

Daniel Miessler's curated collection for every wordlist need β€” especially web dirs and parameter names.

10 min to first windive in β†’

πŸͺœ Priv-Esc & Post-Exploitation Β· 10

Priv-Esc & Post-Exploitation
BloodHound

Maps Active Directory attack paths as a graph β€” reveals "Helpdeskβ†’3 hopsβ†’Domain Admin" chains instantly. Red and blue both swear b…

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
GTFOBins

Bible of Unix binaries that can be abused (sudo, SUID, capabilities) to escalate. Bookmark it forever.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
LinPEAS / WinPEAS

PEASS-ng scripts auto-enumerate Linux/Windows privilege-escalation vectors in screaming colour. Run them on every CTF box.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
linux-exploit-suggester

Compares kernel/distro versions against known local-exploit lists (DirtyCow era classic). LES + LinPEAS = the standard workflow.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
LOLBAS

Windows equivalent: legit Microsoft binaries attackers abuse (certutil download, mshta execution). Defenders monitor for these too…

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
Mimikatz

Extracts plaintext creds, hashes and tickets from Windows memory. The tool that made "credential hygiene" a boardroom topic.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
PowerUp / SharpUp

PowerSploit's Windows enumeration checks: unquoted service paths, weak service ACLs, AlwaysInstallElevated…

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
pspy

Watches every process spawning (even other users') without privileges β€” exposes cron scripts and mistyped passwords.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
Rubeus

The go-to for Kerberos attacks: kerberoasting, AS-REP roasting, ticket manipulation.

15 min to first windive in β†’
Priv-Esc & Post-Exploitation
Seatbelt

C# host enum swiss-army: who am I, what's here, what's defensible. Part of the standard C2 toolkit experience.

15 min to first windive in β†’

πŸ“Ά Wireless Β· 5

Wireless
Aircrack-ng suite

The complete Wi-Fi audit suite: monitor, capture handshakes, deauth, crack WPA keys. The official tutorial is a legendary first la…

30 min to first windive in β†’
Wireless
hcxdumptool + hcxtools

Modern clientless WPA attacks β€” grab a crackable hash without any client connected. Then feed hashcat.

30 min to first windive in β†’
Wireless
Kismet

Passive wireless sniffer/IDS β€” maps networks, detects rogue access points. The defender's wireless eyes.

30 min to first windive in β†’
Wireless
Reaver / Bully

Attacks WPS PIN weakness on older routers. Mostly dead on modern gear β€” but knowing why = interview points.

30 min to first windive in β†’
Wireless
Wifite

Automates Aircrack attacks end-to-end: WEP/WPA/WPS. Great for understanding the attack chain hands-on.

30 min to first windive in β†’

πŸ”¬ Digital Forensics Β· 12

Digital Forensics
Autopsy + Sleuth Kit

Free, friendly forensic platform for disk images. Recover deleted files, browser history, USB artifacts. The CyberDefenders labs p…

30 min to first windive in β†’
Digital Forensics
binwalk

Finds & extracts files hidden inside other files/firmware. First command in CTF forensics.

30 min to first windive in β†’
Digital Forensics
Eric Zimmerman's Tools

The definitive Windows artifact parsers. Real IR shops run on these. Free with training videos.

30 min to first windive in β†’
Digital Forensics
ExifTool

Reads/writes metadata in hundreds of formats. CTF stego staple; real-world leak detector (phones embed GPS!).

30 min to first windive in β†’
Digital Forensics
FTK Imager

Industry-standard imaging tool (free!). First rule of forensics: work on images, never originals.

30 min to first windive in β†’
Digital Forensics
KAPE

Eric Zimmerman's Kroll Artifact Parser & Extractor β€” grabs registry hives, event logs, browser data fast for offline analysis.

30 min to first windive in β†’
Digital Forensics
Plaso / log2timeline

Builds a unified timeline from disks, logs, browsers. Timelines answer "when, then what?" β€” the heart of IR storytelling.

30 min to first windive in β†’
Digital Forensics
Registry Explorer / Timeline Explorer

The friendly front-ends that make Windows forensics approachable while you learn the artifacts.

30 min to first windive in β†’
Digital Forensics
TestDisk + PhotoRec

Recover lost partitions and deleted files by signature β€” also handy when ransomware nukes a test VM.

30 min to first windive in β†’
Digital Forensics
Velociraptor

Open-source DFIR platform: hunt VQL queries across thousands of endpoints in seconds. Enterpise-grade and free.

30 min to first windive in β†’
Digital Forensics
Volatility 3

Analyse RAM captures: running processes, injected code, connections, credentials in memory. Memory never lies.

30 min to first windive in β†’
Digital Forensics
Wireshark (again)

Case captures constantly hide exfil in DNS/HTTP β€” carve it out and prove it.

30 min to first windive in β†’

🦠 Malware Analysis · 12

Malware Analysis
Any.Run

Interactive online sandbox: click like a user, watch processes/network in real time. Free tier + great public reports to learn fro…

30 min to first windive in β†’
Malware Analysis
Cutter + radare2

Free RE framework beloved by CTF players for binaries on any architecture.

30 min to first windive in β†’
Malware Analysis
Detect It Easy (DIE)

Identifies packers (UPX!), compilers, protections β€” step 1 before unpacking.

30 min to first windive in β†’
Malware Analysis
FakeNet-NG / INetSim

Simulate DNS/HTTP services in an isolated VM so malware reveals its C2 behaviour safely.

30 min to first windive in β†’
Malware Analysis
Ghidra

NSA's released RE suite β€” professional-grade and free. Disassemble, decompile, patch. Start with crackmes.

30 min to first windive in β†’
Malware Analysis
Hybrid Analysis

Free CrowdStrike sandbox β€” excellent static+dynamic reports when studying samples safely from your browser.

30 min to first windive in β†’
Malware Analysis
IDA Free

The famous Interactive Disassembler. Most tutorials/books use IDA β€” worth learning the UI early.

30 min to first windive in β†’
Malware Analysis
PEStudio

Instant suspicious-file triage: what it imports, what it pretends to be, MITRE mappings.

30 min to first windive in β†’
Malware Analysis
Procmon + Process Hacker

Windows dynamic-analysis eyes: see exactly what a program does. Sysinternals Suite is mandatory Windows study anyway.

30 min to first windive in β†’
Malware Analysis
VirusTotal

Lookup hashes/URLs across dozens of AV engines + sandbox telemetry. Daily reference for analysts. (Don't upload real secret files!…

30 min to first windive in β†’
Malware Analysis
x64dbg / x32dbg

Open-source Windows debugger for dynamic analysis and crackmes. Friendlier than WinDbg for beginners.

30 min to first windive in β†’
Malware Analysis
YARA

Write pattern rules to classify/hunt malware. Every SOC, sandbox and CTF uses YARA β€” learn the syntax day one.

30 min to first windive in β†’

πŸ›‘οΈ SOC & Defense Β· 12

SOC & Defense
Elastic Stack / Elastic SIEM

Elasticsearch + Kibana + Beats/Agents power countless SOCs. Learn KQL-style querying once, use it everywhere.

30 min to first windive in β†’
SOC & Defense
Fail2Ban

Tiny daemon that bans brute-forcers by tailing logs. Install on any internet-facing Linux box β€” and on day one of any VPS.

30 min to first windive in β†’
SOC & Defense
Graylog

FREE friendly log platform with streams, pipelines, alerts β€” a gentler first SIEM than the giants.

30 min to first windive in β†’
SOC & Defense
MITRE Caldera

Automated adversary emulation platform. Purple-team your lab: fire techniques, confirm your SIEM catches them.

30 min to first windive in β†’
SOC & Defense
pfSense

FreeBSD firewall/router distro β€” learn NAT, rules, VLANs, VPNs by actually building them. Core of serious home labs.

30 min to first windive in β†’
SOC & Defense
Shuffle SOAR

Drag-and-drop playbooks: alert β†’ enrich (VT, AbuseIPDB) β†’ block. Learn SOAR concepts free.

30 min to first windive in β†’
SOC & Defense
Sigma

The open standard for detections ("detect mimikatz-like process names"). Write one rule, run it in Splunk/Elastic anywhere.

30 min to first windive in β†’
SOC & Defense
Snort

The original open-source IDS (1998!) β€” still everywhere, still taught in certs. Learn rule syntax once: alert tcp any any β†’ any 44…

30 min to first windive in β†’
SOC & Defense
Splunk (Free)

The enterprise SIEM leader β€” free 500MB/day tier is plenty for a lab. Splunk skills = directly employable; free Fundamentals cours…

30 min to first windive in β†’
SOC & Defense
Suricata

Fast IDS/IPS using ET Open rules. Feed it homelab traffic, watch it bark at your own Nmap scans.

30 min to first windive in β†’
SOC & Defense
Sysmon

Turns Windows Event Logs from "meh" into a goldmine: process creation, network connections, loading of suspicious DLLs. Pair with …

30 min to first windive in β†’
SOC & Defense
Wazuh

Free open-source SIEM/XDR: file integrity, vulnerability detection, MITRE-mapped alerts. The best first blue-lab install.

30 min to first windive in β†’

πŸ•΅οΈ OSINT Β· 12

OSINT
AbuseIPDB

Crowdsourced IP abuse reports β€” the SOC's reflex check on every alert IP.

10 min to first windive in β†’
OSINT
BuiltWith / Wappalyzer

Profiles a company's web tech β†’ targets for both attacks and job interviews ("I see you use Splunk…").

10 min to first windive in β†’
OSINT
Google Dorking

Advanced search operators expose forgotten files, admin panels, cameras. Free, powerful, underrated β€” master the syntax.

10 min to first windive in β†’
OSINT
Have I Been Pwned

Troy Hunt's legendary service. Check your own accounts, enable the free notify-list. A household name in security.

10 min to first windive in β†’
OSINT
IntelTechniques Tools

Custom search consoles for social, breaches, maps & more from the author of "OSINT Techniques".

10 min to first windive in β†’
OSINT
Maltego CE

Visual intelligence graphs connecting people, domains, IPs, breaches. Free Community edition in Kali.

10 min to first windive in β†’
OSINT
OSINT Framework

Interactive tree of hundreds of OSINT resources by category (usernames, emails, images, leaks…).

10 min to first windive in β†’
OSINT
PhoneInfoga

Investigate phone numbers: Truecaller hits, disposable-number flags. Great for vishing investigations.

10 min to first windive in β†’
OSINT
Sherlock

Finds where a username exists across hundreds of platforms. Prolific for investigations (and self-auditing).

10 min to first windive in β†’
OSINT
SpiderFoot

Automates massive OSINT sweeps: DNS, breaches, emails, darknet mentions. Great for footprinting an org.

10 min to first windive in β†’
OSINT
TinEye / Google Lens

Trace images across the web: sock accounts fall apart fast with these.

10 min to first windive in β†’
OSINT
Wayback Machine

Historical snapshots of any site: find removed admin pages, old emails, "deleted" evidence.

10 min to first windive in β†’

🩹 Vulnerability Management · 4

Vulnerability Management
Greenbone / OpenVAS

Open-source enterprise-grade vulnerability scanner. Runs in your lab VM and produces pro-looking reports.

15 min to first windive in β†’
Vulnerability Management
Lynis

Audits a Linux host against best practices and tells you exactly what to fix. Run it on your own VPS for instant wins.

15 min to first windive in β†’
Vulnerability Management
Nessus Essentials

Tenable's famous scanner, free for home labs. Learn the interface β€” you'll meet it at work, guaranteed.

15 min to first windive in β†’
Vulnerability Management
SCAP / OpenSCAP + CIS-CAT

Automated compliance scoring against the famous CIS hardening benchmarks β€” GRC meets engineering.

15 min to first windive in β†’

🧰 CTF & Utilities · 12

CTF & Utilities
Aperi'Solve

One-stop online steganography triage for CTFs.

5 min to first windive in β†’
CTF & Utilities
CyberChef

GCHQ's "Cyber Swiss Army Knife": 300+ operations β€” encoding, crypto, compression, extraction. CTF oxygen.

5 min to first windive in β†’
CTF & Utilities
dCode.fr

Caesar to Vigenère to mystery hashes — classic-crypto challenges solved in seconds.

5 min to first windive in β†’
CTF & Utilities
Docker

Spin up vulnerable apps (Juice Shop!), tools and malware sandboxes without polluting your VM. Learn basic Docker β€” it's how labs a…

5 min to first windive in β†’
CTF & Utilities
HackTricks

The pentester's encyclopedia: every service, misconfig and technique with commands. The community's brain, free.

5 min to first windive in β†’
CTF & Utilities
Obsidian

Document every machine, command and lesson. Your notes become your portfolio and future self's gift.

5 min to first windive in β†’
CTF & Utilities
PayloadsAllTheThings

GitHub repo of curated payloads/methodologies (SQLi, XSS, SSRF…). CTF clipboard.

5 min to first windive in β†’
CTF & Utilities
RevShells.com

Every language's reverse/bind shell, plus URL/Base64 encoding. Saves real time in labs.

5 min to first windive in β†’
CTF & Utilities
Steghide / zsteg

Classic hidden-data tools (zsteg shines on PNG/BMP LSB data).

5 min to first windive in β†’
CTF & Utilities
tmux

Split screens for scan + listener + notes, and never lose a session. A pro's terminal looks like tmux.

5 min to first windive in β†’
CTF & Utilities
VirtualBox / VMware

Free hypervisors hosting your Kali + targets + SIEM. Section 09 builds on them. (VirtualBox is free; VMware Workstation Pro is now…

5 min to first windive in β†’
CTF & Utilities
WADComs

Interactive cheat-sheet for Windows/AD: filters by what you have (creds? shell?) and shows commands.

5 min to first windive in β†’

πŸ”‚ Personal Security Β· 7

Personal Security
Aegis / 2FAS (authenticator)

App-based MFA with encrypted backup. Turn MFA on for email first, then everything else.

10 min to first windive in β†’
Personal Security
Bitwarden

Open source, free, everywhere. Non-negotiable modern hygiene β€” password reuse is how people get owned.

10 min to first windive in β†’
Personal Security
KeePassXC

Fully offline alternative beloved by the paranoid (healthy paranoia). Kali users' default.

10 min to first windive in β†’
Personal Security
Mullvad / ProtonVPN

Reputable no-log VPNs for untrusted Wi-Fi. (A VPN is privacy hygiene, not magic invisibility.)

10 min to first windive in β†’
Personal Security
Signal

End-to-end encrypted messaging with sealed-sender design. Community standard.

10 min to first windive in β†’
Personal Security
uBlock Origin + Privacy Badger

Malvertising is a real attack vector. Harden your daily browser, too β€” you are a target now.

10 min to first windive in β†’
Personal Security
VeraCrypt

Free TrueCrypt successor β€” encrypt research, notes and VM drives on shared machines.

10 min to first windive in β†’
CYBER//ZERO ToolVault
147 animated tool guides, zero waffle.
✍️ Author LDM · ldmhub4u@gmail.com
guide v1 Β· v2 immersive Β· live news
Made for learners, everywhere Β· 2026
*approximate. and loving it.