π₯οΈ Security Operating Systems Β· 8
Enormous arsenal on Arch Linux. Fantastic once you're comfortable with Linux β not day-one material.
Turns a Windows VM into an attack box β perfect for Active Directory practice on the platform attackers actually target.
Mandiant's Windows box of debuggers/decompilers for safe malware study in an isolated VM.
Start here. Prebuilt with Nmap, Metasploit, Burp, Wireshark & 600 more. Free from kali.org β run it as a VM.
Beautiful, lighter on RAM (good for older laptops), includes anon tools like Tor/AnonSurf.
Preloaded with malware-dissection tools (Ghidra, PE tools, fake network services). Pair with Flare VM.
Bundles Suricata, Zeek, Elastic, Kibana, CyberChef. Build this in your home lab = real blue-team experience on your resume.
DFIR toolkit matching SANS courses: timeline analysis, memory forensics, registry tools.
π‘ Recon & Scanning Β· 13
OWASP's deep subdomain enumerator β discovers an org's forgotten dev/staging servers where bugs breed.
Simple friendly GUI ping/port sweeper β handy for surveying your home lab.
Shodan's scholarly sibling: internet-scan data + TLS certificate history to map any org's footprint.
Rips users, shares, and policy info out of Windows/Samba hosts. First stop on any box with SMB open.
Scans absurdly fast (the whole internet in minutes). Careless use = knocking on every door in town.
Read/write raw network connections: banner grab, chat, transfer files, catch reverse shells. Tiny tool, infinite uses.
The network scanner: discover hosts, open ports, service versions, OS, run scripted checks (-sC). Learn it until flags are muscle β¦
Modular web-recon framework with marketplace modules β automates the "who are they?" phase.
Blazing-fast port scanner that pipes results into Nmap. CTF favourite: full port sweep in seconds.
The search engine of internet-connected devices: open cams, exposed databases, ICS gear. Recon without sending a single packet.
Fast passive subdomain discovery. Pipe into httpx β live web targets in two commands.
Harvests emails, subdomains, employee names from public sources β builds a phishing-target list (defenders: audit yourself!).
Point-and-click Nmap with topology maps. Great while you memorise CLI flags.
π Traffic Analysis Β· 8
Modern MITM framework: ARP/DNS spoofing, wifi attacks, credential capture. The attacker's Wireshark.
Beautiful desktop app for hunting through pcaps with Zed queries. Great intro to network forensics.
Classic ARP-poisoning/MITM suite for your lab only. Seeing cleartext creds fly by teaches why TLS matters.
Passive sniffer that rebuilds files, images, credentials from pcaps. Blue-team CTF darling.
Terminal packet capture for servers and CTF boxes. The flags look scary; learn five and you're set.
Scriptable Wireshark β extract fields from huge pcaps, perfect for CTF automation.
The world's most-used protocol analyser. Capture traffic, follow TCP streams, carve files. Do the Wireshark TryHackMe room early.
Turns raw traffic into structured logs (conn.log, dns.log, http.log). Core of network security monitoring & Security Onion.
π Web App Testing Β· 13
Already installed! Inspect requests, cookies, localStorage, JavaScript. Solve XSS labs with nothing else.
The web-tester's weapon #1: intercept, replay (Repeater), fuzz (Intruder), scan (Pro). Community Edition is free β learn it deeplyβ¦
Fast, pretty newcomer for HTTP interception β nice alternative when Burp CE rate-limits Intruder.
"Fuzz Faster U Fool": fuzz parameters, dirs, vhosts at high speed with fine filters. CTF essential.
Brute-forces hidden directories/files (/admin, /backup.zip), virtual hosts and subdomains.
Probes huge host lists: which are live, what tech, what status. Glue tool of recon pipelines.
Veteran web server scanner: outdated software, dangerous files, misconfigs. Noisy β which is a lesson itself.
Community templateβdriven scanner: thousands of one-click CVE/misconfig checks. Bug-bounty hunters live in it.
100% free/open from OWASP. Great for automated scans and CI pipelines. Teams often run both ZAP and Burp.
APIs leak data constantly (see OWASP API Top 10). Postman is how you poke them methodically.
Detects & exploits SQL injection automatically β even dumps databases. Learn manual SQLi first, then let sqlmap flex.
Identifies CMS, frameworks, server tech on any site β shapes your attack plan instantly.
WordPress = 40%+ of the web. WPScan finds vulnerable plugins/themes and enumerates users.
π₯ Exploitation Β· 11
Browser Exploitation Framework β demonstrates why XSS is terrifying: control the victim's browser in real time.
Relay traffic through compromised hosts to reach hidden networks β pivoting made simple.
The comfortable way to land on Windows via WinRM with creds or a hash. HTB players' best friend.
Offline copy of the Exploit Database. Found a service version? Searchsploit finds the public exploit. CTF daily driver.
Python classes for attacking Windows protocols β the toolbox behind most AD exploitation and Kerberos attacks.
The legendary exploit framework: 2,000+ modules, payloads and post-ex modules. The free "Metasploit Unleashed" course is a rite ofβ¦
Metasploit's in-memory super-shell: file system control, keylogging, pivoting, privilege escalation β all living in RAM.
Metasploit's payload factory: generate shells for any platform/format. Learn payloads by building them.
CrackMapExec's successor: validate creds, spray, dump, execute across whole subnets. AD pentest essential.
Poisons LLMNR/NBT-NS on Windows networks and catches password hashes from thin air. Lab-only; shows why those protocols die in secβ¦
TrustedSec's framework for authorized social-engineering simulations. Why "think before you click" training exists.
π Password Attacks Β· 8
Spiders a website to build a company-flavoured wordlist ("AcmeCorp2026!"). Passwords come from culture β exploit it (with permissiβ¦
Online rainbow-table lookup for quick checks; Name-That-Hash identifies unknown hash formats instantly.
The fastest hash cracker on earth, powered by your GPU. Combine wordlists + rules to crack NTLM/SHA/etc. Benchmark it once β it's β¦
Parallel online login attacks against SSH/FTP/web forms/RDP. Use in labs; in the real world it locks accounts and trips alarms.
The classic cracker, superb on Linux/Unix hashes (/etc/shadow). Pairs with ssh2john/zip2john to crack archives & keys.
Hydra's stable, speedy cousin. Know both; they complement oddly-specific services.
Ships with Kali (gzip'd at /usr/share/wordlists). The definitive wordlist β together with SecLists it forms 90% of password challeβ¦
Daniel Miessler's curated collection for every wordlist need β especially web dirs and parameter names.
πͺ Priv-Esc & Post-Exploitation Β· 10
Maps Active Directory attack paths as a graph β reveals "Helpdeskβ3 hopsβDomain Admin" chains instantly. Red and blue both swear bβ¦
Bible of Unix binaries that can be abused (sudo, SUID, capabilities) to escalate. Bookmark it forever.
PEASS-ng scripts auto-enumerate Linux/Windows privilege-escalation vectors in screaming colour. Run them on every CTF box.
Compares kernel/distro versions against known local-exploit lists (DirtyCow era classic). LES + LinPEAS = the standard workflow.
Windows equivalent: legit Microsoft binaries attackers abuse (certutil download, mshta execution). Defenders monitor for these tooβ¦
Extracts plaintext creds, hashes and tickets from Windows memory. The tool that made "credential hygiene" a boardroom topic.
PowerSploit's Windows enumeration checks: unquoted service paths, weak service ACLs, AlwaysInstallElevatedβ¦
Watches every process spawning (even other users') without privileges β exposes cron scripts and mistyped passwords.
The go-to for Kerberos attacks: kerberoasting, AS-REP roasting, ticket manipulation.
C# host enum swiss-army: who am I, what's here, what's defensible. Part of the standard C2 toolkit experience.
πΆ Wireless Β· 5
The complete Wi-Fi audit suite: monitor, capture handshakes, deauth, crack WPA keys. The official tutorial is a legendary first laβ¦
Modern clientless WPA attacks β grab a crackable hash without any client connected. Then feed hashcat.
Passive wireless sniffer/IDS β maps networks, detects rogue access points. The defender's wireless eyes.
Attacks WPS PIN weakness on older routers. Mostly dead on modern gear β but knowing why = interview points.
Automates Aircrack attacks end-to-end: WEP/WPA/WPS. Great for understanding the attack chain hands-on.
π¬ Digital Forensics Β· 12
Free, friendly forensic platform for disk images. Recover deleted files, browser history, USB artifacts. The CyberDefenders labs pβ¦
Finds & extracts files hidden inside other files/firmware. First command in CTF forensics.
The definitive Windows artifact parsers. Real IR shops run on these. Free with training videos.
Reads/writes metadata in hundreds of formats. CTF stego staple; real-world leak detector (phones embed GPS!).
Industry-standard imaging tool (free!). First rule of forensics: work on images, never originals.
Eric Zimmerman's Kroll Artifact Parser & Extractor β grabs registry hives, event logs, browser data fast for offline analysis.
Builds a unified timeline from disks, logs, browsers. Timelines answer "when, then what?" β the heart of IR storytelling.
The friendly front-ends that make Windows forensics approachable while you learn the artifacts.
Recover lost partitions and deleted files by signature β also handy when ransomware nukes a test VM.
Open-source DFIR platform: hunt VQL queries across thousands of endpoints in seconds. Enterpise-grade and free.
Analyse RAM captures: running processes, injected code, connections, credentials in memory. Memory never lies.
Case captures constantly hide exfil in DNS/HTTP β carve it out and prove it.
π¦ Malware Analysis Β· 12
Interactive online sandbox: click like a user, watch processes/network in real time. Free tier + great public reports to learn froβ¦
Free RE framework beloved by CTF players for binaries on any architecture.
Identifies packers (UPX!), compilers, protections β step 1 before unpacking.
Simulate DNS/HTTP services in an isolated VM so malware reveals its C2 behaviour safely.
NSA's released RE suite β professional-grade and free. Disassemble, decompile, patch. Start with crackmes.
Free CrowdStrike sandbox β excellent static+dynamic reports when studying samples safely from your browser.
The famous Interactive Disassembler. Most tutorials/books use IDA β worth learning the UI early.
Instant suspicious-file triage: what it imports, what it pretends to be, MITRE mappings.
Windows dynamic-analysis eyes: see exactly what a program does. Sysinternals Suite is mandatory Windows study anyway.
Lookup hashes/URLs across dozens of AV engines + sandbox telemetry. Daily reference for analysts. (Don't upload real secret files!β¦
Open-source Windows debugger for dynamic analysis and crackmes. Friendlier than WinDbg for beginners.
Write pattern rules to classify/hunt malware. Every SOC, sandbox and CTF uses YARA β learn the syntax day one.
π‘οΈ SOC & Defense Β· 12
Elasticsearch + Kibana + Beats/Agents power countless SOCs. Learn KQL-style querying once, use it everywhere.
Tiny daemon that bans brute-forcers by tailing logs. Install on any internet-facing Linux box β and on day one of any VPS.
FREE friendly log platform with streams, pipelines, alerts β a gentler first SIEM than the giants.
Automated adversary emulation platform. Purple-team your lab: fire techniques, confirm your SIEM catches them.
FreeBSD firewall/router distro β learn NAT, rules, VLANs, VPNs by actually building them. Core of serious home labs.
Drag-and-drop playbooks: alert β enrich (VT, AbuseIPDB) β block. Learn SOAR concepts free.
The open standard for detections ("detect mimikatz-like process names"). Write one rule, run it in Splunk/Elastic anywhere.
The original open-source IDS (1998!) β still everywhere, still taught in certs. Learn rule syntax once: alert tcp any any β any 44β¦
The enterprise SIEM leader β free 500MB/day tier is plenty for a lab. Splunk skills = directly employable; free Fundamentals coursβ¦
Fast IDS/IPS using ET Open rules. Feed it homelab traffic, watch it bark at your own Nmap scans.
Turns Windows Event Logs from "meh" into a goldmine: process creation, network connections, loading of suspicious DLLs. Pair with β¦
Free open-source SIEM/XDR: file integrity, vulnerability detection, MITRE-mapped alerts. The best first blue-lab install.
π΅οΈ OSINT Β· 12
Crowdsourced IP abuse reports β the SOC's reflex check on every alert IP.
Profiles a company's web tech β targets for both attacks and job interviews ("I see you use Splunkβ¦").
Advanced search operators expose forgotten files, admin panels, cameras. Free, powerful, underrated β master the syntax.
Troy Hunt's legendary service. Check your own accounts, enable the free notify-list. A household name in security.
Custom search consoles for social, breaches, maps & more from the author of "OSINT Techniques".
Visual intelligence graphs connecting people, domains, IPs, breaches. Free Community edition in Kali.
Interactive tree of hundreds of OSINT resources by category (usernames, emails, images, leaksβ¦).
Investigate phone numbers: Truecaller hits, disposable-number flags. Great for vishing investigations.
Finds where a username exists across hundreds of platforms. Prolific for investigations (and self-auditing).
Automates massive OSINT sweeps: DNS, breaches, emails, darknet mentions. Great for footprinting an org.
Trace images across the web: sock accounts fall apart fast with these.
Historical snapshots of any site: find removed admin pages, old emails, "deleted" evidence.
π©Ή Vulnerability Management Β· 4
Open-source enterprise-grade vulnerability scanner. Runs in your lab VM and produces pro-looking reports.
Audits a Linux host against best practices and tells you exactly what to fix. Run it on your own VPS for instant wins.
Tenable's famous scanner, free for home labs. Learn the interface β you'll meet it at work, guaranteed.
Automated compliance scoring against the famous CIS hardening benchmarks β GRC meets engineering.
π§° CTF & Utilities Β· 12
One-stop online steganography triage for CTFs.
GCHQ's "Cyber Swiss Army Knife": 300+ operations β encoding, crypto, compression, extraction. CTF oxygen.
Caesar to VigenΓ¨re to mystery hashes β classic-crypto challenges solved in seconds.
Spin up vulnerable apps (Juice Shop!), tools and malware sandboxes without polluting your VM. Learn basic Docker β it's how labs aβ¦
The pentester's encyclopedia: every service, misconfig and technique with commands. The community's brain, free.
Document every machine, command and lesson. Your notes become your portfolio and future self's gift.
GitHub repo of curated payloads/methodologies (SQLi, XSS, SSRFβ¦). CTF clipboard.
Every language's reverse/bind shell, plus URL/Base64 encoding. Saves real time in labs.
Classic hidden-data tools (zsteg shines on PNG/BMP LSB data).
Split screens for scan + listener + notes, and never lose a session. A pro's terminal looks like tmux.
Free hypervisors hosting your Kali + targets + SIEM. Section 09 builds on them. (VirtualBox is free; VMware Workstation Pro is nowβ¦
Interactive cheat-sheet for Windows/AD: filters by what you have (creds? shell?) and shows commands.
π Personal Security Β· 7
App-based MFA with encrypted backup. Turn MFA on for email first, then everything else.
Open source, free, everywhere. Non-negotiable modern hygiene β password reuse is how people get owned.
Fully offline alternative beloved by the paranoid (healthy paranoia). Kali users' default.
Reputable no-log VPNs for untrusted Wi-Fi. (A VPN is privacy hygiene, not magic invisibility.)
End-to-end encrypted messaging with sealed-sender design. Community standard.
Malvertising is a real attack vector. Harden your daily browser, too β you are a target now.
Free TrueCrypt successor β encrypt research, notes and VM drives on shared machines.