Resources
Links that actually advance an operator
Platforms, methodologies, books, certs, wordlists, and communities — curated for learning, not tab overload. Pair these with the in-app tool directory.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Hands-on platforms
Practice targets, guided paths, and competitive learning.
TryHackMe
Best guided start for absolute beginners.
https://tryhackme.com/
Hack The Box
Realistic machines and career-oriented labs.
https://www.hackthebox.com/
PortSwigger Web Security Academy
Free gold-standard web security labs.
https://portswigger.net/web-security
PentesterLab
Exercise-based skill building and badges.
https://pentesterlab.com/
VulnHub
Downloadable vulnerable VMs for offline practice.
https://www.vulnhub.com/
OverTheWire
Linux and security wargames via SSH.
https://overthewire.org/wargames/
picoCTF
Beginner-friendly CTF challenges.
https://picoctf.org/
CryptoHack
Learn applied crypto by solving puzzles.
https://cryptohack.org/
AttackDefense / Pentester Academy
Browser-based professional labs.
https://attackdefense.com/
RangeForce / commercial cyber ranges
Enterprise-style cyber range training.
https://www.rangeforce.com/
Methodologies & frameworks
How professionals structure engagements and techniques.
PTES
Penetration Testing Execution Standard.
https://www.pentest-standard.org/
OWASP WSTG
Web Security Testing Guide.
https://owasp.org/www-project-web-security-testing-guide/
OWASP ASVS
Application security verification controls.
https://owasp.org/www-project-application-security-verification-standard/
OWASP Top 10
Most critical web application risks.
https://owasp.org/www-project-top-ten/
MITRE ATT&CK
Adversary tactics and techniques knowledge base.
https://attack.mitre.org/
MITRE ATLAS
Adversarial threats to ML/AI systems.
https://atlas.mitre.org/
NIST SP 800-115
Technical guide to information security testing.
https://csrc.nist.gov/publications/detail/sp/800-115/final
OSSTMM
Open Source Security Testing Methodology Manual.
https://www.isecom.org/OSSTMM.3.pdf
CIS Benchmarks
Hardening benchmarks across platforms.
https://www.cisecurity.org/cis-benchmarks
CVSS
Common Vulnerability Scoring System.
https://www.first.org/cvss/
Books that level you up
Deep reading beyond tool tutorials.
The Web Application Hacker's Handbook
Classic web appsec reference.
https://portswigger.net/web-security/web-application-hackers-handbook
Operator Handbook (RTFM-style)
Field cheatsheets for operators.
https://www.amazon.com/Operator-Handbook-Red-Cheatsheet-edition/dp/B08F2S4X9X
Red Team Field Manual / Blue Team Field Manual
Quick command references (pair both colors).
https://www.amazon.com/Rtfm-Red-Team-Field-Manual/dp/1494295504
Hacking: The Art of Exploitation
Low-level programming and exploitation foundations.
https://nostarch.com/hacking2.htm
Practical Malware Analysis
RE and malware triage fundamentals.
https://nostarch.com/malware
Atomic Red Team (project)
Small tests mapped to ATT&CK for purple teams.
https://github.com/redcanaryco/atomic-red-team
Network Basics books / TCP/IP illustrated path
Deep networking literacy.
https://en.wikipedia.org/wiki/TCP/IP_Illustrated
Windows Internals
How Windows actually works.
https://learn.microsoft.com/sysinternals/resources/windows-internals
Certifications (signals, not substitutes)
Useful milestones after hands-on proof exists.
eJPT
Beginner practical pentest cert.
https://security.ine.com/certifications/ejpt-certification/
CompTIA Security+
Broad baseline for cyber careers.
https://www.comptia.org/certifications/security
PNPT (TCM)
Practical network pentest with reporting emphasis.
https://certifications.tcm-sec.com/pnpt/
OSCP
Famous practical exam — prepare with many boxes.
https://www.offsec.com/courses/pen-200/
OSWP / wireless paths
Wireless-focused OffSec options.
https://www.offsec.com/
CRTO / CRTP style AD certs
Active Directory / red team focused paths.
https://www.zeropointsecurity.co.uk/
GWAPT / GMOB / GPEN (SANS)
Specialized professional certs (expensive, deep).
https://www.sans.org/cyber-security-certifications/
AWS / Azure security certs
Pair cloud engineer knowledge with offensive cloud skills.
https://aws.amazon.com/certification/
Wordlists, payloads & references
Daily-driver data for fuzzing and testing.
SecLists
The wordlist collection.
https://github.com/danielmiessler/SecLists
PayloadsAllTheThings
Payloads and bypasses by vulnerability class.
https://github.com/swisskyrepo/PayloadsAllTheThings
HackTricks
Encyclopedic pentest methodology notes.
https://book.hacktricks.xyz/
GTFOBins
Unix binary abuse reference.
https://gtfobins.github.io/
LOLBAS
Windows living-off-the-land reference.
https://lolbas-project.github.io/
WADComs
AD command cheats when you have X and want Y.
https://wadcoms.github.io/
PayloadsAllTheThings / Internal All The Things
Internal pentest cheatsheets.
https://swisskyrepo.github.io/InternalAllTheThings/
Exploit-DB
Public exploit archive (read before you run).
https://www.exploit-db.com/
CVE / NVD
Vulnerability database for research.
https://nvd.nist.gov/
OWASP Cheat Sheet Series
Defensive coding and testing cheatsheets.
https://cheatsheetseries.owasp.org/
Communities & news
Stay current without drowning in hype.
OWASP local chapters
Meet practitioners near you.
https://owasp.org/chapters/
r/netsec
Technical security link aggregation.
https://www.reddit.com/r/netsec/
Hacker News (security threads)
Industry discussion; filter carefully.
https://news.ycombinator.com/
The Hacker News / specialized newsletters
High-level awareness — verify technical claims.
https://thehackernews.com/
ProjectDiscovery blog & Discord
Modern recon tooling ecosystem.
https://projectdiscovery.io/
PortSwigger Research
Cutting-edge web security research.
https://portswigger.net/research
SpecterOps blog
AD and adversary simulation excellence.
https://posts.specterops.io/
Local DEF CON groups / BSIDES
Regional security conferences and meetups.
https://bsides.org/
Legal & ethics anchors
Read before you scan anything outside your lab.
Computer Fraud and Abuse Act overview (US)
US federal cybercrime enforcement context.
https://www.justice.gov/jm/jm-9-48000-computer-fraud
Bug bounty policy examples
Learn how authorized programs define scope.
https://hackerone.com/bug-bounty-programs
CVE disclosure ethics discussions (ISO 29147)
Vulnerability disclosure standard.
https://www.iso.org/standard/72311.html
First.org ethics / CSIRT codes
Incident response community standards.
https://www.first.org/
Suggested 90-day starter plan
Adjust hours to your life — consistency beats binge weekends.
- Days 1–14: Lab Zero + Linux/networking modules + OverTheWire Bandit.
- Days 15–40: Web path (PortSwigger Academy + Juice Shop) with Burp notes.
- Days 41–65: Network boxes (Metasploitable/VulnHub/HTB easy) + cracking fundamentals.
- Days 66–90: One AD intro path, one full writeup/report, and a purple-team logging lab.