Community gallery

Curated writeups & references

Hand-picked external resources — blogs, methodology guides, and lab projects. Not a CMS or user uploads: quality over quantity for deliberate practice.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

24 links
beginner
walkthrough
PortSwigger

PortSwigger Web Security Academy

Free structured web labs with excellent explanations of OWASP-class bugs.

Why read: Best default web practice path before random CTF thrash.

web
xss
sqli
ssrf
access-control
intermediate
methodology
HackTricks

HackTricks

Living encyclopedia of pentest techniques across protocols and platforms.

Why read: When you need a checklist after finding an odd service.

enum
privesc
ad
cloud
network
intermediate
methodology
Swissky

PayloadsAllTheThings

Payload and methodology cheats for web, API, and common services.

Why read: Quick payload inspiration after you understand the sink.

payloads
web
api
wordlists
intermediate
methodology
GTFOBins

GTFOBins

Unix binaries that can be abused for privesc, shell, file transfer.

Why read: After sudo -l or SUID finds — verify impact cleanly.

linux
privesc
lolbin
intermediate
methodology
LOLBAS Project

LOLBAS

Living Off the Land binaries and scripts on Windows.

Why read: Windows post-ex without dropping obvious malware in labs.

windows
privesc
lolbin
advanced
methodology
SpecterOps

BloodHound / AD attack path literature

Official BloodHound docs and AD graph attack path thinking.

Why read: Learn to explain paths, not just click shortest path to DA.

ad
bloodhound
kerberos
advanced
research
adsecurity.org

Active Directory Security blog

Deep AD research writeups useful for serious internal testing study.

Why read: Background for Kerberos and trust abuse beyond CTF recipes.

ad
kerberos
defense
advanced
methodology
iRed.team

iRed Team notes (red team techniques)

Windows red team technique notes — study in authorized labs only.

Why read: Expand post-ex vocabulary after basic shells.

windows
post-ex
evasion
beginner
methodology
OWASP

OWASP Web Security Testing Guide

Industry testing methodology checklist for web applications.

Why read: Structure engagements so coverage is defensible.

web
methodology
reporting
beginner
methodology
OWASP

OWASP Top 10

Shared risk vocabulary with developers and clients.

Why read: Map findings to categories clients recognize.

web
risk
reporting
intermediate
methodology
MITRE

MITRE ATT&CK

Technique taxonomy for purple teaming and report language.

Why read: Connect offensive steps to detection conversations.

att&ck
purple
detection
beginner
methodology
PTES

Penetration Testing Execution Standard

Classic engagement phases from pre-engagement to reporting.

Why read: Professional spine beyond tool lists.

methodology
reporting
scope
intermediate
walkthrough
NetSecFocus / TJ Null

TJ Null’s OSCP-like prep lists (community)

Community pointers for OSCP-style practice box selection (verify current links).

Why read: Practice selection strategy for cert-style grind.

oscp
labs
practice
intermediate
walkthrough
0xdf

0xdf HTB writeups

High-quality Hack The Box writeups with methodology emphasis.

Why read: Study approach after you finish a box yourself.

htb
walkthrough
linux
windows
intermediate
walkthrough
IppSec

IppSec video walkthroughs

Searchable index of HTB video walkthroughs.

Why read: Watch tool workflow after attempting boxes blind.

htb
video
methodology
beginner
methodology
danielmiessler

SecLists project

Canonical wordlist collection for discovery and auth testing.

Why read: Know which list size matches which job.

wordlists
ffuf
hydra
beginner
methodology
Nmap.org

Nmap Network Scanning book / reference

Authoritative Nmap documentation for scan types and scripts.

Why read: Stop cargo-culting flags you do not understand.

nmap
scanning
advanced
walkthrough
Rhino Security Labs

CloudGoat (Rhino Security)

Vulnerable AWS lab scenarios for cloud pentest practice.

Why read: Hands-on cloud paths after reading IAM theory.

cloud
aws
lab
advanced
walkthrough
Madhu Akula

Kubernetes Goat

Intentional K8s vulnerable scenarios for learning cluster risk.

Why read: Practice container/cluster issues safely.

k8s
containers
lab
advanced
walkthrough
Orange Cyberdefense

GOAD — Game of Active Directory

Lab AD environment for realistic multi-forest practice.

Why read: Serious AD practice beyond single-box CTFs.

ad
lab
bloodhound
advanced
methodology
Chris Long

DetectionLab

Windows domain + logging stack for purple exercises.

Why read: See your own attacks in logs.

purple
detection
lab
intermediate
research
SigmaHQ

Sigma rules (SigmaHQ)

Generic detection rules convertible to many SIEMs.

Why read: Write detections for techniques you just practiced.

detection
sigma
purple
beginner
methodology
CISA / vendor docs

Router security guidance (consumer)

Baseline home network hardening advice for personal practice scope.

Why read: Pair offense learning with real home remediation.

home-network
router
defense
beginner
research
IETF

Thinking in private networks (RFC1918 context)

Private address space definition — helps home lab network design.

Why read: Design isolated lab ranges intentionally.

networking
lab