Community gallery
Curated writeups & references
Hand-picked external resources — blogs, methodology guides, and lab projects. Not a CMS or user uploads: quality over quantity for deliberate practice.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
PortSwigger Web Security Academy
Free structured web labs with excellent explanations of OWASP-class bugs.
Why read: Best default web practice path before random CTF thrash.
HackTricks
Living encyclopedia of pentest techniques across protocols and platforms.
Why read: When you need a checklist after finding an odd service.
PayloadsAllTheThings
Payload and methodology cheats for web, API, and common services.
Why read: Quick payload inspiration after you understand the sink.
GTFOBins
Unix binaries that can be abused for privesc, shell, file transfer.
Why read: After sudo -l or SUID finds — verify impact cleanly.
Why read: Windows post-ex without dropping obvious malware in labs.
BloodHound / AD attack path literature
Official BloodHound docs and AD graph attack path thinking.
Why read: Learn to explain paths, not just click shortest path to DA.
Active Directory Security blog
Deep AD research writeups useful for serious internal testing study.
Why read: Background for Kerberos and trust abuse beyond CTF recipes.
iRed Team notes (red team techniques)
Windows red team technique notes — study in authorized labs only.
Why read: Expand post-ex vocabulary after basic shells.
OWASP Web Security Testing Guide
Industry testing methodology checklist for web applications.
Why read: Structure engagements so coverage is defensible.
Why read: Map findings to categories clients recognize.
Why read: Connect offensive steps to detection conversations.
Penetration Testing Execution Standard
Classic engagement phases from pre-engagement to reporting.
Why read: Professional spine beyond tool lists.
TJ Null’s OSCP-like prep lists (community)
Community pointers for OSCP-style practice box selection (verify current links).
Why read: Practice selection strategy for cert-style grind.
0xdf HTB writeups
High-quality Hack The Box writeups with methodology emphasis.
Why read: Study approach after you finish a box yourself.
Why read: Watch tool workflow after attempting boxes blind.
SecLists project
Canonical wordlist collection for discovery and auth testing.
Why read: Know which list size matches which job.
Nmap Network Scanning book / reference
Authoritative Nmap documentation for scan types and scripts.
CloudGoat (Rhino Security)
Vulnerable AWS lab scenarios for cloud pentest practice.
Kubernetes Goat
Intentional K8s vulnerable scenarios for learning cluster risk.
GOAD — Game of Active Directory
Lab AD environment for realistic multi-forest practice.
Why read: Write detections for techniques you just practiced.
Router security guidance (consumer)
Baseline home network hardening advice for personal practice scope.
Why read: Pair offense learning with real home remediation.
Thinking in private networks (RFC1918 context)
Private address space definition — helps home lab network design.
Why read: Design isolated lab ranges intentionally.