Pentest Resources

📚 Pentest-Resources

A curated list of websites and github repos with pentest cheatsheets, tools, techniques, CTF write-ups, programming languages, and more.

The goal of this project is to centralize pertinent and most used pentest/redteam cheatsheets, techniques, tools, and write-ups for like-minded offensive security enthusiasts and professionals.

NameAuthor(s) / Maintainer(s)DescriptionLinkType
HackTricksCarlos PolopA website featuring curated hacking tricks, techniques, and methodologies, spanning from network penetration testing to web penetration testing.LinkPentest cheatsheats
Red Team NotesMantvydas BaranauskasA list of red teaming and penetration testing notes on various tools and techniques utilized by penetration testers, red teams, and real adversaries.LinkRed team/Pentest notes
GtfobinsEmilio Pinna, Andrea CardaciA curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.LinkUnix binaries
LOLBASOddvar MoeContains a list of Windows binaries, scripts, and libraries that can be used for executing codes, Compiling code, UAC bypass, Persistance, etcLinkWindows binaries/scripts
0xBENBenjamin H.0xBEN’s blog featuring cybersecurity/IT resources, cheat sheets, and write-ups.LinkCybersecurity/IT blog
IppSecIppSecIppSec’s website that helps streamline your search for his YouTube videos and courses on HTB walkthroughs and techniquesLinkCTF (HTB) videos
0xdf hacks stuff0xdf0xdf’s website with detailed write-ups on HTB machinesLinkCTF (HTB) write-ups
Goal KickerUnknownProvides free exceptional programming notes covering 49 different types of programming languages, including scripting languages such as python and powershellLinkProgramming/Scripting language notes
The Hacker RecipesCharlie BrombergProvides technical guides on various hacking topics as well as advanced topics such as Active Directory and Web services.LinkEthical Hacking guide
harmj0yharmj0yharmj0y’s blog covering security researches and attacks on active directory.LinkOffsec/Active Directory resource
CyberChefGCHQA web app for encryption, encoding, compression and data analysisLinkWeb based security analysis tool
Payloads All The ThingsSwisskyA list of useful payloads and bypass for Web Application Security and Pentest/CTFLinkWeb App payloads/cheatsheets
SecListsDaniel Miessler, Jason Haddix, g0tmi1kA collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.LinkWordlists
Assetnote WordlistsAssetnoteThe website provides wordlists that are up to date and effective against the most popular technologies on the internet.LinkWordlists
Speed GuideSG StaffThe site offers free network tools and covers Broadband Internet connections, network security, wireless and system performance. A large section focuses on Cable Modems and DSL technology, stressing on improving TCP/IP performance over high speed/latency networks.LinkNetwork/Security resource
pentestmonkeypentestmonkeyContains pentest blogs, tools, and cheatsheetsLinkPentest cheatsheets
Awesome Hacker Search EnginesEdoardo OttavianelliA curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more.LinkPentest search engines
HackToolsLudovic COULON, Riadh BOUCHAHOUAA web extension facilitating web application penetration tests, it includes cheatsheets as well as all the tools used during a test such as XSS payloads, Reverse shells and much more.LinkWeb App tool/cheatsheet
NetSPI BlogNetSPIA blog on various Pentest, Red Team, General Offsec focused topics.LinkPentest/Red Team in depth
Hacking ArticlesRaj Chandel - Founder and OthersDetailed and Summarised articles on various Pentest and Red Team topics, Offsec Tools and CTF writeupsLinkDetailed Pentest/Red Team Blog
PortSwigger Web Security AcademyPortSwiggerAn academy with lessons and hands on lab to learn WebApp PentestingLinkWebApp Security Lessons & Labs
Juggernaut Pentesting AcademyJuggernautExtensive blog on General Offsec, Read Teaming and Pentesting TopicsLinkPentest, Red Team, Offsec Topics
HackersploitHackersploitVideo content on Red Team, Blue Team, Android Sec, CTF Writeup, Bug BountyLinkRed/Blue Team, Webapp, Android, Bug Bounty
TechMintRavi SaiveFree online community-supported publication that publishes practical and useful out-of-the-box high-quality articles on Linux, Sysadmin, Security, DevOps, Cloud Computing, Tools, and many other topics.LinkCheatsheets and High-quality articles on Linux, Sysadmin, Security, Tools, etc
Active Directory Exploitation Cheat SheetNikos KatsiopisA cheat sheet that contains common enumeration and attack methods for Windows Active Directory.LinkActive Directory Cheatsheets
Awesome PentestNick RaienkoA collection of awesome penetration testing resources, tools and other shiny thingsLinkPenetration testing and offensive cybersecurity resources.