π resources
Table of Contents
Collection of some great resources to become a Pentester / Red Teamer. Keep these resources handy if you are preparing for certifications like OSCP, eCPPT, CRTP, CRTO etc.
Note: π² means paid resources.
Enumeration
-
Introduction To Pentesting - Enumeration - HackerSploit
-
Ethical Hacking Practical - Enumeration - Semi Yulianto
Network Pentesting
-
Beginner Network Penetration Testing - Heath Adams (The Cyber Mentor)
-
Network Penetration Testing for Beginners - FreeCodeCamp
Web Applications Pentesting
-
https://owasp.org/www-project-web-security-testing-guide/latest/
-
Web Application Ethical Hacking - Penetration Testing Course for Beginners - FreeCodeCamp, Heath Adams (The Cyber Mentor)
Buffer Overflows
-
Buffer Overflows Made Easy (2022 Edition) - Heath Adams (The Cyber Mentor)
-
Running a Buffer Overflow Attack - Computerphile
Buffer Overflow Labs
-
Sneaky (Medium) - Machine, Walkthrough
-
Enterprise (Medium) - Machine, Walkthrough
-
October (Medium) - Machine, Walkthrough
-
Jail (Insane) - π² Machine, Walkthrough
-
Node (Medium) - π² Machine, Walkthrough
Metasploit Usage
-
Metasploit Minute - Hak5
-
Metasploit For Beginners - HackerSploit
-
Metasploit - David Bombal
-
Complete Metasploit System Hacking Tutorial! - Joseph Delgadillo
-
https://karol-mazurek95.medium.com/solid-metasploit-b1e043470b8c
-
https://www.offensive-security.com/metasploit-unleashed/meterpreter-basics/
Active Directory Pentesting
-
Active Directory Pentesting - Red Team - I.T & Security
-
Building Home AD Lab - Conda
-
Attacking Active Directory - Conda
-
https://book.hacktricks.xyz/windows/active-directory-methodology
-
https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
Active Directory Labs
-
Forest (Easy) - π² Machine, Walkthrough
-
Active (Easy) - π² Machine, Walkthrough
-
Fuse (Medium) - π² Machine, Walkthrough
-
Cascade (Medium) - π² Machine, Walkthrough
-
Monteverde (Medium) - π² Machine, Walkthrough
-
Resolute (Medium) - π² Machine, Walkthrough
-
Arkham (Medium)- π² Machine, Walkthrough
-
Mantis (Hard) - π² Machine, Walkthrough
-
APT (Insane) - π² Machine, Walkthrough
Password Cracking & Brute Forcing
-
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords - HackerSploit
-
Password cracking with Kali Linux and HashCat - NetworkChuck
Exploit Development
Exploition & Post-Exploition
-
Ethical Hacking Practical - Exploitation - Semi Yulianto
-
Ethical Hacking Practical - Automated Exploitation - Semi Yulianto
-
Ethical Hacking Practical - Post Exploitation - Semi Yulianto
Privilege Escalation
-
Windows Local Privilege Escalation - Sagi Shahar
-
Privilege Escalation - Conda
-
π² https://academy.tcm-sec.com/p/windows-privilege-escalation-for-beginners
-
π² https://academy.tcm-sec.com/p/linux-privilege-escalation
-
π² https://www.udemy.com/course/windows-privilege-escalation/
-
π² https://www.udemy.com/course/linux-privilege-escalation/
-
https://book.hacktricks.xyz/windows/windows-local-privilege-escalation
Privilege Escalation Labs
Lateral Movement
-
https://riccardoancarani.github.io/2019-10-04-lateral-movement-megaprimer/
-
https://kjohn333.gitbook.io/offsec-journey/active-directory/lateral-movement
-
https://pentestlab.blog/2020/07/21/lateral-movement-services/
-
https://cheats.philkeeble.com/active-directory/lateral-movement
Pivoting
-
https://posts.specterops.io/offensive-security-guide-to-ssh-tunnels-and-proxies-b525cbd4d4c6
-
https://systemweakness.com/the-shades-of-tunneling-a8b6ce1d7fed
-
https://gitbook.seguranca-informatica.pt/cheat-sheet-1/stuff/pivoting
-
Port Forwarding and Tunneling - Network Pivoting - Motasem Hamdan
-
https://www.hackingarticles.in/port-forwarding-tunnelling-cheatsheet/
-
https://sushant747.gitbooks.io/total-oscp-guide/content/port_forwarding_and_tunneling.html
-
https://www.onmsft.com/how-to/how-to-configure-port-forwarding-on-a-windows-10-pc
Courses
-
Ethical Hacking in 12 Hours - Heath Adams (The Cyber Mentor)
-
π² Practical Ethical Hacking - Heath Adams (The Cyber Mentor)
-
π² Windows Privilege Escalation for OSCP & Beyond! - Tib3rius
-
π² Windows Privilege Escalation for Beginners - Heath Adams (The Cyber Mentor)
-
π² Linux Privilege Escalation for OSCP & Beyond! - Tib3rius
-
π² Linux Privilege Escalation for Beginners - Heath Adams (The Cyber Mentor)
-
π² Movement, Pivoting, and Persistence For Pentesters and Ethical Hackers - Joe Helle
-
π² Active Directory Pentesting Full Course - Red Team Hacking - Security Gurus
Books
-
π² Penetration Testing: A Hands-On Introduction to Hacking - Georgia Weidman
-
π² The Hacker Playbook 3: Practical Guide To Penetration Testing - Peter Kim
Free Labs to Practice
- Attack-Defense - https://attackdefense.com
- Alert to win - https://alf.nu/alert1
- Bancocn - https://bancocn.com
- CTF Komodo Security - https://ctf.komodosec.com
- CryptoHack - https://cryptohack.org/
- CMD Challenge - https://cmdchallenge.com
- Explotation Education - https://exploit.education
- Google CTF - https://capturetheflag.withgoogle.com
- HackTheBox - https://www.hackthebox.com
- Hackthis - https://www.hackthis.co.uk
- Hacksplaining - https://www.hacksplaining.com/lessons
- Hacker101 - https://ctf.hacker101.com
- Hacker Security - https://capturetheflag.com.br
- Hacking-Lab - https://hacking-lab.com/
- HSTRIKE - https://hstrike.com
- ImmersiveLabs - https://immersivelabs.com
- NewbieContest - https://www.newbiecontest.org
- OverTheWire - http://overthewire.org
- Practical Pentest Labs - https://practicalpentestlabs.com
- Pentestlab - https://pentesterlab.com
- Hackaflag BR - https://hackaflag.com.br/
- Penetration Testing Practice Labs - https://www.amanhardikar.com/mindmaps/Practice.html
- PentestIT LAB - https://lab.pentestit.ru
- PicoCTF - https://picoctf.com
- PWNABLE - https://pwnable.kr/play.php
- Root-Me - https://www.root-me.org
- Root in Jail - http://rootinjail.com
- SANS Challenger - https://www.holidayhackchallenge.com/2021/
- SmashTheStack - http://www.smashthestack.org/wargames.html
- The Cryptopals Crypto Challenges - https://cryptopals.com
- Try Hack Me - https://tryhackme.com
- Vulnhub - https://www.vulnhub.com
- W3Challs - https://w3challs.com
- WeChall - http://www.wechall.net
- Zenk-Security - https://www.zenk-security.com
- Cyberdefenders - https://cyberdefenders.org/blueteam-ctf-challenges/
- LetsDefend- https://letsdefend.io/