Useful Resources
Resources and Trainings I've come across
These are a bunch of resources and trainings I've come across. Some I've used, some I've not. Some are free, some are not. They're in no particular order nor do I have any affiliation with these.
Resources
Blogs
BC Security (PowerShell Empire maintainers)
Linuxize (Linux blog and tutorials)
Pentestlab (blog)
Rasta Mouse (blog)
Recipe for Root (my friend's blog)
TJnull OSCP Prep (blog)
Cloud
Azure Citadel (hands-on exercises for Azure/Azure DevOps)
Microsoft Learn Azure Labs (contains labs removed from MS Learn courses)
Azure Security Best Practices (videos from Microsoft)
Coding, Scripting, WebDev
mdn web docs (Mozilla Developer Guides)
Dan's Tools (webdev tools and more)
Pentesting & Red Teaming
Active Directory Security (go-to resource for AD)
CloudGoat (AWS Vulnerable Cloud lab)
GTFOBins (Unix binary abuse)
GTFOBins - LOLBAS (Windows binary abuse)
PenTest.WS (pentesting toolset)
PrivEsc Blog (click menu for Linux, Windows, or Red teaming)
PrivEsc Mindmap (Linux and Windows)
PTES (Standard for conducting pentest engagements)
Red Teaming Experiments (similar to HackTricks)
WADComs (like GTFOBins for Active Directory)
Security
MalwareBazaar (malware samples)
Threat & Vulnerability Intel
NVD (NIST National Vulnerability Database)
Tools
ADRecon.ps1 (AD enumeration tool)
Browser Plugin Security Scanner (DUO Security)
Converters (Hex > ASCII and more)
Other
Awesome List (references for everything)
MITRE Engage (Frameworks and Resources)
Mess with DNS (DNS tutorial)
Red Team Infrastructure (IaC lab)
__Rex Egg (Regex tutorial)
Training Platforms
OWASP Juice Shop (GitHub link if you prefer to download)
ACloudGuru (merging with pluralsight)
eLearnSecurity (available on INE as a subscription)
Last updated